GDPR

The GDPR, for a software company

Regulation (EU) 2016/679 reaches every company that processes personal data; which of its 31 catalogued duties turn on depends on your role and on a few answers about the data, and the breach clock of 72 hours runs from the moment you become aware.

Do you process personal data on behalf of your customers, as their processor?

A SaaS that holds its customers' end-user data does; every company is the controller of its own customer and staff data regardless (Article 4(7) and (8)).

Where is the company established?

Answer above to read the determination for your case; the full tool takes your answers with it.

Continue in the free determination

Eight tools, free, no account

Every free template on one page

The instrument and the standard

  • Regulation (EU) 2016/679, applying since 25 May 2018: 31 duties catalogued

    One row per statute reference for a controller or a processor, the Official Journal text in six languages. Article 83 sets the ceilings: €10,000,000 or 2% of worldwide annual turnover for the duties of Articles 25 to 39, €20,000,000 or 4% for the principles, the lawful bases, the data subjects' rights and the transfers.

  • ISO/IEC 27701, the privacy extension to ISO 27001

    The ISO references in the catalogue are StandardOS's reading, Annex A for a controller and Annex B for a processor. The Regulation names no standard and no certificate is a presumption of conformity with it.

Read next

Dates and counts are read from the Regulation and the catalogue, never typed on this page. This is not legal advice, and the Regulation is the text to read: Regulation (EU) 2016/679