Skip to content

Compliance matrix

General Data Protection Regulation

European Union / EEA (extraterritorial) · Updated 2026-07-19

Applies to: Any organization processing personal data of people in the EU/EEA, wherever the organization is based.

Vendor certification snapshot

GDPR readiness status across the 48 vendors we track, read live from each profile. This field reflects vendor-stated readiness, not an independent audit.

47

Certified

1

Partial

0

Not stated

Status is one signal, not a guarantee. Always confirm current certification scope directly with the vendor.

Requirements mapped to CIAM

Lawful basis and consent (Art. 6-7)

Where consent is the basis, it must be freely given, specific, informed, and as easy to withdraw as to give.

CIAM controls

  • Granular, purpose-specific consent capture
  • Preference center to withdraw consent
  • Consent records with timestamp and version

Evidence

  • Consent logs with purpose, timestamp, and version
  • Screenshots of the consent and preference UI

Ask the vendor

  • Do you support purpose-specific, revocable consent with an audit trail?
  • Is there a preference center, or do you integrate with a CMP?

Data subject rights (Art. 15-20)

Users can request access, correction, erasure ('right to be forgotten'), and portability of their identity data.

CIAM controls

  • Self-service profile access and correction
  • Account deletion and data export
  • Machine-readable export for portability

Evidence

  • DSAR fulfillment logs and turnaround times
  • Export file format samples

Ask the vendor

  • Can end users self-serve deletion and export, or is it manual?
  • What is the data export format, and does it include all profile data?

Security of processing (Art. 32)

You must apply appropriate technical measures, which for identity means strong authentication and encryption.

CIAM controls

  • MFA and phishing-resistant authentication
  • Encryption in transit and at rest
  • Breach detection and account-takeover defenses

Evidence

  • Authentication and encryption configuration
  • Incident detection and response records

Ask the vendor

  • What authentication and encryption controls are available by default?
  • How quickly are breaches detected and surfaced to us?

International transfers and residency (Ch. V)

Transferring EU personal data outside the EEA requires a valid mechanism, and residency controls reduce exposure.

CIAM controls

  • EU data residency / regional hosting
  • Standard Contractual Clauses in the DPA

Evidence

  • Data Processing Agreement with SCCs
  • Hosting region configuration

Ask the vendor

  • Do you offer EU data residency, and where is identity data stored?
  • Are SCCs included in your DPA?

Take this into procurement

Turn these requirements into vendor questions.

The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.

Go deeper

Where it bites hardest

FAQ

Does GDPR require consent for all processing?
No. Consent is one of six lawful bases. Much identity processing relies on contract or legitimate interests instead. Consent is required where you rely on it (e.g. marketing), and there it must be granular and revocable.
What CIAM features matter most for the right to be forgotten?
Self-service account deletion, complete data export, and audit logs that prove the deletion happened. Confirm the vendor deletes derived and backup copies within a defined window, not just the primary record.

Source

Regulation (EU) 2016/679 (official text, EUR-Lex)

This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.