GDPR · EU 2016/679 Dataskyddsförordningen

GDPR has applied since 2018. Could your security prove it in 72 hours?

If you hold data about customers, citizens, patients or employees, GDPR applies to you. Article 32 requires security measures proportionate to the risk. Articles 33 and 34 give you 72 hours to notify a breach, or explain why you didn’t.

See what Article 32 requires

Article 32: Four Security Measures

Encryption, resilience, recovery and regular testing. Proportionate to risk, not a fixed checklist.

Articles 33 & 34: 72-Hour Notification

The clock starts on awareness, not a finished investigation. High-risk breaches also require telling the people affected.

Article 83: Two Fine Tiers

Up to €20M or 4% of turnover for core violations. Up to €10M or 2% for security and breach-notification failures.

Trusted by 100+ Swedish Kommuner, Regions and
EU-Regulated Enterprises Since 2002

Stakes

Why Acting Now Is Not Optional

GDPR has applied across the EU since 25 May 2018. It reaches beyond company location, and one supplier’s breach can trigger notification duties at national scale.

Scope

Who Does This Apply To?

Unlike NIS2, GDPR isn’t limited to critical sectors. It applies based on what you do with personal data, not what industry you’re in.

Controller

You Decide How & Why

Most Swedish municipalities, SMEs and enterprises fall here for their customer, citizen or employee data.

Processor

You Act on Someone Else’s Behalf

A payroll provider or a marketing agency handling a client’s contact lists, for example.

Article 3(2)

In Scope Without an EU Base

If you offer goods or services to people in the EU, or monitor their online behaviour, GDPR applies even without an EU establishment.

GDPR · Articles 32–34

What the Law Requires, and How eBuilder Helps

Every Article 32 and 33 obligation, and the eBuilder Security service that satisfies it directly.

Art. 32(1)(b)

Ongoing Confidentiality, Integrity & Availability

Continuous protection of the systems and services that process personal data.

Managed by MDR & SOC 24/7
Art. 32(1)(d)

Regular Testing & Evaluation

Dated, recurring evidence that your technical measures actually work, not just that they exist.

Art. 33

72-Hour Notification to IMY

Detecting a breach fast enough, and documenting it precisely enough, to notify within the window.

Managed by MDR & SOC 24/7
Art. 32 & 33 (Governance)

A Governed, Board-Visible Programme

Coordinated technical and organisational measures, with breach-handling readiness built into governance and reporting.

Managed by CISO as a Service
GDPR · Free Readiness Score

See Exactly Where You Stand on Article 32 and Breach Readiness

Maps your current state against Article 32’s four security measures and your Article 33 notification readiness. Takes about 20 minutes. The output is board-ready.

  • Your score against each Article 32(1) measure, not a generic checklist.
  • Your highest-priority gap, ranked by how it would look to IMY on review.
  • A board-ready summary, written in plain language, not legal text.

No obligation · EU data residency · Results reviewed in a 30-minute call.

GDPR Article 32 Readiness Score

See where you stand on security-of-processing and breach notification, scored in plain language.

No spam. EU data residency. Unsubscribe any time.

Why eBuilder

Sweden-Based Security Built for This Regulation

We are not a global firm that adapted generic content for the EU. IMY’s expectations, EU data residency and Schrems II are what we design our services around.

See Full Article 32 Coverage

Sweden-Based
24/7 SOC

Human analysts watching every signal, every minute, every day. Logs stay in Sweden.

3-minute
Median Response

The industry talks in hours. We measure in minutes and escalate threats fast enough to matter.

Onboard in Days,
Not Quarters

Signed Monday. MDR live Thursday.

20+ Years in SaaS

Cybersecurity practice within eBuilder, a Swedish enterprise-software company operating since 1999.

ISO 27001 Certified

Independently audited and certified to the ISO 27001 information-security standard for our SOC.

ISO 27001 certification mark

Article 32 Aligned

All services mapped to GDPR Article 32 security-of-processing measures.

Schrems II
Compliant

All monitoring data, logs and incident records stay within the EU: nothing transferred to a non-adequate third country.

Questions

GDPR Compliance, Answered

Real questions a board or IT lead asks before engaging on GDPR, answered in two to three sentences.

Does GDPR apply to our municipality or SME even though we’re small?

Yes. GDPR applies based on what personal data you process, not your size or sector. A small business holding customer or employee records is a controller in the same way a large enterprise is; the scale of your measures should match your risk, not your headcount.

What actually counts as a “personal data breach”?

Any security incident leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data, not just data theft. A misconfigured system that exposes data, or an employee losing an unencrypted laptop, can qualify.

When does the 72-hour clock start?

From the moment you have a reasonable degree of certainty that a breach involving personal data has occurred, not from when the breach happened, and not from when your investigation is complete.

Does using eBuilder Security’s MDR make us GDPR compliant?

No single service can make an organisation GDPR compliant, because compliance also depends on your lawful basis, data-handling practices, contracts and governance. MDR addresses the security-of-processing and breach-detection side of Articles 32 and 33; the legal and organisational parts sit with your DPO or legal counsel.

Do we need a Data Protection Officer?

That depends on your specific processing activities under Article 37, and it’s a legal question, not one we determine for you. What we can help with is the technical security and breach-readiness work that supports whichever governance structure you put in place.

Can a penetration test or vulnerability management report be used as evidence for Article 32(1)(d)?

Yes, dated, recurring test and remediation evidence is specifically what Article 32(1)(d) calls for. Both services produce reports and verified-closure records that document ongoing testing of your technical measures.

Act Now

IMY’s 72-Hour Clock Doesn’t Wait for a Convenient Time.
Let’s Get Your Evidence Ready.

Book a free 30-minute security briefing with a Sweden-based advisor. We’ll tell you exactly where your Article 32 measures and breach-notification readiness stand, with no obligation.

Book a 30-Minute Security Briefing
No commitment required Sweden-based advisor responds same business day