A blog that helps software companies navigate GDPR compliance
GDPR has no data residency rule. It regulates how data moves, not where it sits. The pressure to store in the EU almost always comes from contracts.
Posted by Kevin Yun | 2026-08-28T15:49:15.451Z
Office CCTV is lawful under GDPR, but consent is the wrong basis and signage alone is not notice. Retention and access requests are where it breaks.
Posted by Kevin Yun | 2026-08-27T18:46:23.340Z
Portability is narrower than access. It only covers consent and contract processing, and only data the person provided, including what you observed.
Posted by Kevin Yun | 2026-08-27T18:43:00.901Z
Article 22 is a prohibition with three exceptions, not a right people have to claim. It also catches ordinary rules engines, not just machine learning.
Posted by Kevin Yun | 2026-08-26T18:47:02.048Z
Pseudonymised data is still personal data and fully in scope. Anonymised data is outside GDPR entirely. The test is not whether you hold the key.
Posted by Kevin Yun | 2026-08-26T18:44:48.545Z
Session replay can be lawful, but two separate rules apply: consent to run the script, and a lawful basis for the recordings it produces.
Posted by Kevin Yun | 2026-08-25T18:34:38.467Z
You can monitor employees under GDPR, but almost never on consent. The test is necessity and proportionality, and the answer changes by country.
Posted by Kevin Yun | 2026-08-25T18:30:57.115Z
GDPR never mentions penetration testing. Article 32(1)(d) requires a process for regularly testing your security measures, a lower bar and a wider one.
Posted by Kevin Yun | 2026-08-23T18:13:11.764Z
GDPR does not mandate encryption. Article 32 lists it as one example of an appropriate measure, which moves the judgment, and the paperwork, onto you.
Posted by Kevin Yun | 2026-08-23T18:11:13.925Z
Popular Posts
The 7 Basic Principles of GDPR Compliance
GDPR Cookie Consent (Banner): An Essential Guide, Checklist, and Examples
OpenAI's GDPR Compliance: Understanding the €15 Million Fine and What It Means for AI Companies
GDPR Software ROI: Is It Worth the Investment?
GDPR and the Consequences of Non-Compliance: What B2B SaaS Companies Need to Know
New to ComplyDog? Your Guide to Getting Started
What is a DPA? Data Processing Agreement for GDPR Explained
GDPR Compliance Checklist For B2B SaaS Companies
GDPR Implementation Examples: Success Stories for B2B SaaS Companies
With ComplyDog, our team was able to create a fully compliant GDPR page in just 30 minutes. We were impressed with how user-friendly the interface was, and how it guided us step-by-step through the process. The tool even helped us to identify potential privacy issues on our site that we hadn"t considered before, which was incredibly helpful.
Sagar Soni
Co-Founder at Requestify