# GDPR Requirements | Secureframe

> Learn the key requirements of GDPR, including data subject rights, data privacy principles, and data transfer requirements.

canonical: https://secureframe.com/hub/gdpr/report

General Data Protection Regulation (GDPR) is widely considered the most significant data privacy laws in recent history, with major implications for how companies can handle European Union residents’ personal data.

Yet, [70% of law practitioners](https://aboutblaw.com/YCU) said the complexity of GDPR requirements is one of the top challenges they face in implementing and maintaining GDPR compliance at their organizations.

The 88-page law is complex, with nearly 100 articles and 173 recitals. To help you get a clear understanding of the data privacy law’s requirements and guidance for how to comply, we are going to focus on the key areas below.

## Intermediate: I’m preparing for GDPR compliance

**So you’re in prep mode for GDPR compliance. **

[Getting GDPR compliant](https://secureframe.com/blog/gdpr-announcement) is important for avoiding fines and, more importantly, gaining customer trust and growing your business. Knowing what to expect can make it easier to manage the entire compliance process and set expectations with internal stakeholders. 

![](https://prismic-io.s3.amazonaws.com/secureframe-com/3872c5d3-0cc1-4513-a64f-be81177ab9a7_GDPR+hub+intermediate.png)

## What are GDPR compliance requirements?

[Any organization that falls within the scope of GDPR](https://secureframe.com/hub/gdpr/who-does-gdpr-apply-to) must satisfy the requirements for properly controlling and/or processing personal data of EU residents.

These requirements can include:

- Providing a way for EU residents to know that their personal data is being collected and/or processed
- Allowing EU residents to opt-out of certain personal data processing activities, request disclosure of their collected personal information in a portable format, and request that their personal data be forgotten
- Documenting what personal information is collected, how it is processed, who has access to it, and the legal justification for collecting it
- Encrypting, anonymizing, and/or pseudonymizing personal information 
- Establishing and maintaining information security policies and procedures
- Training personnel on GDPR requirements
- Signing data processing agreements with third parties that process personal data
- Establishing formal personnel roles around GDPR compliance and data protection, like hiring a Data Protection Officer (DPO) if necessary

## Streamline GDPR Compliance With Automation 

[Compliance automation software](https://secureframe.com/frameworks/gdpr) cuts out hundreds of hours of legwork when you’re preparing for GDPR compliance. Look for software that integrates with your tech stack to automate evidence collection and continuously monitor your infrastructure for vulnerabilities. Vendor management, employee onboarding, and expert support throughout the audit are also key features to look for.
