GDPR Compliance

Data processing agreements, subprocessor management, and breach notification under GDPR.

GDPR Compliance in 2026: Principles, Rights & How to Prove It

GDPR Compliance in 2026: Principles, Rights & How to Prove It

GDPR compliance explained for 2026: the 7 principles, 6 lawful bases, data subject rights, the compliance checklist, 2025–26 fines, and UK/Norway divergence.

2026-06-12 · By Orbiq Team

GDPR Compliance for B2B SaaS: Articles 28–34 Explained

GDPR Compliance for B2B SaaS: Articles 28–34 Explained

A B2B SaaS reference to GDPR Articles 28, 32, 33 & 34 — DPAs, security of processing, and breach notification — with a compliance checklist and links to each deep-dive.

2026-07-06 · By Anna Bley

Subprocessor Management Under GDPR Article 28: What Controllers Actually Expect

Subprocessor Management Under GDPR Article 28: What Controllers Actually Expect

What do controllers, DPOs, and procurement teams actually expect from your subprocessor management? A practical guide beyond GDPR Article 28 minimum compliance — covering sub-processor lists, change notifications, data flow transparency, and ongoing due diligence.

2026-02-23 · By Anna Bley

GDPR Article 33: 72-Hour Breach Notification Rule (2026)

GDPR Article 33: 72-Hour Breach Notification Rule (2026)

GDPR Article 33: when the 72-hour breach clock starts, exactly what to report, the fines for missing it, how to prove compliance, and the UK & Norway position.

2026-07-06 · By Anna Bley

GDPR Article 34: Communicating a Data Breach to Data Subjects (2026)

GDPR Article 34: Communicating a Data Breach to Data Subjects (2026)

GDPR Article 34: when you must tell individuals about a breach, the high-risk threshold, the three exceptions that get you out of it, and how to prove it.

2026-07-06 · By Anna Bley

GDPR Article 32: Security of Processing Requirements (2026)

GDPR Article 32: Security of Processing Requirements (2026)

GDPR Article 32 explained: the technical and organisational measures required, whether encryption is mandatory, the risk-based test, fines, and how to prove it.

2026-07-06 · By Anna Bley

GDPR Article 28: DPA Requirements & Processor Duties (2026)

GDPR Article 28: DPA Requirements & Processor Duties (2026)

GDPR Article 28 explained: the mandatory DPA clauses, controller due-diligence duties, sub-processor authorisation, EDPB Opinion 22/2024, and how to prove it.

2026-07-06 · By Anna Bley

EU Compliance Software: Complete Buyer's Guide (2026)

EU Compliance Software: Complete Buyer's Guide (2026)

How to choose EU compliance software in 2026. Covers NIS2, DORA, GDPR, and CRA requirements, key features to evaluate, EU data residency risks, and how Orbiq compares.

2026-03-24 · By Orbiq Team

Compliance Software Comparison for Germany: Buyer's Guide 2026

Compliance Software Comparison for Germany: Buyer's Guide 2026

Comparing the best compliance software for German companies in 2026. Covers ISMS, GRC, NIS2, DSGVO/GDPR, BSI IT-Grundschutz, and EU data residency requirements.

2026-03-30 · By Orbiq Team