€20M or 4% of Turnover
The ceiling for core-principle violations, whichever is higher. Security and breach-notification failures under Articles 25–39 draw up to €10M or 2%.
If you hold data about customers, citizens, patients or employees, GDPR applies to you. Article 32 requires security measures proportionate to the risk. Articles 33 and 34 give you 72 hours to notify a breach, or explain why you didn’t.
See what Article 32 requiresEncryption, resilience, recovery and regular testing. Proportionate to risk, not a fixed checklist.
The clock starts on awareness, not a finished investigation. High-risk breaches also require telling the people affected.
Up to €20M or 4% of turnover for core violations. Up to €10M or 2% for security and breach-notification failures.
Trusted by 100+ Swedish Kommuner, Regions and
EU-Regulated Enterprises Since 2002








GDPR has applied across the EU since 25 May 2018. It reaches beyond company location, and one supplier’s breach can trigger notification duties at national scale.
The ceiling for core-principle violations, whichever is higher. Security and breach-notification failures under Articles 25–39 draw up to €10M or 2%.
The clock starts the moment you have reasonable certainty a breach occurred, not once your investigation is finished.
Article 3 covers any EU-established organisation, and any organisation elsewhere that offers goods or services to, or monitors, people in the EU.
In August 2025, a ransomware attack on Swedish supplier Miljödata disrupted roughly 200 municipalities and exposed data on 1.5M+ people.
Unlike NIS2, GDPR isn’t limited to critical sectors. It applies based on what you do with personal data, not what industry you’re in.
Most Swedish municipalities, SMEs and enterprises fall here for their customer, citizen or employee data.
A payroll provider or a marketing agency handling a client’s contact lists, for example.
If you offer goods or services to people in the EU, or monitor their online behaviour, GDPR applies even without an EU establishment.
Every Article 32 and 33 obligation, and the eBuilder Security service that satisfies it directly.
Continuous protection of the systems and services that process personal data.
Dated, recurring evidence that your technical measures actually work, not just that they exist.
Detecting a breach fast enough, and documenting it precisely enough, to notify within the window.
Coordinated technical and organisational measures, with breach-handling readiness built into governance and reporting.
Maps your current state against Article 32’s four security measures and your Article 33 notification readiness. Takes about 20 minutes. The output is board-ready.
No obligation · EU data residency · Results reviewed in a 30-minute call.
See where you stand on security-of-processing and breach notification, scored in plain language.
No spam. EU data residency. Unsubscribe any time.
We are not a global firm that adapted generic content for the EU. IMY’s expectations, EU data residency and Schrems II are what we design our services around.
See Full Article 32 CoverageHuman analysts watching every signal, every minute, every day. Logs stay in Sweden.
The industry talks in hours. We measure in minutes and escalate threats fast enough to matter.
Signed Monday. MDR live Thursday.
Cybersecurity practice within eBuilder, a Swedish enterprise-software company operating since 1999.
Independently audited and certified to the ISO 27001 information-security standard for our SOC.
All services mapped to GDPR Article 32 security-of-processing measures.
All monitoring data, logs and incident records stay within the EU: nothing transferred to a non-adequate third country.
Real questions a board or IT lead asks before engaging on GDPR, answered in two to three sentences.
Yes. GDPR applies based on what personal data you process, not your size or sector. A small business holding customer or employee records is a controller in the same way a large enterprise is; the scale of your measures should match your risk, not your headcount.
Any security incident leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, personal data, not just data theft. A misconfigured system that exposes data, or an employee losing an unencrypted laptop, can qualify.
From the moment you have a reasonable degree of certainty that a breach involving personal data has occurred, not from when the breach happened, and not from when your investigation is complete.
No single service can make an organisation GDPR compliant, because compliance also depends on your lawful basis, data-handling practices, contracts and governance. MDR addresses the security-of-processing and breach-detection side of Articles 32 and 33; the legal and organisational parts sit with your DPO or legal counsel.
That depends on your specific processing activities under Article 37, and it’s a legal question, not one we determine for you. What we can help with is the technical security and breach-readiness work that supports whichever governance structure you put in place.
Yes, dated, recurring test and remediation evidence is specifically what Article 32(1)(d) calls for. Both services produce reports and verified-closure records that document ongoing testing of your technical measures.
Book a free 30-minute security briefing with a Sweden-based advisor. We’ll tell you exactly where your Article 32 measures and breach-notification readiness stand, with no obligation.
Book a 30-Minute Security Briefing