Privacy Laws and the Frameworks That Prove Them: GDPR and Beyond
GDPR turned "we respect privacy" into "prove it." This post is about the second half of that sentence: the frameworks and controls that turn a privacy promise into audit-ready evidence.

Part of the pillar series Sovereignty You Can Actually Operate.
This is practical guidance for compliance teams, not legal advice. Current as of July 2026.
Why GDPR exists
Before 2018, Europe had 28 national interpretations of a 1995 directive and a digital economy running on personal data. GDPR (Regulation (EU) 2016/679) replaced that patchwork with one directly-applicable law: harmonized rules, enforceable individual rights, and, its defining move, the accountability principle (Article 5(2)). You must be able to demonstrate compliance, not merely assert it. In force 24 May 2016, applicable from 25 May 2018 (EUR-Lex).
The obligations that generate real, recurring work (and the same pattern shows up in the overlap dividend):
| GDPR obligation | Article | What it demands operationally |
|---|---|---|
| Lawful basis | Art. 6 (Art. 9 special data) | Documented basis for each processing activity |
| Accountability | Art. 5(2), 24 | Records that demonstrate compliance |
| Data-subject rights | Arts. 12–22 | Processes to handle access, erasure, portability |
| Records of processing | Art. 30 | A maintained RoPA |
| DPIAs | Art. 35 | Impact assessments for high-risk processing |
| Security of processing | Art. 32 | Technical + organizational security controls |
| Breach notification | Art. 33 | Notify the authority within 72 hours |
| Transfers | Ch. V | A valid mechanism for extra-EU transfers |
Maximum fine: €20M or 4% of global annual turnover (Art. 83). Cumulative GDPR fines now exceed €6 billion, the largest being €1.2 billion against Meta (2023) for unlawful EU–US transfers (Enforcement Tracker).
Two things people get wrong about the privacy landscape
- ePrivacy is not a coming regulation. The 2002 ePrivacy Directive (the "cookie law") is still in force and applied through national law. The proposed ePrivacy Regulation was withdrawn in 2025. Don't plan around it.
- Health data has its own overlay, on a long fuse. The European Health Data Space (Regulation (EU) 2025/327) entered into force 26 March 2025, but its major obligations apply from 2029 (and 2031 for further data categories). For health organizations it's a roadmap, not an immediate scramble.
The frameworks that prove privacy compliance
GDPR tells you what. These frameworks are how you demonstrate it, and one of them changed materially in 2025.
| Framework | What it is | Why it proves privacy |
|---|---|---|
| ISO/IEC 27701:2025 | Privacy information management system, now a standalone standard (previously an extension of ISO 27001) | The cleanest tool to demonstrate GDPR accountability; retains a control-to-GDPR-article mapping. Lead with this. |
| ISO/IEC 27001:2022 | Information-security management system | Evidences "security of processing" (Art. 32) via Annex A controls |
| NIST Privacy Framework | Voluntary, outcome-based privacy risk management | Supports DPIAs (Art. 35) and accountability (note: v1.1 is still a draft; v1.0 is the current published version) |
| ISO/IEC 29100:2024 | Privacy terminology + principles | Common vocabulary aligning with GDPR Art. 5 |
Sources: ISO/IEC 27701:2025; NIST Privacy Framework.
The worked example that ties the series together: GDPR's accountability obligation (Art. 5(2)) → an ISO 27701 control for documented processing and roles → the evidence artifact (your RoPA, DPIA, and access logs). One obligation, one control, one piece of evidence, reusable the next time an auditor asks.
Where Soveryne fits
Privacy is the domain where "demonstrate" bites hardest, and where the two Soveryne jobs are clearest.
When a data-subject request lands, or a transfer question comes up, or you're not sure whether a processing activity needs a DPIA, that's coverage intelligence: Counsel answers from GDPR and its guidance, and from your own uploaded policies and records, with every claim cited, so a DPO gets a grounded answer in seconds instead of re-reading the regulation. Its knowledge base already includes GDPR alongside NIS2, DORA, ISO/IEC and NIST.
When the auditor asks you to prove accountability, that's proof of implementation: Command maps your GDPR obligations to ISO/IEC 27701 and 27001 controls, tracks the evidence for each, and, because privacy controls overlap heavily with security controls, lets that same evidence count toward your NIS2 and ISO 27001 posture at the same time. Demonstrating GDPR compliance stops being a separate project and becomes part of one evidenced control library. And it all runs on EU-sovereign infrastructure, which, for a privacy program, is the point.
FAQ
Which framework best demonstrates GDPR compliance? ISO/IEC 27701 (now a standalone privacy information management system standard that maps its controls to GDPR articles) is the strongest single tool, layered on ISO/IEC 27001 for the security side.
Is ISO 27701 the same as GDPR? No. GDPR is the law; ISO 27701 is a certifiable management system that helps you demonstrate you meet it. Certification is strong evidence but not a legal safe harbor.
Do I still need to worry about ePrivacy / cookies? Yes: the 2002 ePrivacy Directive is still in force via national law. But the proposed ePrivacy Regulation was withdrawn in 2025, so don't plan around it.
When does the European Health Data Space start applying? It entered into force in March 2025, but its major obligations apply from 2029 (and 2031 for further data categories), a long runway for health-sector organizations.
Privacy compliance is provable, not just promised. Get cited answers on GDPR with Counsel, and map obligations to evidenced ISO 27701 controls with Command.
Sources
- GDPR (EUR-Lex): https://eur-lex.europa.eu/eli/reg/2016/679/oj
- European Health Data Space (Regulation 2025/327): https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en
- ISO/IEC 27701:2025: https://www.iso.org/standard/27701
- NIST Privacy Framework: https://www.nist.gov/privacy-framework
- GDPR Enforcement Tracker: https://www.enforcementtracker.com/statistics




