Compliance framework

What is GDPR?

The GDPR is the European Union's comprehensive data protection law that governs the processing of personal data of EU residents, regardless of where the processing organization is located. Non-compliance carries fines of up to 4% of global annual turnover.

For vendor risk purposes, GDPR requires that data controllers only engage processors who provide sufficient guarantees of GDPR compliance. This typically means a Data Processing Agreement (DPA), evidence of sub-processor management, Standard Contractual Clauses for international transfers, and a documented lawful basis for each processing activity. TrustVendor monitors DPA availability and subprocessor additions that may affect transfer compliance.

Which vendors hold GDPR?

Search the TrustVendor vendor graph to see current certification status, evidence age, and expiry runway across all your vendors.

Common questions about GDPR

Which vendors hold GDPR certification?
Search the TrustVendor vendor graph to see which vendors in your portfolio hold current GDPR certification, when it was last verified, and how long until it expires. Certifications are tracked continuously and alerts fire when evidence ages past its half-life.
How often does GDPR certification need to be renewed?
Renewal frequency depends on the framework. SOC 2 Type II reports typically cover a 12-month audit period and should be requested annually. ISO 27001 certificates are valid for three years with annual surveillance audits. FedRAMP authorizations require annual assessment. TrustVendor tracks expiry dates and alerts you 90, 60, and 30 days before lapse.
Can I verify a vendor's GDPR report myself?
For certifications that produce a published artifact (ISO 27001 certificate, FedRAMP Marketplace listing), you can verify directly with the certifying body. For SOC 2, the report is issued by the auditing CPA firm and should be shared directly by the vendor under NDA. TrustVendor stores a sha256-hashed snapshot of every artifact it processes — you can verify the hash client-side using standard tooling.

Related frameworks

ISO 27018ISO 27001HIPAA