A blog that helps software companies navigate GDPR compliance
There is no expiry date in the regulation. Consent stops being valid when the facts it rested on change, which is a different question.
Posted by Kevin Yun | 2026-09-12T07:34:47.073Z
Genuine choice, and no penalty for saying no. It is the condition that fails most often, and it fails for structural reasons.
Posted by Kevin Yun | 2026-09-12T07:30:56.128Z
Yes, and Recital 49 says so almost in terms. The difficulty is not the basis, it is where monitoring systems becomes monitoring people.
Posted by Kevin Yun | 2026-09-10T18:23:54.796Z
Article 8 sets 16 and lets Member States drop to 13. The tables you will find online disagree with each other, and here is why.
Posted by Kevin Yun | 2026-09-10T18:18:50.186Z
The regulation never defines it. Four regulator factors decide it, and none of them is the size of your company or your headcount.
Posted by Kevin Yun | 2026-09-09T18:41:12.560Z
A decision procedure rather than a glossary. Pick per purpose, before you process, and write down why the others did not fit.
Posted by Kevin Yun | 2026-09-09T18:38:02.943Z
Almost none of it turns on headcount. There is no employee threshold for scope, and the two places numbers appear are narrower than they look.
Posted by Kevin Yun | 2026-09-08T14:58:52.805Z
Usually yes for the part that touches the device, and that is a separate question from your lawful basis for the processing that follows.
Posted by Kevin Yun | 2026-09-08T14:55:48.944Z
The controller and the processor both do. In a B2B SaaS deal your customer signs yours, and you sign your vendors' — often on the same day.
Posted by Kevin Yun | 2026-09-06T15:58:42.261Z
Popular Posts
The 7 Basic Principles of GDPR Compliance
GDPR Cookie Consent (Banner): An Essential Guide, Checklist, and Examples
OpenAI's GDPR Compliance: Understanding the €15 Million Fine and What It Means for AI Companies
GDPR Software ROI: Is It Worth the Investment?
GDPR and the Consequences of Non-Compliance: What B2B SaaS Companies Need to Know
New to ComplyDog? Your Guide to Getting Started
What is a DPA? Data Processing Agreement for GDPR Explained
GDPR Compliance Checklist For B2B SaaS Companies
GDPR Implementation Examples: Success Stories for B2B SaaS Companies
With ComplyDog, our team was able to create a fully compliant GDPR page in just 30 minutes. We were impressed with how user-friendly the interface was, and how it guided us step-by-step through the process. The tool even helped us to identify potential privacy issues on our site that we hadn"t considered before, which was incredibly helpful.
Sagar Soni
Co-Founder at Requestify