GDPR
The GDPR, for a software company
Regulation (EU) 2016/679 reaches every company that processes personal data; which of its 31 catalogued duties turn on depends on your role and on a few answers about the data, and the breach clock of 72 hours runs from the moment you become aware.
Answer above to read the determination for your case; the full tool takes your answers with it.
Continue in the free determinationEight tools, free, no account
Which GDPR duties apply to you, in writing
Nine questions; the duties read from the Regulation with the provision each rests on, the 31 catalogue rows in six Official Journal languages, the ISO 27701 reading, the clocks; copy or download.
The record of processing, written
The 7 fields of a controller's record and the 4 of a processor's, verbatim from Article 30, one activity at a time; the document to copy or download.
The processor contract, term by term
The 8 terms of Article 28(3) every processor contract carries, verbatim, with a status per term and the DORA clause each sits beside when the customer is a bank; the checklist to copy or download.
The impact assessment: due or not, and written
The 3 cases of Article 35(3) as questions, the 4 elements of Article 35(7) as the assessment itself, the Article 36 consultation; the document to copy or download.
The breach clock: 72 hours from awareness
The moment you became aware in, the Article 33 deadline out, the processor's notice, the Article 34 communication, and the notification written to Article 33(3).
The request clock: 1 month from receipt
The day of receipt in, the deadline out by the period rule, the 2 further months and the refusal kept to the first month, and an access request answered with the 8 contents of Article 15(1).
Which transfer mechanism: adequacy, clauses, or none
The destination and the two roles in; no transfer, one of the 17 adequacy decisions, or the standard contractual clauses' module out, with the 6 safeguards and 7 derogations as the Official Journal words them.
The privacy notice, written from Articles 13 and 14
Where the data come from decides the article; the 12 pieces at collection or the 13 for data obtained elsewhere as the Official Journal words them, an answer under each, the notice written.
Every free template on one page
The instrument and the standard
Regulation (EU) 2016/679, applying since 25 May 2018: 31 duties catalogued
One row per statute reference for a controller or a processor, the Official Journal text in six languages. Article 83 sets the ceilings: €10,000,000 or 2% of worldwide annual turnover for the duties of Articles 25 to 39, €20,000,000 or 4% for the principles, the lawful bases, the data subjects' rights and the transfers.
ISO/IEC 27701, the privacy extension to ISO 27001
The ISO references in the catalogue are StandardOS's reading, Annex A for a controller and Annex B for a processor. The Regulation names no standard and no certificate is a presumption of conformity with it.
Read next
The GDPR for a software company: controller of your own data, processor for your customers', and the five duties that turn on size and data
The GDPR record of processing for a software company: the seven fields of Article 30(1), the four of Article 30(2), why the 250-person exemption never applies, and a page that writes it
The GDPR processor contract for a SaaS company: the eight terms of Article 28(3) every customer addendum carries, the duty most of them forget, and what sits beside them under DORA
The GDPR 72-hour breach clock for a software company: when awareness starts it, what the notification contains, the processor's own clock, and the NIS2, CRA and DORA clocks beside it
The GDPR impact assessment for a software company: the three cases of Article 35(3), the nine criteria behind them, the four elements of Article 35(7), and a page that writes it
ISO/IEC 27701:2025 for a software company: the standalone privacy standard, its 78 controls, what an ISO 27001 system already covers, and the GDPR articles each control evidences
Which GDPR supervisory authority is yours: the main establishment, the lead authority of Article 56, the local cases, and the 30 authorities of the Board
The GDPR representative of Article 27 for a software company outside the EU: who must appoint one, the three conditions of the exemption, and where the name goes
The GDPR data subject request for a software company: the month of Article 12(3), the eight contents of an access answer, the two further months, and a page that computes the deadline
GDPR international transfers for a software company: the 17 adequacy decisions, the four SCC modules, what a US, UK or Indian sub-processor needs, and a page that picks the mechanism
The GDPR privacy notice for a software company: the twelve pieces of Article 13, the thirteen of Article 14, the moment each is given, and a page that writes it
NIS2 or CRA: which incident clock runs for a software company, next to the GDPR's 72 hours
DORA for a software vendor: the contract clauses a bank customer sends, and the processor terms they sit beside
Dates and counts are read from the Regulation and the catalogue, never typed on this page. This is not legal advice, and the Regulation is the text to read: Regulation (EU) 2016/679