GDPR Guide
GDPR differs from the security frameworks on this site in kind: it is law, not attestation, and it regulates personal data broadly rather than security controls specifically. For US companies it usually enters the picture through enterprise deals — EU customers require Data Processing Agreements, transfer mechanisms, and evidence of a real privacy program before signing.
The obligations that bite in practice
For a typical B2B SaaS processor, the operational core is: a compliant DPA with every customer and sub-processor, a maintained record of processing activities, a lawful transfer mechanism for EU-to-US data flows, workable data-subject-rights procedures (access, deletion, portability), and security measures appropriate to the data — where your SOC 2 or ISO 27001 control set does double duty.
Where security frameworks help
Article 32’s “appropriate technical and organisational measures” is deliberately unprescriptive, and demonstrating it is far easier atop an attested control environment. Cross-mapped evidence means your access reviews, encryption posture, and incident procedures answer GDPR security questions without a parallel program.
vCISO Services
Virtual CISO services for startups and scaleups: security strategy, compliance roadmap, enterprise deal support, and board reporting — without the $300K hire.
Vendor Risk Management
Automate vendor security reviews, track third-party risk, and generate audit-ready vendor evidence for SOC 2, ISO 27001, and HIPAA — continuously.
GDPR Compliance Checklist — A GDPR checklist built for B2B SaaS — lawful bases, DPAs, sub-processors, data-subject rights, transfers, and breach clocks. Full list on-page.
Does GDPR apply to our US company?
If you offer goods or services to people in the EU or monitor their behavior, yes — establishment in Europe is not required. A SaaS product with EU users and EU-targeted marketing is typically in scope.
What's the difference between a controller and a processor?
Controllers decide why and how personal data is processed; processors handle it on a controller's instructions. Most B2B SaaS companies are processors for customer data and controllers for their own marketing and employee data — carrying both obligation sets simultaneously.