Back to Webinars

What You Need to Know About GDPR Compliance

Date Aired: July 29, 2025

What You’ll Learn

GDPR resources are most useful when they clarify how legal requirements affect the systems and processes that handle personal data. This webinar explains how to identify the appropriate legal basis for processing, obtain valid consent, respond to privacy rights requests, manage controller and processor responsibilities, and transfer EU personal data using the required safeguards.

Key Takeaways:

  • GDPR can apply to organizations outside the European Union when they offer goods or services to EU residents or monitor their behavior. A US headquarters does not remove the obligation if your website, analytics, advertising, or customer systems process EU personal data.
  • Personal data includes more than names and email addresses. IP addresses, account activity, analytics data, advertising interactions, and other information connected to an identifiable person can all fall within scope.
  • Every processing activity needs an appropriate legal basis. Consent, contract, legal obligation, vital interests, public interest, and legitimate interests serve different purposes and cannot be substituted for one another because one is more convenient.
  • Valid consent requires a specific, informed, freely given, and affirmative choice. Pre-checked boxes, bundled agreements, assumed consent, and cookie banners that treat continued browsing as approval do not meet that standard.
  • Data collection must remain limited to the purpose disclosed to the individual. Collecting additional information for possible future use, retaining it indefinitely, or reusing it for a new purpose can conflict with GDPR’s requirements for minimization, purpose limitation, and storage limitation.
  • Privacy rights create operational requirements across your systems. Access, correction, erasure, restriction, portability, objection, and automated decision-making requests are only manageable when teams know where personal data resides and how each system must be updated.
  • Data subject requests need a defined process before the first request arrives. Organizations should assign an owner, maintain a data map, create request-specific checklists, verify the requester’s identity, prepare response templates, and track the applicable deadline.
  • Technical and organizational measures must reflect the sensitivity of the data and the risks surrounding it. Encryption, backups, security testing, employee training, access controls, vendor oversight, and documented procedures all contribute to demonstrating appropriate protection.
  • Controller and processor roles determine who decides how data is used and who acts on those instructions. Contracts and data processing agreements must clearly define those responsibilities, including confidentiality, security, and limits on further use.
  • Transferring EU personal data outside the region requires an approved mechanism. Adequacy decisions, standard contractual clauses, the EU-US Data Privacy Framework, and binding corporate rules provide different ways to preserve legal protections across borders.
  • GDPR compliance does not automatically satisfy other privacy laws. US state laws, UK requirements, Canadian rules, Australian law, contractual obligations, and emerging AI regulations can impose different rights, disclosures, timelines, and restrictions.
  • GDPR still applies when personal data is used in AI systems. The legal questions remain familiar, including whether the data was collected lawfully, how it is used, whether automated decisions affect individuals, and whether the organization can meet deletion or access obligations once that data enters a training set.
View Transcript

Who Should Watch This Webinar?

  • CISOs
  • CTOs
  • Privacy officers
  • Security architects
  • Compliance leaders
  • Product leaders
  • Engineering leaders
  • Legal teams

Topics Discussed:

  • GDPR scope and applicability
  • Personal data and processing
  • Legal bases for processing
  • Consent requirements
  • Data minimization and retention
  • Privacy notices and transparency
  • Data subject rights
  • Access and identity verification
  • Erasure and restriction
  • Data portability
  • Automated decision-making
  • Data request procedures
  • Data mapping and response templates
  • Technical and organizational measures
  • Controllers and processors
  • Vendor agreements
  • International data transfers
  • GDPR resources and compliance planning
  • GDPR and other privacy laws
  • GDPR and AI systems

Speakers:

Donata Stroink-Skillrud Photo
Donata Stroink-Skillrud
President, Termageddon
Donata Stroink-Skillrud is a data privacy attorney, Certified Information Privacy Professional, and a practitioner who translates dense regulatory frameworks into something businesses can actually act on. She chairs the American Bar Association's ePrivacy Committee, serves on its Cybersecurity Legal Task Force, and is a Fellow at the American Bar Foundation. She's the creator and host of the Privacy Lawls podcast and has spoken internationally, including at Hong Kong Legal Week. Her practice covers the full span of where law, technology, and business meet. She's equally comfortable explaining GDPR compliance to a developer audience as she is advising legal teams on how to build auto-updating privacy frameworks.
Featured Capability
Security
learn more
Sign-in screen with a breached-password alert warning that the password was found in a list of vulnerable passwords and must be changed.
Share this post
Watch  On-Demand
Subscribe to The FusionAuth Newsletter
Get updates on techniques, technical guides, and the latest product innovations coming from FusionAuth.