Data Privacy

GDPR Compliance

What GDPR actually asks of a product team, which obligations bite hardest for SaaS, and the practical steps that get you compliant without stalling the roadmap.

A GDPR compliance dashboard showing consent and data-subject requests

The short version

  • GDPR is not a website fix. It is an organisational change project that happens to have technical components.
  • Seven principles and eight individual rights define the obligations. Everything practical follows from those.
  • Start with a data map. You cannot protect, minimise or delete data whose journey through your systems you cannot describe.
  • Breaches must be reported to the supervisory authority within 72 hours unless the data was anonymised or encrypted.

Users everywhere are increasingly worried about privacy and about how their personal information is used online. In response, a series of regulations have appeared to guarantee privacy rights — and the largest of them is the European Union’s GDPR.

What GDPR is

GDPR stands for General Data Protection Regulation. It is a regulation in EU law covering data protection and privacy across the European Union and the European Economic Area, and it also governs the transfer of personal data outside those areas.

The complete text is available in the official EUR-Lex publication.

What compliance actually means

IT runs on information, and the information age has produced countless breaches affecting organisations of every size. Data gets lost, stolen, or released into the hands of people who were never meant to see it — people who frequently have bad intentions.

Under GDPR, organisations must not only gather personal data lawfully and under strict conditions, but also manage it: protecting it from misuse and exploitation, and preserving the rights of the people it describes. Failure carries substantial penalties, as the record of fines and notices makes clear.

The seven principles

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

The ICO publishes detailed guidance on each principle.

What it means for the people in your database

Given the volume of breaches and hacks, the reality for many people is that personal email addresses, passwords, national identifiers, confidential health records and payment details have already been exposed somewhere. GDPR responds by granting a set of individual rights:

  • The right to be informed
  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restrict processing
  • The right to data portability
  • The right to object
  • Rights in relation to automated decision-making and profiling

Full detail is in the ICO’s individual rights guidance.

One of the most consequential changes GDPR introduced is the right to know when your data has been breached. Organisations must notify the appropriate national bodies as quickly as possible so that citizens can act to prevent their data being abused. Consumers are also promised clearer access to their own data and to how it is processed, with organisations required to explain their use of customer information in language people can actually understand.

The main stages of achieving GDPR compliance in an organisation
Compliance as a sequence: understand the regulation, map the data, adjust the product, then monitor continuously.

Five steps to becoming compliant

1. Understand the key concepts and articles

Being GDPR compliant is not a matter of fixing a website. It has to be part of the whole organisation.

Many people in any organisation have access to personal information. HR, IT, marketing and security teams all interact with customer data at different levels, and all of them need to understand the regulation. It is not one department’s responsibility, and it requires both technical and legal implementation.

2. Do the groundwork

The following is not exhaustive, but it is the minimum that moves an organisation towards compliance.

Data mapping

Start by understanding how data moves through your organisation. Documenting the flow of information by building an inventory is how you demonstrate compliance in the first place.

Mapping the flow also surfaces the areas most likely to cause problems. You need to identify how information is processed, how long it stays in the system, how it is transferred in and out of your network, and who has access to it by any route. You also need to establish why you need each piece of information — and to minimise what you capture where the answer is unconvincing.

Privacy policy

Review and update your privacy policy. It is the public statement of how the organisation handles compliance, what data it collects and how that data is used. The data map from the previous step is what makes a genuinely specific policy possible.

A policy should cover the legal basis for collecting the data, retention periods, the right to refuse collection, whether data is subject to automated decision-making, and the reader’s rights under GDPR. All of it in concise, clear language.

Training

GDPR is a business change project. The people you work with need to understand why data protection matters, and be trained on both the principles and the specific procedures you are putting in place.

3. Build the ongoing practice

Administrators responsible for managing data should cooperate with the supervisory authority in fulfilling their duties. Plan and schedule regular audits of processing activities and security controls. Keep records of the personal data held and of the audits themselves, including proof of consent — this is the most direct evidence that your organisation has been actively engaged with compliance rather than declaring it.

Watch what other vendors do

Because GDPR sets guidelines rather than a fixed approach, the market continually invents ways to comply without wrecking the user experience. Study competitors and similar companies, and feed what you find back to whoever owns compliance internally.

Report breaches

Breaches happen to the best-run companies. What matters is having a plan so the damage stays contained. Ensure you have procedures to detect, report and investigate breaches, internally and to the external bodies responsible. Build the severity matrix in advance, factoring in the number of data subjects affected and the type of personal data involved.

72 hours. Breaches must generally be reported to the supervisory authority within 72 hours, unless the personal data was anonymised or encrypted. That is not enough time to design a process from scratch, which is exactly why it has to exist beforehand.

Keep the policies alive

Compliance is not a one-time activity. It needs continuous adoption, planning and auditing. Review the policies periodically to confirm they still cover every individual right, including how personal data is deleted or provided electronically in a commonly used format.

4. Adjust the product

GDPR does not prescribe how to make an application compliant. It sets guidelines and leaves implementation to each organisation. You will hear it said that adjusting forms and adding cookie consent handles roughly 80% of the problem.

Treat that as a rough heuristic, not a rule. Compliance differs meaningfully between organisations, and yours has to be evaluated in its own context.

5. Monitor and audit

Having defined and implemented the policies, the responsibility does not end. Auditing and monitoring are routine work that confirm the current implementation still works and is still current.

GDPR leaves considerable room for future regulation to go further, particularly around transparency in big data and analytics. That alone is reason enough to keep auditing on a regular cadence rather than treating the project as finished.

Where we would start on a Monday. Build the data map before touching the product. Almost every difficult compliance question — what can we delete, what must we retain, who is a processor — becomes answerable once the map exists, and remains unanswerable until it does.

Boolean Solutions experience with GDPR

We have helped organisations work through GDPR compliance from both sides: the technical implementation of consent, access, export and erasure, and the documentation that makes those implementations defensible. We maintain templates and the technical know-how to move an application several steps closer to compliance without stalling the product roadmap.

If compliance is on your roadmap and you would rather not discover the gaps during an audit, talk to us.

Further reading

Written by

Udit Mittal

Founder at Boolean Solutions. Twenty years of building and rescuing web, mobile and AI products for SaaS companies and startups — and writing down what actually worked.

Get in touch