Automate GDPR readiness with adaptive compliance
For any company holding data on people in Europe or the UK, GDPR isn't a certification you pass; it's a standard you have to keep meeting. See how growing teams evidence the security side of it continuously.

GDPR: Prove you protect personal data
Unified by design. Built for the AI era.
Iru AI is designed from the ground up to connect a grid of agents behind the scenes—across identity, endpoint, and compliance. Powered by the Iru Context Model, it understands your users, apps, and devices to act safely, intelligently, and in context across your organization.
Iru combines native endpoint and identity telemetry with continuous evidence collection, making it easier to implement the technical measures Article 32 requires and keep evidencing that they work.
Implement GDPR technical measures, don't just document them
Automate evidence collection
Automatically pull evidence from connected sources via Iru Compliance Automation — Art. 5(2)Answer customer security reviews
Share your security posture through a public-facing portal via Iru Trust Center — Art. 28Encrypt personal data on every device
Apply full-disk encryption and maintain a live record of which devices are protected, via Iru Endpoint Management — Art. 32(1)(a)Control who can access personal data
Phishing-resistant authentication, separated admin accounts, and access removed when people leave, via Iru Workforce Identity — Art. 32(1)(b)Keep software patched
Continuously detect and remediate OS and third-party software risk via Iru Vulnerability Management — Art. 32(1)(b)Detect and contain incidents
Identify and contain threats on managed devices via Iru Endpoint Detection & Response — Art. 32(1)(b)Document a breach inside 72 hours
Produce the timeline of what happened, to which devices, and when — the record Article 33 requires you to keep, via Iru Endpoint Detection & Response — Art. 33(5)Keep testing that your measures work
Continuous evidence that controls are still operating, not just that they were configured, via Iru Compliance Automation — Art. 32(1)(d)Customize GDPR controls for your unique business
Most compliance tools turn frameworks into generic checklists. Iru generates controls that are specific to your organization, in plain language, broken down into sub-tasks.
- Iru AI generates tailored controls, based on your company context and audit details
- You can migrate existing controls over from other products, or upload your own custom control set
- Controls become actions the moment they are created, with suggested owners and due dates

Automate your GDPR evidence collection
For connected and activated sources, Iru can discover and attach relevant artifacts to the supported control actions, reducing manual uploads. And because you can manage your devices and identity within Iru, that data is pulled natively.
- Evidence flows in continuously from supported devices, integrations and systems
- Iru AI helps to identify stale, missing or potentially irrelevant evidence for you to review
- You stay better prepared before fieldwork begins, with fewer fire drills before your engagement

Ensure continuous GDPR audit readiness
Iru's Adaptive Compliance capabilities watch for changes in your organization, and automatically suggest updates to your controls and actions.
- Iru AI regularly checks for changes to your sources, artifacts or company profile
- If a change is detected, a control update recommendation is surfaced for you to review, often within 24 hours
- No changes are made without your approval, and every change is logged for your auditors to review

Turn GDPR preparation into an always-on workflow
Iru's AI-powered compliance solution helps IT, security and GRC teams spend less time on manual compliance work and stay audit-ready all year.
Let your team focus on what matters
Iru replaces fragmented tools with one AI-powered platform, so IT & security spend less time chasing tickets and more time improving the business.
Frequently asked
questions
Get answers to commonly asked questions
Who makes and enforces GDPR?
GDPR was adopted by the European Parliament and the Council as Regulation (EU) 2016/679. Enforcement sits with the independent supervisory authority in each EU member state — Ireland's DPC, France's CNIL, Germany's state authorities, and so on. The European Data Protection Board coordinates between them and issues guidelines on how the Regulation should be applied.
In the UK, the equivalent regulator is the Information Commissioner's Office.
Does GDPR apply to us if we're a US company with no European offices?
Often, yes.
GDPR reaches organisations with no EU establishment where they either offer goods or services to people in the EU, or monitor their behaviour within the EU. The EDPB's guidance sets a meaningful bar — the targeting has to be intentional, and a website merely being reachable from Europe doesn't count. But if you're selling into European markets, running campaigns there, or tracking European users, you're within scope.
It also flows downhill. If you process personal data on behalf of a customer who is in scope, you're pulled in as a processor.
What does GDPR actually require?
More than a page can cover, but the obligations cluster into a few areas. You need a lawful basis for every use of personal data. You have to honour the rights of the people whose data you hold — access, rectification, erasure, portability, objection. You must keep records of your processing activities, assess high-risk processing before you start, control how data moves outside Europe, report certain breaches within tight deadlines, and implement appropriate technical and organisational security measures.
That last one is Article 32, and it's the part your security team owns.
What is Article 32, and why do security teams care about it?
Article 32 is the security obligation. It requires appropriate technical and organisational measures for the risk, and names specific ones: pseudonymisation and encryption of personal data; the ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems; the ability to restore access to personal data in a timely way after an incident; and a process for regularly testing, assessing and evaluating the effectiveness of those measures.
That last requirement is the one people underestimate. Article 32 doesn't ask you to have security measures — it asks you to keep proving they work. The ICO's guidance says such testing "can include virus and malware scanning, vulnerability scanning and penetration testing," and that results and remediation plans should be recorded.
What are the penalties for getting it wrong?
There are two tiers in the EU. The lower tier reaches €10 million or 2% of total worldwide annual turnover, whichever is higher. The upper tier reaches €20 million or 4%, again whichever is higher, and applies to the more serious infringements — including breaches of the core principles and of data subject rights.
The UK mirrors this structure at £8.7 million or 2% and £17.5 million or 4%.
Fines aren't the only exposure. Supervisory authorities can also issue reprimands, order you to bring processing into compliance, and — most disruptively — impose temporary or permanent bans on processing.
Can we get "GDPR certified"?
Not in the way most people mean, and this is worth being precise about because you'll see vendors claim otherwise.
GDPR does provide for approved certification mechanisms, seals and marks, including the European Data Protection Seal. These are real and can be useful evidence. But the Regulation is explicit that certification does not reduce your responsibility for compliance — you remain accountable regardless. And no certificate covers "GDPR" as a whole.
If a supplier tells you they're GDPR certified, ask which mechanism, approved by which authority, covering which processing.
Do we have to report a breach, and how fast?
Personal data breaches must be reported to the supervisory authority within 72 hours of becoming aware of them, where feasible, unless the breach is unlikely to result in a risk to people's rights and freedoms. Where the risk to individuals is high, you also have to tell the affected people without undue delay.
Seventy-two hours is less time than it sounds. The clock starts at awareness, and you need to know what happened, what data was involved, and who was affected — which is a detection and evidence problem before it's a legal one.
What's the difference between EU GDPR and UK GDPR?
They started identical, but are now diverging.
UK GDPR is the retained version of the Regulation, sitting alongside the Data Protection Act 2018 and regulated by the ICO. It was amended by the Data (Use and Access) Act 2025, whose data protection provisions all came into force on 19 June 2026. The DUAA amends rather than replaces UK GDPR, DPA 2018 and PECR, but the ICO is still rolling out updated guidance — publication runs from autumn 2026 into spring 2027.
If you operate in both markets, you're now tracking two rulebooks rather than one.
Does ISO 27001 make us GDPR compliant?
No — but it helps with one part.
An ISO 27001 information security management system is commonly used as evidence toward Article 32, because the two are asking related questions about technical and organisational security measures. What ISO 27001 doesn't touch is most of GDPR: lawful basis, data subject rights, records of processing, impact assessments, and international transfers are outside its scope entirely.
Treat it as useful supporting evidence for the security obligation, not as an answer to the Regulation.
What about transferring personal data to the US?
Transfers outside the EEA need a legal basis under Chapter V. For the US, the EU-U.S. Data Privacy Framework adequacy decision has been in place since July 2023 and allows transfers to participating US organisations without additional safeguards. It's subject to periodic review by the European Commission, with the first review published in October 2024.
Organisations outside the framework typically rely on Standard Contractual Clauses plus a transfer impact assessment.
Can Iru make us GDPR compliant?
No, and be sceptical of anyone who says they can. GDPR compliance isn't a state a vendor can deliver or attest to — it depends on your lawful bases, your processing activities, your contracts, and decisions no platform makes for you.
What Iru does is the security half of Article 32. The platform enforces encryption and access control on the devices and identities that touch personal data, detects and contains incidents, and — because Article 32 asks you to keep testing and evaluating your measures — produces the continuous record that demonstrates those measures are working, not just installed.