The Three Key Domains of the GDPR Explained

There are three keys areas organisations should know about concerning the EU GDPR legislation. GDPR focuses on the core areas of data governance, data management, and data transparency.

Three Core Domains of the EU GDPR.jpg

In this blog, we will review the three key GDPR domains will aim to protect individuals and enforce tougher measures on organisations that handle personal data.



Data governance is how data controllers exercise their control and compliance over their data assets. This area is important to ensure you are maintaining compliance while navigating GDPR.

  • Breach Notification: Any data breaches an organisation may encounter must be communicated within 72 hours and to any affected data subjects and the ‘controllers’ of the data without undue delay if the breach may result in a high risk to rights and freedoms.
  • Privacy by Design: With this provision, businesses must begin to consider the nature of data privacy at the onset of starting a project as well as throughout the data processing lifecycle. A company will need to design for privacy during any data control or processing phase.
  • Vendor Management: Vendors and third parties will face the regulatory scrutiny of GDPR as well. Any processor or controller of data must keep details records of any processing activities done with data.


 Take a look at this NEW infographic on how you can prepare for the EU GDPR. 



Data management is how data controllers and processors will handle the processing activities. It’s important that the data is managed to GDPR compliance in the following areas.

  • Data Erasure (the right to be forgotten): Individuals can now request the deletion of personal data even if the data is public. In addition, individuals may also request that personal data not be processed in particular circumstances which can be found here.
  •  Data Processing: Organisations must maintain internal records of all data processing activities under GDPR. The information recorded will need to include the name and details of your organisation, purposes of the data processing, description of categories of individuals and personal data, recipients of personal data, the details of data transfers, and data retention schedules. Organisations may want to consider automated cryptographic protection controls for transparent automatic email and attachment encryption.
  • Data Transfers: Under GDPR, businesses will be prohibited from transferring data from outside the EU to a third country that does not have adequate data protection laws. The European Commission approves countries with “satisfactory” data protection laws and maintains a list of “approved countries” here.
  • Data Protection Officer (DPO): Any data controller processing more than 5000 data subject records in a 12-month period are required to have a Data Protection Officer. A DPO will monitor your GPDR compliance and conduct data protection assessments as well as train staff on overall policies. A DPO can support one company or a group of companies or a group of public authorities under GPDR. Your DPO must have the necessary skill sets to advise the organisation and employees to comply with GPDR and other data protection laws. It’s worth noting, an organisation does not need to hire new personnel to fill the DPO, they simply need to have a qualified and authorised individual assigned to the role as DPO.

 Interested in GDPR Assessment and Consulting? Learn more about CIPHER's GDPR Services. 




Data subjects will have additional rights under GDPR. Data controllers will need to be mindful of the following areas under GDPR.

  • Consent: Organisations that are processing personal data must be able to demonstrate that the person with whom the data relates to has given their consent to use that data. Individuals also have the right to withdraw their consent at any time, and the company must make it easy for an individual to withdraw their consent.
  • Data Portability: Under GDPR, data subjects in the EU can obtain a copy of the data from the service provider and request to take their data. Under GDPR, data subjects will be able to move, copy or transfer data easily from one service provider to another without hindrance to usability.
  • Privacy Policies: Companies must provide disclosures about data processing to data subjects, and the rights of customers must be easily interpretable and easily accessible.

It is critical for organisations to prepare for the implementation of the EU GDPR with a thorough and planned procedure. GDPR impacts the technology, people, and processes required to address the readiness of data privacy. You will need to start planning for your customized approach to GDPR compliance as early as possible, ensuring consistency throughout your organisation.

EU GDPR Whitepaper Three Primary Domains of GDPR

Did you enjoy this blog article? Share it with your friends or comment below.


Founded in 2000, CIPHER is a global cybersecurity company that delivers highly accredited Managed Security Services holding ISO 20000 and ISO 27001, SOC I and SOC II, PCI QSA and PCI ASV certifications. We have received many awards including Best MSSP from Frost & Sullivan for the past five years. These services are supported by the best in class security intelligence lab: CIPHER Intelligence. Our offices are located in North America, Europe, and Latin America with 24×7×365 Security Operations Centers and R&D laboratories, complemented by strategic partners around the globe. 

Our clients consist of Fortune 500 companies, world-renowned enterprises, and government agencies with countless success stories. CIPHER provides organizations with proprietary technologies and specialized services to defend against advanced threats while managing risk and ensuring compliance through innovative solutions.

Subscribe to Us!

Recent Security Posts


Twitter Feed