GDPR compliance and data protection
The European regulation follows your users rather than your address. We will say whether it reaches you, put every purpose on a lawful ground and build the file behind the policy.
Breach report
Сообщить об утечке
72 hours
72 часа
Answer a request in
Ответ на запрос
one month
один месяц
Top fine band
Верхний штраф
EUR 20m or 4%
20 млн € или 4%
Lawful grounds
Законных оснований
six of them
их шесть
When you need GDPR compliance

Your users are in Europe
The regulation follows the person, not the company. Offering a service to people in the union brings you inside it even with no office, no server and no entity there.
Nobody speaks for you in the union
A company caught by the regulation from outside has to appoint someone inside it in writing. Without that appointment the first regulator letter has nowhere to land.
A customer sent a processing agreement
Enterprise buyers arrive with a contract fixing your role, your security duties and your breach deadlines. Signing settles those questions for years.
A breach surfaced this morning
Awareness inside the company is what starts the count, long before the investigation ends, and a late notice has to explain its own delay.
What you get
- A lawful ground written down for every purpose
- A record of processing that matches the product
- A representative and an officer where they are owed
- Transfers out of Europe put on a legal footing
- A breach plan that fits inside the deadline
What is required for GDPR compliance

The regulation says who it reaches in as many words. It applies to a controller or processor not established in the union where the processing relates to offering goods or services to people in the union, paid or free, or to monitoring their behaviour there.
So the address of your company decides nothing. Analytics on a European visitor is monitoring; a free tier open to European users is an offering.
The next question is your role. A controller decides why and how data is processed; a processor only acts on instructions. Most products are a controller for their own users and a processor for their business customers at once.
The four duties that decide everything else
A lawful ground for every purpose
There are six, and consent is only one: a contract, a legal obligation, vital interests, a public task and legitimate interests are the others. Each purpose gets its own.
A representative inside the union
A company caught from outside designates one in writing, in a member state where its users are. Only occasional, low-risk processing is let off, and public authorities.
A record of processing activities
Purposes, categories of people and data, recipients, transfers, retention. Fewer than 250 employees is no release if the processing is regular or touches special categories.
An officer, where the trigger is met
An officer is compulsory for a public body, for large-scale regular monitoring of people and for large-scale processing of special or criminal data.
The deadlines and the money
A breach goes to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware; a later notice carries the reasons. A request is answered within one month, extendable by two more for genuinely complex cases if you say so inside the first.
Fines run in two bands. Breaching the duties of a controller or processor reaches 10 million euro or 2% of worldwide annual turnover, whichever is higher. Breaching the basic principles, the conditions for consent, the rights of people or the rules on transfers reaches 20 million euro or 4%.
Sending data out of Europe
A transfer needs either a decision that the destination country protects data adequately, or safeguards of your own: standard contractual clauses adopted by the commission, or binding corporate rules inside a group. The safeguard belongs in the contract with the recipient before the data moves rather than after a customer asks.
A privacy policy, and what a generator leaves out
The policy is the visible part of all this. A privacy policy generator writes a document from a questionnaire; it cannot check the answers against your build, pick your lawful grounds or answer a request inside the deadline.
Where the rules are not European
The Californian code
There a verified request is answered inside 45 days, with one extension, and fines reach 2,500 dollars per violation, or 7,500 if it was intentional or touched someone under 16.
Children in the United States
The federal rule on under-13s asks for a parent's verified agreement before anything is gathered, and adds a written security programme and a ceiling on how long the data is kept.
Sources: the reach of the regulation, the representative, the record, the officer, 72 hours, one month, the transfer safeguards and both fine bands — the General Data Protection Regulation; the Californian deadline and amounts — Civil Code 1798.155; the American children's duties — 16 CFR part 312.
Stages of work
Establishing what reaches you — 3–5 working days
Where your users sit and what the product does with them decides this. Then we say plainly whether the regulation applies and what arrives with it.
Fixing your role for each activity
Controller or processor is decided per activity rather than per company. We will write the answer down before the first customer contract forces a worse one on you.
Choosing a lawful ground for every purpose
Each field, event and integration gets a purpose and a ground, or a note that it has neither. Where consent is used, we will write what happens on withdrawal.
Appointing the representative and the officer
Where the appointment is owed, we will handle it and put the contact details in the notice; where it is not, we will record why.
Papering transfers and processors
Hosting, analytics, support and payment providers all process data for you. We will paper each relationship and put every transfer out of Europe on its safeguard.
Writing the breach plan against 72 hours
Who decides, what goes to the authority, and what is written down when you report nothing at all — on one page, tested before it is needed.
The rest of what we do in this field is grouped under Licensing & Compliance.
FAQ
It can, and the text says so directly. The regulation reaches a controller or processor not established in the union when the processing relates to offering goods or services to people in the union, paid or free, or to monitoring their behaviour there. Your address, your hosting and your place of incorporation decide nothing by themselves. A signup page open to European users, or analytics running on European visitors, is enough on its own.
If the regulation reaches you from outside, yes, in writing, and established in a member state where your users are. The exemption is narrow: processing that is occasional, involves no special categories on a large scale and is unlikely to risk people's rights. Public authorities are also outside it. The representative is the address the authority and individuals write to, so the common mistake is appointing one and never staffing the inbox.
No. Consent is one of six lawful grounds, and often the weakest, because it can be withdrawn and then the processing has to stop. A contract with the person, a legal obligation, vital interests, a public task and legitimate interests are the others. The work is to write down which ground carries which purpose before anyone asks, and to keep that analysis current as purposes change.
Without undue delay and, where feasible, within 72 hours of becoming aware of it. Awareness is the trigger rather than the end of the investigation, and a notification sent later has to carry the reasons for the delay. Where the breach is unlikely to risk people's rights, no notification is due — but that conclusion is a decision you have to record, because the record is what shows the decision was actually taken.
It produces a document, which is the visible tenth of the duty. A generator cannot check its answers against what your build collects, choose the lawful ground behind each purpose, appoint a representative or answer a request inside a month. The document is also the easiest part to compare with reality, so a generated page describing a product you do not have works against you.
Discuss
the Task
Speak to our team
Speak to our team. Tell us about your task –
we’ll help you with it in any jurisdiction.
