Home Blog

ComplyDog Blog

A blog that helps software companies navigate GDPR compliance

The Right To Data Portability In Practice

Portability is narrower than access. It only covers consent and contract processing, and only data the person provided, including what you observed.

Posted by Kevin Yun | 2026-08-27T18:43:00.901Z

GDPR And Automated Decision-Making (Article 22)

Article 22 is a prohibition with three exceptions, not a right people have to claim. It also catches ordinary rules engines, not just machine learning.

Posted by Kevin Yun | 2026-08-26T18:47:02.048Z

Anonymisation Vs Pseudonymisation Under GDPR

Pseudonymised data is still personal data and fully in scope. Anonymised data is outside GDPR entirely. The test is not whether you hold the key.

Posted by Kevin Yun | 2026-08-26T18:44:48.545Z

Is Session Replay Legal Under GDPR?

Session replay can be lawful, but two separate rules apply: consent to run the script, and a lawful basis for the recordings it produces.

Posted by Kevin Yun | 2026-08-25T18:34:38.467Z

GDPR And Employee Surveillance: What You Can Track

You can monitor employees under GDPR, but almost never on consent. The test is necessity and proportionality, and the answer changes by country.

Posted by Kevin Yun | 2026-08-25T18:30:57.115Z

Does GDPR Require Penetration Testing?

GDPR never mentions penetration testing. Article 32(1)(d) requires a process for regularly testing your security measures, a lower bar and a wider one.

Posted by Kevin Yun | 2026-08-23T18:13:11.764Z

Does GDPR Require Encryption? Article 32 Explained

GDPR does not mandate encryption. Article 32 lists it as one example of an appropriate measure, which moves the judgment, and the paperwork, onto you.

Posted by Kevin Yun | 2026-08-23T18:11:13.925Z

Is Sentry GDPR Compliant? PII in Your Error Logs

Sentry's DPA is opt-in and its EU region is real. The harder problem is that error reports capture personal data nobody ever decided to send.

Posted by Kevin Yun | 2026-08-22T06:10:26.650Z

Is Segment GDPR Compliant? Destinations Are the Risk

Segment's DPA is in the terms and its EU region is real. The compliance work sits in the destinations your data fans out to, and each one is yours.

Posted by Kevin Yun | 2026-08-22T06:05:43.358Z

Try It Free for 14 Days,
See if It's Right for You

No credit card required