GDPR
EU regulation for personal data protection and privacy
ISO 28000
International standard for supply chain security management systems.
Quick Verdict
GDPR mandates personal data protection for EU residents globally with hefty fines, while ISO 28000 is a voluntary standard for supply chain security management via risk-based systems. Companies adopt GDPR for legal compliance; ISO 28000 for resilience and certification.
GDPR
Regulation (EU) 2016/679 General Data Protection Regulation
Key Features
- Extraterritorial scope targets non-EU entities processing EU data
- Accountability principle demands demonstrable compliance proof
- Fines up to 4% of global annual turnover
- 72-hour mandatory personal data breach notification
- Enhanced rights including erasure and portability
ISO 28000
ISO 28000:2022 Security management systems — Requirements
Key Features
- Risk assessment and treatment aligned with ISO 31000
- PDCA cycle for continual security improvement
- Supply chain-focused operational controls and plans
- Leadership commitment and top management accountability
- Integration with ISO 22301 for resilience
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
GDPR Details
What It Is
GDPR (Regulation (EU) 2016/679) is a binding EU regulation protecting natural persons' personal data. It modernizes privacy for the digital age with extraterritorial scope, applying globally to EU data processors. Core approach is accountability-based, requiring organizations to demonstrate compliance via risk assessments.
Key Components
- Seven principles: lawfulness, purpose limitation, minimization, accuracy, storage limitation, integrity, accountability.
- Data subject rights: access, rectification, erasure, portability, objection.
- Obligations: DPO appointment, DPIAs, 72-hour breach notifications, ROPAs.
- Enforcement via DPAs with fines up to 4% global turnover; no certification needed, continuous compliance model.
Why Organizations Use It
Mandated for EU data handling, reduces breach risks, builds trust. Enables Digital Single Market, avoids massive penalties, inspires global standards like LGPD. Enhances reputation, supports innovation under privacy-by-design.
Implementation Overview
Assess processing, map data flows, appoint DPO, train staff, update contracts. Applies to all sizes/industries processing EU data; SMEs face high burdens. No formal certification; ongoing audits by DPAs, two-year initial transition typical.
ISO 28000 Details
What It Is
ISO 28000:2022 — Security management systems — Requirements is an international certification standard for establishing, implementing, maintaining, and improving a security management system (SMS) focused on supply chain security. It adopts a risk-based approach using the PDCA cycle to manage threats like theft, sabotage, and disruptions.
Key Components
- Clauses 4-10 cover context, leadership, planning, support, operation, evaluation, and improvement.
- Emphasizes risk assessment (aligned with ISO 31000), operational controls, and security plans.
- Built on harmonized ISO structure for integration; supports third-party certification per ISO 28003.
Why Organizations Use It
- Reduces supply chain risks and incidents for continuity.
- Meets contractual, regulatory, and partner requirements.
- Enhances market access, insurance terms, and stakeholder trust.
- Provides governance for resilience and competitive edge.
Implementation Overview
- Phased: gap analysis, risk assessment, controls deployment, audits.
- Applicable to all sizes/industries; scalable for logistics, manufacturing.
- Involves training, documentation; certification via Stage 1/2 audits.
Key Differences
| Aspect | GDPR | ISO 28000 |
|---|---|---|
| Scope | Personal data privacy and protection | Supply chain security management |
| Industry | All sectors processing EU data globally | Logistics, manufacturing, any supply chain |
| Nature | Mandatory EU regulation with fines | Voluntary management system standard |
| Testing | DPIAs, audits by DPAs | Internal audits, certification audits |
| Penalties | Up to 4% global turnover fines | Loss of certification, no legal fines |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about GDPR and ISO 28000
GDPR FAQ
ISO 28000 FAQ
You Might also be Interested in These Articles...

Step-by-Step Implementation Guide to ISO 27701: Building a Privacy Information Management System (PIMS) on Your ISO 27001 Foundation
Implement ISO 27701 on your ISO 27001 foundation with this actionable guide. Tackle PII controls, audit evidence, GDPR integration. Templates, checklists for 20

SOC 2 Trust Services Criteria in Plain English: Side-by-Side Decoder for Security, Availability, and Beyond
Decode AICPA Trust Services Criteria from auditor jargon to plain English with side-by-side tables, analogies & TL;DRs. CISOs & founders: implement SOC 2 contro

SOC 2 Audit Survival Guide: First 5 Steps to Ace Your Type 2 Audit with Infographic
Ace your SOC 2 Type 2 audit with the first 5 essential steps: evidence collection, auditor tips, red flags from SignWell's experience. Get checklists & infograp
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Check out these other Gradum.io Standards Comparison Pages
NIST 800-171 vs ISO 30301
Compare NIST 800-171 vs ISO 30301: Cybersecurity for CUI protection meets records management standards. Key differences, compliance strategies & implementation tips to secure data now!
PMBOK vs POPIA
Unlock PMBOK vs POPIA: Compare project mgmt standards with SA's data privacy law. Achieve compliance, cut risks, boost strategy. Integrate for success now!
POPIA vs HITRUST CSF
Discover POPIA vs HITRUST CSF: Compare South Africa's GDPR-aligned privacy law with the certifiable security framework. Master compliance gaps, align controls, reduce risks. Dive in now!