€20M or 4% of Turnover
The ceiling for core-principle violations whichever is higher. Security and breach-notification failures under Articles 83(4) draw up to €10M or 2%.
Any organisation holding personal data is in scope. Article 32 wants evidence, not intentions.
Encryption, resilience, recovery and regular testing. Proportionate to risk, not a fixed checklist.
The clock starts on awareness, not a finished investigation. High-risk breaches also require telling the people affected.
Up to €20M or 4% of turnover for core violations. Up to €10M or 2% for security and breach notification failures.
Trusted by 100+ Swedish Kommuner Regions and
EU-Regulated Enterprises Since 2002








GDPR has applied across the EU since 25 May 2018. It reaches beyond company location and one supplier’s breach can trigger notification duties at national scale.
The ceiling for core-principle violations whichever is higher. Security and breach-notification failures under Articles 83(4) draw up to €10M or 2%.
The clock starts the moment you have reasonable certainty a breach occurred not once your investigation is finished.
Article 3 covers any EU-established organisation and any organisation elsewhere that offers goods or services to, or monitors people in the EU.
In August 2025, a ransomware attack on Swedish supplier Miljödata disrupted roughly 200 municipalities and exposed data on 1.5M+ people.
Unlike NIS2, GDPR is not limited to critical infrastructure. Your obligations depend on the personal data you hold and the role you play with it, whatever industry you are in.
Decide how and why personal data is processed and you are a controller. Most Swedish municipalities, SMEs and enterprises sit here for their customer, citizen and employee data and carry the primary accountability under Article 24.
Handle personal data on another organisation’s instructions and you are a processor, like a payroll bureau or a marketing agency running a client’s contact lists. Article 28 makes your security duties binding through the data-processing agreement, not a matter of goodwill.
GDPR reaches past EU borders. Under Article 3(2), offer goods or services to people in the EU or monitor their behaviour online and it applies with no EU establishment required and no money needing to change hands.
Every Article 32 and 33 obligation and the eBuilder Security service that satisfies it directly.
Continuous protection of the systems and services that process personal data.
Dated, recurring evidence that your technical measures actually work, not just that they exist.
Detecting a breach fast enough and documenting it precisely enough to notify within the window.
Coordinated technical and organisational measures with breach-handling readiness built into governance and reporting.
Maps your current state against Article 32’s four security measures and your Article 33 notification readiness. Takes about 20 minutes. The output is board-ready.
No obligation · EU data residency · Results reviewed in a 30-minute call.
See where you stand on security-of-processing and breach notification, scored in plain language.
No spam. EU data residency.
We are not a global firm that adapted generic content for the EU. IMY’s expectations, EU data residency and Schrems II are what we design our services around.
See Full Article 32 CoverageHuman analysts watching every signal, every minute, every day. Logs stay in Sweden.
Industry response times average 1 –24 hours. We measure ours in minutes and escalate threats fast enough to matter.
Signed Monday. MDR live Thursday.
Cybersecurity practice within eBuilder, a Swedish enterprise-software company operating since 2002.
Independently audited and certified to the ISO 27001 information security standard for our SOC.
All services mapped to GDPR Article 32 security-of-processing measures.
All monitoring data, logs and incident records stay within the EU, nothing transferred to a non-adequate third country.
Real questions a board or IT lead asks before engaging on GDPR, answered in two to three sentences.
Yes. GDPR applies based on what personal data you process, not your size or sector. A small business holding customer or employee records is a controller in the same way a large enterprise is, the scale of your measures should match your risk, not your headcount.
Any security incident leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data, not just data theft. A misconfigured system that exposes data or an employee losing an unencrypted laptop can qualify.
From the moment you have a reasonable degree of certainty that a breach involving personal data has occurred, not from when the breach happened and not from when your investigation is complete.
No single service can make an organisation GDPR compliant because compliance also depends on your lawful basis, data-handling practices, contracts and governance. MDR addresses the security-of-processing and breach-detection side of Articles 32 and 33, the legal and organisational parts sit with your DPO or legal counsel.
That depends on your specific processing activities under Article 37 and it’s a legal question, not one we determine for you. What we can help with is the technical security and breach-readiness work that supports whichever governance structure you put in place.
Yes dated, recurring test and remediation evidence is specifically what Article 32(1)(d) calls for. Both services produce reports and verified-closure records that document ongoing testing of your technical measures.
Book a free 30-minute security briefing with a Sweden-based advisor. We’ll tell you exactly where your Article 32 measures and breach-notification readiness stand, with no obligation.
Book a 30-Minute Security Briefing