About Us Solutions How We Work Contact Blog
Book a Demo
GDPR — EU General Data Protection Regulation

GDPR Compliance for SaaS Startups Selling into Europe.

GDPR isn't just for European companies. If you process data of EU residents, you're in scope. Folksoft maps your data flows, implements required controls, and keeps you audit-ready.

For any SaaS processing EU residents' data — wherever you're based.
Data flow mapping DSR workflows 72-hour breach notice Article 32 controls
€20M / 4%
Max fines for violations
72 hrs
Breach notification window
Article 32
Technical controls mapped
EU + CCPA
Both handled by Folksoft
The basics

What GDPR means for your startup

If you touch the personal data of EU residents, these four facts apply to you.

Applies wherever you're based

Applies to any company processing personal data of EU residents, regardless of where you're based.

Fines up to €20M or 4%

Fines up to €20M or 4% of global annual turnover for violations — whichever is higher.

Lawful basis & data rights

Requires a lawful basis for data processing, clear privacy notices, and data subject rights.

72-hour breach notification

Requires breach notification to the relevant authority within 72 hours of discovery.

The platform

What Folksoft automates for GDPR

From data mapping to DSRs to Article 32 controls, Folksoft operationalises GDPR across your stack.

Data flow mapping & ROPA

Folksoft maps your data flows and builds your Record of Processing Activities (ROPA) automatically.

Collect Map ROPA

Privacy & cookie policy templates

Privacy policy and cookie policy templates, tailored to how your product actually processes data.

Consent management guidance

Practical consent management guidance so you capture, store, and honour user consent correctly.

ConsentCookiesPreferences

Data subject request (DSR) workflows

Ready-made DSR workflows for access, rectification, and erasure requests — so nothing slips.

Request Verify Fulfil

Breach notification procedures

Documented breach notification procedures built around the GDPR 72-hour reporting window.

Detect Notify · 72h Respond

Technical controls — Article 32

Technical controls mapped to Article 32 requirements across your AWS, Azure, GCP, and identity stack.

Pair it up

GDPR + ISO 27001 — a natural pairing

Cover Article 32 with one ISMS

ISO 27001 certification covers most of GDPR's Article 32 technical requirements. Folksoft handles both together for maximum efficiency.

Explore ISO 27001 certification
Read our full GDPR compliance guide
FAQ

GDPR questions, answered

Everything founders ask us before starting their GDPR journey.

Still have questions?

01 Does GDPR apply to US-based startups?

Yes — if you process personal data of EU residents, GDPR applies regardless of where your company is based or incorporated. Folksoft maps your data flows and implements the required controls so you can operate lawfully in every EU market.

02 What is a Data Processing Agreement (DPA)?

A DPA is a legally required contract between a data controller and a data processor under GDPR Article 28. It must be in place before any processor handles personal data on your behalf. Folksoft provides a standard DPA for all customers.

03 Can Folksoft sign a DPA?

Yes. Folksoft provides a standard Data Processing Agreement for all customers. Contact us to receive our DPA before onboarding.

04 What's the difference between GDPR and CCPA?

GDPR covers all EU residents' personal data globally; CCPA covers California residents. While both are privacy regulations, they have different rights, obligations, and penalty structures. Folksoft handles both frameworks, allowing you to address EU and US privacy requirements efficiently.

Get started

Book a GDPR compliance call.

Talk to our team and we'll map your data flows and the controls you need to process EU data with confidence.

Folksoft provides a standard DPA for all customers. EU + CCPA covered.