All articles
ComplianceData & privacy

Privacy Laws and the Frameworks That Prove Them: GDPR and Beyond

GDPR turned "we respect privacy" into "prove it." This post is about the second half of that sentence: the frameworks and controls that turn a privacy promise into audit-ready evidence.

Ilke Tosunoğlu
Ilke TosunoğluMay 28, 20265 min readUpdated July 20, 2026
GDPR at the centre with spokes to ISO 27701, ISO 27001 and the NIST Privacy Framework, plus a health-sector tag for the EHDS.

Part of the pillar series Sovereignty You Can Actually Operate.

This is practical guidance for compliance teams, not legal advice. Current as of July 2026.

Why GDPR exists

Before 2018, Europe had 28 national interpretations of a 1995 directive and a digital economy running on personal data. GDPR (Regulation (EU) 2016/679) replaced that patchwork with one directly-applicable law: harmonized rules, enforceable individual rights, and, its defining move, the accountability principle (Article 5(2)). You must be able to demonstrate compliance, not merely assert it. In force 24 May 2016, applicable from 25 May 2018 (EUR-Lex).

The obligations that generate real, recurring work (and the same pattern shows up in the overlap dividend):

GDPR obligation Article What it demands operationally
Lawful basis Art. 6 (Art. 9 special data) Documented basis for each processing activity
Accountability Art. 5(2), 24 Records that demonstrate compliance
Data-subject rights Arts. 12–22 Processes to handle access, erasure, portability
Records of processing Art. 30 A maintained RoPA
DPIAs Art. 35 Impact assessments for high-risk processing
Security of processing Art. 32 Technical + organizational security controls
Breach notification Art. 33 Notify the authority within 72 hours
Transfers Ch. V A valid mechanism for extra-EU transfers

Maximum fine: €20M or 4% of global annual turnover (Art. 83). Cumulative GDPR fines now exceed €6 billion, the largest being €1.2 billion against Meta (2023) for unlawful EU–US transfers (Enforcement Tracker).

Two things people get wrong about the privacy landscape

  • ePrivacy is not a coming regulation. The 2002 ePrivacy Directive (the "cookie law") is still in force and applied through national law. The proposed ePrivacy Regulation was withdrawn in 2025. Don't plan around it.
  • Health data has its own overlay, on a long fuse. The European Health Data Space (Regulation (EU) 2025/327) entered into force 26 March 2025, but its major obligations apply from 2029 (and 2031 for further data categories). For health organizations it's a roadmap, not an immediate scramble.

The frameworks that prove privacy compliance

GDPR tells you what. These frameworks are how you demonstrate it, and one of them changed materially in 2025.

Framework What it is Why it proves privacy
ISO/IEC 27701:2025 Privacy information management system, now a standalone standard (previously an extension of ISO 27001) The cleanest tool to demonstrate GDPR accountability; retains a control-to-GDPR-article mapping. Lead with this.
ISO/IEC 27001:2022 Information-security management system Evidences "security of processing" (Art. 32) via Annex A controls
NIST Privacy Framework Voluntary, outcome-based privacy risk management Supports DPIAs (Art. 35) and accountability (note: v1.1 is still a draft; v1.0 is the current published version)
ISO/IEC 29100:2024 Privacy terminology + principles Common vocabulary aligning with GDPR Art. 5

Sources: ISO/IEC 27701:2025; NIST Privacy Framework.

The worked example that ties the series together: GDPR's accountability obligation (Art. 5(2)) → an ISO 27701 control for documented processing and roles → the evidence artifact (your RoPA, DPIA, and access logs). One obligation, one control, one piece of evidence, reusable the next time an auditor asks.

GDPR Art. 5(2)“demonstrate compliance”
ISO 27701 controldocumented processing & roles
EvidenceRoPA · DPIA · access logs

Where Soveryne fits

Privacy is the domain where "demonstrate" bites hardest, and where the two Soveryne jobs are clearest.

When a data-subject request lands, or a transfer question comes up, or you're not sure whether a processing activity needs a DPIA, that's coverage intelligence: Counsel answers from GDPR and its guidance, and from your own uploaded policies and records, with every claim cited, so a DPO gets a grounded answer in seconds instead of re-reading the regulation. Its knowledge base already includes GDPR alongside NIS2, DORA, ISO/IEC and NIST.

When the auditor asks you to prove accountability, that's proof of implementation: Command maps your GDPR obligations to ISO/IEC 27701 and 27001 controls, tracks the evidence for each, and, because privacy controls overlap heavily with security controls, lets that same evidence count toward your NIS2 and ISO 27001 posture at the same time. Demonstrating GDPR compliance stops being a separate project and becomes part of one evidenced control library. And it all runs on EU-sovereign infrastructure, which, for a privacy program, is the point.

FAQ

Which framework best demonstrates GDPR compliance? ISO/IEC 27701 (now a standalone privacy information management system standard that maps its controls to GDPR articles) is the strongest single tool, layered on ISO/IEC 27001 for the security side.

Is ISO 27701 the same as GDPR? No. GDPR is the law; ISO 27701 is a certifiable management system that helps you demonstrate you meet it. Certification is strong evidence but not a legal safe harbor.

Do I still need to worry about ePrivacy / cookies? Yes: the 2002 ePrivacy Directive is still in force via national law. But the proposed ePrivacy Regulation was withdrawn in 2025, so don't plan around it.

When does the European Health Data Space start applying? It entered into force in March 2025, but its major obligations apply from 2029 (and 2031 for further data categories), a long runway for health-sector organizations.


Privacy compliance is provable, not just promised. Get cited answers on GDPR with Counsel, and map obligations to evidenced ISO 27701 controls with Command.

Sources