GDPR · EU 2016/679 Dataskyddsförordningen

GDPR Applies to You
Could You Prove It in 72 Hours?

Any organisation holding personal data is in scope. Article 32 wants evidence, not intentions.

Article 32: Four Security Measures

Encryption, resilience, recovery and regular testing. Proportionate to risk, not a fixed checklist.

Articles 33: 72-Hour Notification

The clock starts on awareness, not a finished investigation. High-risk breaches also require telling the people affected.

Article 83: Two Fine Tiers

Up to €20M or 4% of turnover for core violations. Up to €10M or 2% for security and breach notification failures.

Trusted by 100+ Swedish Kommuner Regions and
EU-Regulated Enterprises Since 2002

Stakes

Why Acting Now is Not Optional

GDPR has applied across the EU since 25 May 2018. It reaches beyond company location and one supplier’s breach can trigger notification duties at national scale.

Scope

GDPR Follows the Data, Not the Sector

Unlike NIS2, GDPR is not limited to critical infrastructure. Your obligations depend on the personal data you hold and the role you play with it, whatever industry you are in.

Controller: You Decide How and Why

Decide how and why personal data is processed and you are a controller. Most Swedish municipalities, SMEs and enterprises sit here for their customer, citizen and employee data and carry the primary accountability under Article 24.

Processor: You Act on Someone Else’s Behalf

Handle personal data on another organisation’s instructions and you are a processor, like a payroll bureau or a marketing agency running a client’s contact lists. Article 28 makes your security duties binding through the data-processing agreement, not a matter of goodwill.

In Scope Without an EU Base

GDPR reaches past EU borders. Under Article 3(2), offer goods or services to people in the EU or monitor their behaviour online and it applies with no EU establishment required and no money needing to change hands.

GDPR · Articles 32–34

What the Law Requires and How eBuilder Helps

Every Article 32 and 33 obligation and the eBuilder Security service that satisfies it directly.

Art. 32(1)(b)

Ongoing Confidentiality, Integrity & Availability

Continuous protection of the systems and services that process personal data.

Managed by MDR & SOC 24/7
Art. 32(1)(d)

Regular Testing & Evaluation

Dated, recurring evidence that your technical measures actually work, not just that they exist.

Art. 33

72-Hour Notification to IMY

Detecting a breach fast enough and documenting it precisely enough to notify within the window.

Managed by MDR & SOC 24/7
Art. 32 & 33 (Governance)

A Governed, Board-Visible Programme

Coordinated technical and organisational measures with breach-handling readiness built into governance and reporting.

Managed by CISO as a Service
GDPR · Free Readiness Score

See Exactly Where You Stand on Article 32 and Breach Readiness

Maps your current state against Article 32’s four security measures and your Article 33 notification readiness. Takes about 20 minutes. The output is board-ready.

  • Your score against each Article 32(1) measure, not a generic checklist.
  • Your highest-priority gap ranked by how it would look to IMY on review.
  • A board-ready summary written in plain language, not legal text.

No obligation · EU data residency · Results reviewed in a 30-minute call.

GDPR Article 32 Readiness Score

See where you stand on security-of-processing and breach notification, scored in plain language.

No spam. EU data residency.

Why eBuilder

Sweden-Based Security Built for This Regulation

We are not a global firm that adapted generic content for the EU. IMY’s expectations, EU data residency and Schrems II are what we design our services around.

See Full Article 32 Coverage

Sweden-Based
24/7 SOC

Human analysts watching every signal, every minute, every day. Logs stay in Sweden.

3-minute
Median Response

Industry response times average 1 –24 hours. We measure ours in minutes and escalate threats fast enough to matter.

Onboard in Days,
Not Quarters

Signed Monday. MDR live Thursday.

20+ Years in SaaS

Cybersecurity practice within eBuilder, a Swedish enterprise-software company operating since 2002.

ISO 27001 Certified

Independently audited and certified to the ISO 27001 information security standard for our SOC.

ISO 27001 certification mark

Article 32 Aligned

All services mapped to GDPR Article 32 security-of-processing measures.

Schrems II
Compliant

All monitoring data, logs and incident records stay within the EU, nothing transferred to a non-adequate third country.

Questions

GDPR Compliance, Answered

Real questions a board or IT lead asks before engaging on GDPR, answered in two to three sentences.

Does GDPR apply to our municipality or SME even though we’re small?

Yes. GDPR applies based on what personal data you process, not your size or sector. A small business holding customer or employee records is a controller in the same way a large enterprise is, the scale of your measures should match your risk, not your headcount.

What actually counts as a “personal data breach”?

Any security incident leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data, not just data theft. A misconfigured system that exposes data or an employee losing an unencrypted laptop can qualify.

When does the 72-hour clock start?

From the moment you have a reasonable degree of certainty that a breach involving personal data has occurred, not from when the breach happened and not from when your investigation is complete.

Does using eBuilder Security’s MDR make us GDPR compliant?

No single service can make an organisation GDPR compliant because compliance also depends on your lawful basis, data-handling practices, contracts and governance. MDR addresses the security-of-processing and breach-detection side of Articles 32 and 33, the legal and organisational parts sit with your DPO or legal counsel.

Do we need a Data Protection Officer?

That depends on your specific processing activities under Article 37 and it’s a legal question, not one we determine for you. What we can help with is the technical security and breach-readiness work that supports whichever governance structure you put in place.

Can a penetration test or vulnerability management report be used as evidence for Article 32(1)(d)?

Yes dated, recurring test and remediation evidence is specifically what Article 32(1)(d) calls for. Both services produce reports and verified-closure records that document ongoing testing of your technical measures.

Act Now

IMY’s 72-Hour Clock Doesn’t Wait for a Convenient Time.
Let’s Get Your Evidence Ready.

Book a free 30-minute security briefing with a Sweden-based advisor. We’ll tell you exactly where your Article 32 measures and breach-notification readiness stand, with no obligation.

Book a 30-Minute Security Briefing
No commitment required