Since coming into force in May 2018, the General Data Protection Regulation (GDPR) has profoundly transformed how companies manage personal data. Yet many SMEs remain non-compliant, often through lack of information or resources.
What is the GDPR?
The GDPR is a European regulation that frames the processing of personal data. It applies to any organisation that collects, processes or stores data of people residing in the European Union, regardless of where the organisation is located.
The essential obligations
Transparency and consent The people whose data you collect must be informed of how it is used and have given their explicit consent.
Rights of individuals The GDPR enshrines several rights: right of access, right of rectification, right to erasure ("right to be forgotten"), right to portability.
Data security You must put in place technical and organisational measures to protect data against unauthorised access, loss or breach.
Breach notification In the event of a data breach, you have 72 hours to notify the competent supervisory authority (the CNIL in France).
What to check in your software solutions?
When acquiring a software solution, systematically verify:
KEATIC and compliance
All solutions listed on KEATIC are subject to a GDPR compliance check. We favour European publishers and solutions hosted on certified infrastructures.


