GDPR compliance and data protection

The European regulation follows your users rather than your address. We will say whether it reaches you, put every purpose on a lawful ground and build the file behind the policy.

 

Breach report

Сообщить об утечке

72 hours

72 часа

Answer a request in

Ответ на запрос

one month

один месяц

Top fine band

Верхний штраф

EUR 20m or 4%

20 млн € или 4%

Lawful grounds

Законных оснований

six of them

их шесть

When you need GDPR compliance

Your users are in Europe

The regulation follows the person, not the company. Offering a service to people in the union brings you inside it even with no office, no server and no entity there.

Nobody speaks for you in the union

A company caught by the regulation from outside has to appoint someone inside it in writing. Without that appointment the first regulator letter has nowhere to land.

A customer sent a processing agreement

Enterprise buyers arrive with a contract fixing your role, your security duties and your breach deadlines. Signing settles those questions for years.

A breach surfaced this morning

Awareness inside the company is what starts the count, long before the investigation ends, and a late notice has to explain its own delay.

What you get

  • A lawful ground written down for every purpose
  • A record of processing that matches the product
  • A representative and an officer where they are owed
  • Transfers out of Europe put on a legal footing
  • A breach plan that fits inside the deadline

What is required for GDPR compliance

The regulation says who it reaches in as many words. It applies to a controller or processor not established in the union where the processing relates to offering goods or services to people in the union, paid or free, or to monitoring their behaviour there.

So the address of your company decides nothing. Analytics on a European visitor is monitoring; a free tier open to European users is an offering.

The next question is your role. A controller decides why and how data is processed; a processor only acts on instructions. Most products are a controller for their own users and a processor for their business customers at once.

The four duties that decide everything else

A lawful ground for every purpose

There are six, and consent is only one: a contract, a legal obligation, vital interests, a public task and legitimate interests are the others. Each purpose gets its own.

A representative inside the union

A company caught from outside designates one in writing, in a member state where its users are. Only occasional, low-risk processing is let off, and public authorities.

A record of processing activities

Purposes, categories of people and data, recipients, transfers, retention. Fewer than 250 employees is no release if the processing is regular or touches special categories.

An officer, where the trigger is met

An officer is compulsory for a public body, for large-scale regular monitoring of people and for large-scale processing of special or criminal data.

The deadlines and the money

A breach goes to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware; a later notice carries the reasons. A request is answered within one month, extendable by two more for genuinely complex cases if you say so inside the first.

Fines run in two bands. Breaching the duties of a controller or processor reaches 10 million euro or 2% of worldwide annual turnover, whichever is higher. Breaching the basic principles, the conditions for consent, the rights of people or the rules on transfers reaches 20 million euro or 4%.

Sending data out of Europe

A transfer needs either a decision that the destination country protects data adequately, or safeguards of your own: standard contractual clauses adopted by the commission, or binding corporate rules inside a group. The safeguard belongs in the contract with the recipient before the data moves rather than after a customer asks.

A privacy policy, and what a generator leaves out

The policy is the visible part of all this. A privacy policy generator writes a document from a questionnaire; it cannot check the answers against your build, pick your lawful grounds or answer a request inside the deadline.

Where the rules are not European

The Californian code

There a verified request is answered inside 45 days, with one extension, and fines reach 2,500 dollars per violation, or 7,500 if it was intentional or touched someone under 16.

Children in the United States

The federal rule on under-13s asks for a parent's verified agreement before anything is gathered, and adds a written security programme and a ceiling on how long the data is kept.

Sources: the reach of the regulation, the representative, the record, the officer, 72 hours, one month, the transfer safeguards and both fine bands — the General Data Protection Regulation; the Californian deadline and amounts — Civil Code 1798.155; the American children's duties — 16 CFR part 312.

Stages of work

Establishing what reaches you — 3–5 working days

Where your users sit and what the product does with them decides this. Then we say plainly whether the regulation applies and what arrives with it.

Fixing your role for each activity

Controller or processor is decided per activity rather than per company. We will write the answer down before the first customer contract forces a worse one on you.

Choosing a lawful ground for every purpose

Each field, event and integration gets a purpose and a ground, or a note that it has neither. Where consent is used, we will write what happens on withdrawal.

Appointing the representative and the officer

Where the appointment is owed, we will handle it and put the contact details in the notice; where it is not, we will record why.

Papering transfers and processors

Hosting, analytics, support and payment providers all process data for you. We will paper each relationship and put every transfer out of Europe on its safeguard.

Writing the breach plan against 72 hours

Who decides, what goes to the authority, and what is written down when you report nothing at all — on one page, tested before it is needed.

The rest of what we do in this field is grouped under Licensing & Compliance.

Our case studies

Document Framework for Regulated FinTech Platform

Client

Regulated fintech platform for insurance and pension services

arrow_outward

CeFi Compliance System for Crypto Wallet Holding

Client

Crypto wallet holding company

arrow_outward

Leaders of the Area

Alexandra Kurdyumova

Alexandra

Kurdyumova

arrow_outward

FAQ

Does GDPR apply to a company outside Europe?
add
remove
Do we need a representative in the union?
add
remove
Do we always need consent to process data?
add
remove
How fast do we have to report a data breach?
add
remove
Does a privacy policy generator make us compliant?
add
remove

Discuss
the Task

Speak to our team

Speak to our team. Tell us about your task –

we’ll help you with it in any jurisdiction.

Tell us about your task –
we’ll help you with it in any jurisdiction.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use cookies to improve your experience.