{"id":398,"date":"2023-07-12T12:00:53","date_gmt":"2023-07-12T10:00:53","guid":{"rendered":"https:\/\/stage.usercentrics.com\/?post_type=knowledge&#038;p=31240"},"modified":"2025-06-26T15:00:08","modified_gmt":"2025-06-26T13:00:08","slug":"who-is-responsible-for-gdpr-compliance","status":"publish","type":"knowledge","link":"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/","title":{"rendered":"Who is responsible for GDPR compliance?"},"content":{"rendered":"\n\n<h2 class=\"wp-block-heading\">Introduction to the GDPR and data privacy compliance<\/h2>\n<p>The General Data Protection Regulation (GDPR) has been in effect in the European Union (EU) since 2018, so companies doing business in the EU have had time to learn their privacy compliance responsibilities. We will look at who is responsible for data privacy compliance and how to implement best practices. We will also outline GDPR enforcement from a government level down to day to day corporate operations.<\/p>\n\n\n<h2 class=\"wp-block-heading\">What is GDPR?<\/h2>\n<p>The <a href=\"\/gdpr\/\">General Data Protection Regulation<\/a> (GDPR) is a set of regulations introduced by the European Union (EU) to protect the privacy of EU residents\u2019 personal data. The focus is on individuals. GDPR compliance is mandatory for any organization that processes the personal data of EU residents, regardless of where the organization is located or whether or not the processing is for commercial purposes.<\/p>\n<p>The GDPR has been highly influential on subsequent data privacy legislation around the world, like Brazil\u2019s <a href=\"\/lgpd\/\">Lei Geral de Prote\u00e7\u00e3o de Dados Pessoais<\/a> (LGPD). After Brexit, <a href=\"https:\/\/www.cookiebot.com\/en\/gdpr-brexit\/\" target=\"_blank\" rel=\"noopener\">GDPR UK compliance requirements<\/a> didn\u2019t really change, as the EU\u2019s GDPR was maintained almost in its entirety.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Who is responsible for GDPR compliance in companies?<\/h2>\n<h4>Data controllers and data processors and GDPR compliance<\/h4>\n<p>To ensure GDPR compliance, it&#8217;s essential to understand the roles of data controllers and data processors. They are the ones collecting and processing users\u2019 personal data, and thus responsible at the day to day level for data security and privacy.<\/p>\n<p>A data controller under the GDPR is a \u201cperson\u201d, but in reality likely an organization, that collects personal data and determines the purposes and means of its processing. Data processing can mean anything from creating customer profiles to aggregating demographic information for sale.<\/p>\n<p>A data processor is a person \u2014 again, likely an organization \u2014 who processes personal data on behalf of a data controller. Advertising partners are a good example of this. GDPR requirements apply to both data controllers and data processors, but the specific responsibilities differ. Ultimately, data security and privacy compliance is usually the controller\u2019s responsibility.<\/p>\n\n\n<h4>Responsibilities of data controllers under the GDPR<\/h4>\n<p>Data controllers are primarily responsible for ensuring GDPR compliance. They must obtain valid consent from individuals for data processing. (See <a href=\"https:\/\/gdpr.eu\/article-7-how-to-get-consent-to-collect-personal-data\/\" target=\"_blank\" rel=\"noopener\">Art. 7 GDPR<\/a> for conditions for valid consent.) Their additional responsibilities include:<\/p>\n<ul>\n<li>maintaining secure records of consent preferences<\/li>\n<li>keeping data accurate and up to date<\/li>\n<li>correcting or deleting data when requested, under certain circumstances<\/li>\n<li>implementing appropriate technical and organizational measures to protect data<\/li>\n<\/ul>\n<p>Data controllers must also ensure that any third-party data processors they work with are GDPR-compliant, with contractual agreements in place.<\/p>\n\n\n<h4>Responsibilities of data processors under the GDPR<\/h4>\n<p>Data processors must process personal data only according to the instructions and contractual agreement with the data controller. Their additional responsibilities include:<\/p>\n<ul>\n<li>implementing appropriate technical and organizational measures to protect data<\/li>\n<li>notifying the data controller of any data breaches<\/li>\n<li>keeping records of their processing activities<\/li>\n<li>compliance with data deletion requirements after processing<\/li>\n<\/ul>\n\n\n<h4>Data Protection Authority (DPA)<\/h4>\n<p>Data Protection Authorities (DPAs) are independent public authorities that oversee GDPR compliance and enforcement within each EU member state. Typically, each EU member country has its own DPA, which enforces the GDPR and other local or regional privacy laws. DPAs have the power to investigate GDPR violations, issue fines, and order organizations to take corrective actions.<\/p>\n<p>Who has a duty to monitor compliance with the GDPR? DPAs, certainly, but organizations need to monitor data processing and security themselves every day. This includes which third-party vendors like data processors and other partners are handling user data.<\/p>\n<p>Additionally, the technology and legal landscapes are always changing, so organizations need to keep up with those changes. A consent management solution can help to automate and comply with the GDPR\u2019s consent requirements for use of cookies and trackers, but this is a primary responsibility of legal counsel and\/or a privacy expert.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Common GDPR compliance issues and challenges<\/h2>\n<p>Ensuring GDPR compliance can be challenging, especially for small and medium-sized organizations. In many cases, GDPR compliance requires appointment of a Data Protection Officer (DPO). In smaller organizations, this could be someone who already has another job within the company.<\/p>\n<p>Common compliance challenges include:<\/p>\n<ul>\n<li>understanding the organization\u2019s specific compliance responsibilities<\/li>\n<li>obtaining valid user consent<\/li>\n<li>setting up and maintaining a consent management solution<\/li>\n<li>implementing appropriate data security measures<\/li>\n<li>complying with data subject rights requests in a timely manner, particularly when a smaller organization has limited resources available<\/li>\n<li>reporting data breaches to DPAs within 72 hours<\/li>\n<\/ul>\n\n\n<h4>Best practices for GDPR compliance<\/h4>\n<p>To enable and maintain GDPR compliance, organizations should implement data protection and privacy best practices. Some of these actions are regulatory requirements in some countries, but just recommendations for security and compliance elsewhere. It is important to check on GDPR and other local regulations for requirements applicable to your business:<\/p>\n<ul>\n<li>conducting data audits to fully understand data processing activities<\/li>\n<li>conducting data protection impact assessments<\/li>\n<li>implementing data protection policies and procedures<\/li>\n<li>training employees on GDPR compliance<\/li>\n<li>appointing a qualified and well-informed DPO (from outside the company in some cases to access sufficient expertise)<\/li>\n<li>working with trusted third-party vendors and service providers that are GDPR-compliant<\/li>\n<li>using a comprehensive consent management solution online to collect and store valid user consent<\/li>\n<\/ul>\n\n\n<h4>Penalties for GDPR noncompliance<\/h4>\n<p>GDPR enforcement is the process of ensuring that organizations comply with GDPR regulations, like obtaining consent before data processing. It can include activities like investigations of violation reports or audits of a company\u2019s handling of user data, including consent information. Organizations that fail to comply with GDPR requirements, whether failing to obtain valid consent, experiencing a data breach, or other issue, can face significant fines and other penalties.<\/p>\n<p>GDPR fines can range up to \u20ac20 million, or 4% of a company&#8217;s annual global revenue, whichever is higher, for severe or repeated offenses, or \u20ac10 million, or 2% of a company&#8217;s annual global revenue, whichever is higher, for milder or first offenses. DPAs can also order a halt to data processing activities temporarily or permanently, or even deletion of data.<\/p>\n<p>The largest GDPR fine levied to date was against US-based company Meta, formerly Facebook, for US $1.3 billion over handling of user information. EU privacy regulators gave the company five months to stop transferring EU-based users&#8217; data to the United States. The EU and US have been without the EU-US Privacy Shield framework covering international data transfers since July 2020 when it was invalidated by the \u201cSchrems II\u201d judgment.<\/p>\n<p>Penalties represent a failure of data controllers and processors to adequately comply with the GDPR via understanding and securing their data processing, failing to demonstrate legitimate use of their chosen legal basis, and other issues. Data controllers and processors are also responsible to \u201ccure\u201d GDPR violations to ensure issues do not continue to happen, or happen again in the future.<\/p>\n<p>However, unlike under some other data privacy laws, like those in the United States, under the GDPR there is no \u201ccure period\u201d when organizations accused of or found in violation of the law can fix or remediate data privacy issues without facing penalties.<\/p>\n\n\n<h2 class=\"wp-block-heading\">Conclusion and maintaining GDPR compliance<\/h2>\n<p>Data controllers and data processors have specific responsibilities under the GDPR, and organizations should implement best practices to protect data and limit data processing to only what\u2019s necessary. If organizations fail to comply with GDPR requirements, they can face significant fines and other penalties, as well as loss of brand reputation and user trust, which will also impact revenue long-term.<\/p>\n<p>To ensure GDPR compliance, organizations should appoint a DPO if required, implement appropriate data security measures, including limiting data processing and having strong contractual agreements, and work with trusted third-party vendors and service providers.<\/p>\n<p>Organizations should also use comprehensive tools like a <a href=\"https:\/\/www.cookiebot.com\/en\/cookiebot-cmp-features\/\" target=\"_blank\" rel=\"noopener\">Consent Management Platform<\/a> to inform users and securely collect and store user consent data. Ideally you also want a consent solution to integrate with your tech stack and marketing tools to help integrate consent and data privacy compliance across your operations, user engagement touchpoints, and marketing activities.<\/p>\n<p>Do you have concerns about how to achieve GDPR compliance, or whether you are doing it correctly? We want to help you ensure that your organization meets its responsibilities to users and customers. <a href=\"https:\/\/www.cookiebot.com\/en\/cookiebot-cmp-features\/\" target=\"_blank\" rel=\"noopener\">Check out Cookiebot CMP<\/a> now for the most reliable, user-friendly consent management solution.<\/p>\n<p>The <a href=\"https:\/\/wordpress.org\/plugins\/cookiebot\/\" target=\"_blank\" rel=\"noopener\">Cookiebot\u2122 WordPress plugin<\/a> may be the perfect solution for your WordPress site. It\u2019s fast and easy to install, and enables fully automated GDPR compliance and consent management.<\/p>\n<p><em>Usercentrics AS (Cookiebot\u2122) does not provide legal advice, and information is provided for educational purposes only. We always recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.<\/em><\/p>\n\n\n","protected":false},"excerpt":{"rendered":"<p>Data controllers and processors are mainly responsible for ensuring data processing they do is GDPR-compliant. Data protection authorities in EU countries manage GDPR enforcement.<\/p>\n","protected":false},"featured_media":2733,"template":"","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"tags":[],"magazine_issue":[],"magazine_tag":[],"resource_tag":[14,13],"class_list":["post-398","knowledge","type-knowledge","status-publish","has-post-thumbnail","hentry","resource_tag-privacy","resource_tag-regulations"],"acf":[],"yoast_head":"<title>Who is responsible for GDPR compliance?<\/title>\n<meta name=\"description\" content=\"Usercentrics explains who is responsible for GDPR compliance and enforcement, as well as issues and best practices. Find out more today.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Who is responsible for GDPR compliance?\" \/>\n<meta property=\"og:description\" content=\"Usercentrics explains who is responsible for GDPR compliance and enforcement, as well as issues and best practices. Find out more today.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/\" \/>\n<meta property=\"og:site_name\" content=\"Usercentrics - US\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/usercentrics\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-26T13:00:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/usercentrics.com\/wp-content\/uploads\/2021\/10\/GDPR.svg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Who is responsible for GDPR compliance?\" \/>\n<meta name=\"twitter:description\" content=\"Usercentrics explains who is responsible for GDPR compliance and enforcement, as well as issues and best practices. Find out more today.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/usercentrics.com\/wp-content\/uploads\/2021\/10\/GDPR.svg\" \/>\n<meta name=\"twitter:site\" content=\"@usercentrics\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/\",\"url\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/\",\"name\":\"Who is responsible for GDPR compliance?\",\"isPartOf\":{\"@id\":\"https:\/\/usercentrics.com\/us\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2021\/10\/GDPR.svg?v=f7df66640d7839ae\",\"datePublished\":\"2023-07-12T10:00:53+00:00\",\"dateModified\":\"2025-06-26T13:00:08+00:00\",\"description\":\"Usercentrics explains who is responsible for GDPR compliance and enforcement, as well as issues and best practices. Find out more today.\",\"breadcrumb\":{\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/\"}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/#primaryimage\",\"url\":\"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2021\/10\/GDPR.svg?v=f7df66640d7839ae\",\"contentUrl\":\"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2021\/10\/GDPR.svg?v=f7df66640d7839ae\",\"caption\":\"Make sure you comply with the GDPR and the ePrivacy Directive by following these simple steps in our Checklist.\",\"copyrightNotice\":\"\u00a9 Copyright 2026 Usercentrics GmbH\",\"creator\":{\"@type\":\"Organization\",\"name\":\"Usercentrics GmbH\"},\"creditText\":\"Image: Usercentrics GmbH\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Resources\",\"item\":\"https:\/\/usercentrics.com\/us\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Who is responsible for GDPR compliance?\",\"item\":\"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/usercentrics.com\/us\/#website\",\"url\":\"https:\/\/usercentrics.com\/us\/\",\"name\":\"Usercentrics - US\",\"description\":\"Consent Management Platform (CMP) Usercentrics\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/usercentrics.com\/us\/?s={search_term_string}\"}}],\"inLanguage\":\"en-US\"}]}<\/script>","yoast_head_json":{"title":"Who is responsible for GDPR compliance?","description":"Usercentrics explains who is responsible for GDPR compliance and enforcement, as well as issues and best practices. Find out more today.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"Who is responsible for GDPR compliance?","og_description":"Usercentrics explains who is responsible for GDPR compliance and enforcement, as well as issues and best practices. Find out more today.","og_url":"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/","og_site_name":"Usercentrics - US","article_publisher":"https:\/\/www.facebook.com\/usercentrics","article_modified_time":"2025-06-26T13:00:08+00:00","og_image":[{"url":"https:\/\/usercentrics.com\/wp-content\/uploads\/2021\/10\/GDPR.svg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_title":"Who is responsible for GDPR compliance?","twitter_description":"Usercentrics explains who is responsible for GDPR compliance and enforcement, as well as issues and best practices. Find out more today.","twitter_image":"https:\/\/usercentrics.com\/wp-content\/uploads\/2021\/10\/GDPR.svg","twitter_site":"@usercentrics","twitter_misc":{"Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/","url":"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/","name":"Who is responsible for GDPR compliance?","isPartOf":{"@id":"https:\/\/usercentrics.com\/us\/#website"},"primaryImageOfPage":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/#primaryimage"},"image":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/#primaryimage"},"thumbnailUrl":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2021\/10\/GDPR.svg?v=f7df66640d7839ae","datePublished":"2023-07-12T10:00:53+00:00","dateModified":"2025-06-26T13:00:08+00:00","description":"Usercentrics explains who is responsible for GDPR compliance and enforcement, as well as issues and best practices. Find out more today.","breadcrumb":{"@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/"}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/#primaryimage","url":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2021\/10\/GDPR.svg?v=f7df66640d7839ae","contentUrl":"https:\/\/usercentrics.com\/us\/wp-content\/uploads\/sites\/7\/2021\/10\/GDPR.svg?v=f7df66640d7839ae","caption":"Make sure you comply with the GDPR and the ePrivacy Directive by following these simple steps in our Checklist.","copyrightNotice":"\u00a9 Copyright 2026 Usercentrics GmbH","creator":{"@type":"Organization","name":"Usercentrics GmbH"},"creditText":"Image: Usercentrics GmbH"},{"@type":"BreadcrumbList","@id":"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https:\/\/usercentrics.com\/us\/resources\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/usercentrics.com\/us\/knowledge-hub\/"},{"@type":"ListItem","position":3,"name":"Who is responsible for GDPR compliance?","item":"https:\/\/usercentrics.com\/us\/knowledge-hub\/who-is-responsible-for-gdpr-compliance\/"}]},{"@type":"WebSite","@id":"https:\/\/usercentrics.com\/us\/#website","url":"https:\/\/usercentrics.com\/us\/","name":"Usercentrics - US","description":"Consent Management Platform (CMP) Usercentrics","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/usercentrics.com\/us\/?s={search_term_string}"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge\/398","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge"}],"about":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/types\/knowledge"}],"version-history":[{"count":0,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/knowledge\/398\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/media\/2733"}],"wp:attachment":[{"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/media?parent=398"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/tags?post=398"},{"taxonomy":"magazine_issue","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/magazine_issue?post=398"},{"taxonomy":"magazine_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/magazine_tag?post=398"},{"taxonomy":"resource_tag","embeddable":true,"href":"https:\/\/usercentrics.com\/us\/wp-json\/wp\/v2\/resource_tag?post=398"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}