A blog that helps software companies navigate GDPR compliance
Notion's DPA is incorporated by reference, so there is nothing to sign. The harder questions are subprocessors, AI, and what your workspace holds.
Posted by Kevin Yun | 2026-08-18T17:40:58.681Z
Typeform's DPA sits inside its privacy policy and binds without a signature. The harder GDPR questions are about your form, your embed and your retention.
Posted by Kevin Yun | 2026-08-17T08:09:09.676Z
Supabase provides an Article 28 addendum that takes effect when you accept its terms, plus a dated subprocessor list. Your build is a separate question.
Posted by Kevin Yun | 2026-08-17T08:04:20.956Z
Build the library from questionnaires you've already completed, not from scratch. Here's the extraction, the governance, and how to stop it going stale.
Posted by Kevin Yun | 2026-08-16T07:34:47.254Z
An answer is a claim; evidence is what makes it checkable. Here are the six kinds of proof reviewers request, and what you should never send.
Posted by Kevin Yun | 2026-08-16T07:32:20.966Z
A first questionnaire usually takes two to three weeks of part-time work. The second takes a fraction. Here's where the time actually goes, and why.
Posted by Kevin Yun | 2026-08-15T06:06:23.230Z
Ownership belongs with whoever is accountable for the deal, not whoever knows the most about security. Here's the split, and where each model breaks.
Posted by Kevin Yun | 2026-08-15T06:04:29.976Z
The questionnaire rarely arrives alone. Here are the nine documents that travel with it, why buyers want each, and what to send when you don't have one.
Posted by Kevin Yun | 2026-08-14T13:15:57.200Z
The SIG is broad third-party risk and costs money to license. The CAIQ is deep on cloud and is free and publishable. Most SaaS vendors meet both.
Posted by Kevin Yun | 2026-08-14T13:14:21.341Z
Popular Posts
The 7 Basic Principles of GDPR Compliance
GDPR Cookie Consent (Banner): An Essential Guide, Checklist, and Examples
OpenAI's GDPR Compliance: Understanding the €15 Million Fine and What It Means for AI Companies
GDPR Software ROI: Is It Worth the Investment?
GDPR and the Consequences of Non-Compliance: What B2B SaaS Companies Need to Know
New to ComplyDog? Your Guide to Getting Started
What is a DPA? Data Processing Agreement for GDPR Explained
GDPR Compliance Checklist For B2B SaaS Companies
GDPR Implementation Examples: Success Stories for B2B SaaS Companies
With ComplyDog, our team was able to create a fully compliant GDPR page in just 30 minutes. We were impressed with how user-friendly the interface was, and how it guided us step-by-step through the process. The tool even helped us to identify potential privacy issues on our site that we hadn"t considered before, which was incredibly helpful.
Sagar Soni
Co-Founder at Requestify