What Is GDPR?
The General Data Protection Regulation (GDPR, EU 2016/679) is the European Union's core data protection law, governing how organizations collect, process, store, and transfer the personal data of individuals in the EU. It applies to any organization processing EU residents' data, regardless of where the organization is based, and establishes principles such as lawful basis for processing, data minimization, purpose limitation, and the right to erasure. GDPR requires organizations to implement 'appropriate technical and organizational measures' to protect personal data and to report qualifying data breaches to a supervisory authority within 72 hours. Non-compliance carries fines of up to €20 million or 4% of global annual turnover, whichever is higher.
Why It Matters
GDPR's breach-notification and 'appropriate technical measures' requirements apply just as much when personal data is exposed by a compromised service account or API key as when it's exposed by a human error — but non-human identities are frequently the weaker link. A forgotten API key with read access to a customer database, an over-privileged automation bot, or a dormant OAuth token from a decommissioned integration can each expose personal data just as effectively as a phished employee account, and often for longer, since these credentials are rarely monitored or rotated. OWASP's 2025 NHI Top 10 research found that 80% of identity breaches involve a non-human identity, and with organizations typically running 2,000+ non-human identities against 100 human employees, the attack surface for a GDPR-reportable breach is concentrated in exactly the credentials most security programs don't inventory. When a breach traces back to an orphaned service account, regulators still ask why 'appropriate technical measures' didn't catch it.
How Cydenti Helps
Cydenti helps organizations close the visibility gap that turns a forgotten API key or orphaned service account into a GDPR-reportable incident. By inventorying non-human identities, mapping what data and systems each one can reach, and flagging stale, over-privileged, or orphaned credentials before they're exploited, Cydenti gives security and privacy teams a concrete way to demonstrate 'appropriate technical and organizational measures' over the machine identities that touch personal data. That evidence trail also supports faster, more accurate breach-scoping if an incident does occur — which matters against a 72-hour notification clock.
Explore →Frequently Asked Questions
Can a leaked API key cause a GDPR breach?
Yes. If an API key or service account provides access to personal data and it's exposed or misused, that qualifies as a personal data breach under GDPR, triggering the same 72-hour notification obligation as a breach caused by human error or a stolen password.
Does GDPR require monitoring of service accounts?
GDPR doesn't name service accounts explicitly, but its requirement for 'appropriate technical and organizational measures' to protect personal data is generally interpreted to include controlling and monitoring any credential — human or machine — that can access that data, including API keys and service accounts.
Discover the machine identities you didn't know you had
— in 27 minutes, for free.
NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.
No commitment • No credit card • Data hosted in Europe • Response within 24h