EU & UK · Applies by law
GDPR compliance
General Data Protection Regulation
Any company processing personal data of people in the EU or UK, regardless of where your company is based.
The context
What it actually asks of you
GDPR is the regulation SaaS companies most often assume they have handled and most often have not. A privacy policy and a cookie banner satisfy two obligations out of dozens. The regulation is built around demonstrable accountability: not whether you are careful, but whether you can prove it on request.
For a product company the practical burden concentrates in four places, knowing what personal data you hold and why, being able to answer a data subject request inside a month, having a lawful basis for each processing purpose, and controlling what your sub-processors do with the data you pass them.
None of that requires a large privacy function. It requires a data map that reflects reality, a small number of documented decisions, and a request process someone has actually run end to end before a real one arrives.
The common mistake
What teams get wrong.
Most teams write a privacy policy and stop. The regulation asks for a Record of Processing Activities, a lawful basis per purpose, a DPIA for high-risk processing, and a documented process for answering a data subject request in 30 days.
Our scope
What we do for GDPR.
- 01Data mapping and Record of Processing Activities (Article 30)
- 02Lawful basis assessment and consent mechanics
- 03DPIAs for high-risk processing
- 04Data subject request workflow, tested end to end
- 05International transfer assessments and Standard Contractual Clauses
- 06Processor agreements and sub-processor register
- 0772-hour breach notification runbook
innsecs provides security and compliance services, not legal advice, and we are not a law firm. We build the technical and organisational measures, evidence and processes these obligations require, and work alongside your counsel on legal interpretation.
Questions
GDPR FAQ
Yes. Article 3 makes it extraterritorial, if you offer goods or services to people in the EU or UK, or monitor their behaviour, it applies regardless of where you are established. Where you may need a representative in the EU is a separate question that depends on scale and risk.
No Record of Processing Activities. It is an explicit Article 30 obligation, it is the first artefact a regulator or enterprise customer asks for, and it is the document everything else depends on. You cannot assess lawful basis, retention or transfers without first knowing what you hold.
For a typical SaaS company with one product, six to ten weeks to a defensible position. Most of that is data mapping and building the rights-request process; the policy drafting is the fast part.
Find out whether GDPR binds you.
Bring your product, your users and your markets. We will tell you what applies, what does not, and what it takes to close the gap.
No sales sequence. A scoping call and a written proposal cost nothing.