Skip to content
Menu

Data privacy · European Union

GDPR — General Data Protection Regulation (EU) 2016/679 Compliance

GDPR — General Data Protection Regulation (EU) 2016/679 is issued by European Data Protection Board and has applied since 2018-05-25. It applies to products sold in EU, EEA. Below: what it covers, which products trigger it, the documents a supplier must provide, and how Complyra checks a product against it.

Authority
European Data Protection Board
Jurisdiction
European Union
Regions
EU, EEA
Effective
2018-05-25
Evidence renewal
every 365 days
Official source
https://gdpr.eu/

What GDPR — General Data Protection Regulation (EU) 2016/679 covers

GDPR — General Data Protection Regulation (EU) 2016/679 is a data privacy requirement in European Union. In Complyra's dataset it is triggered by products in the following categories and by product descriptions that mention the keywords listed below.

Product categories affected

  • electronics

Keywords that trigger a check

  • data
  • personal data
  • privacy
  • GDPR
  • software
  • SaaS
  • app
  • IoT
  • connected device
  • tracking
  • cookies

Who it applies to

Buyers importing or placing the affected products on the market in EU, EEA, and the suppliers who manufacture or distribute them. In a procurement workflow the buyer is responsible for obtaining the evidence listed below from the supplier before the order is placed.

Consequences of non-compliance recorded in the dataset: Up to €20M or 4% global annual turnover (whichever higher)

Supplier requirements and compliance evidence

Documents a supplier should be able to provide for products in scope. Ask for these in the RFQ rather than after the goods ship.

Document
Privacy Policy (GDPR compliant)
Data Processing Agreement (DPA) with processors
Records of Processing Activities (RoPA)
Data Protection Impact Assessment (DPIA) if high-risk
DPO appointment (if required)
Cookie consent mechanism

Certification types recorded for this regulation

  • privacy policy
  • dpo appointed
  • data processing agreement

How Complyra checks GDPR — General Data Protection Regulation (EU) 2016/679

When a product is searched or sourced in Complyra, its category and description are matched against the trigger categories and keywords above. If GDPR — General Data Protection Regulation (EU) 2016/679 applies, the product and its supplier are checked against the materials, substance limits and required documents recorded for the regulation, and the result is shown alongside the supplier match, before an RFQ is generated.

Suppliers on Complyra register and upload certifications that are reviewed by an administrator; see supplier compliance for how that review works and supplier sourcing for how compliant suppliers are found and matched.

Complyra checks product and supplier information against regulatory requirements to support procurement decisions. It does not issue certifications or guarantee legal compliance; final responsibility for compliance remains with the buyer and supplier.

Related regulations

Check a product against GDPR — General Data Protection Regulation (EU) 2016/679

Describe the product and destination market. Complyra identifies whether this regulation applies and which documents to request from the supplier.