KoComplyAgentic Compliance
GDPR guide

GDPR compliance:the complete guide (2026).

GDPR is not a certificate you buy — it is a set of obligations EU buyers verify through your DPA, your subprocessor list, your records of processing and your answers on data transfers. This guide explains the regulation in plain language, then shows exactly which artefacts procurement asks for and how KoComply's agents produce them from your live systems.

72 hrs
Breach notification deadline to a supervisory authority
1 month
Standard deadline to answer a data subject request
4%
Of global turnover — maximum fine tier
2–4 wks
To an EU-buyer-ready posture with agents

Get a plan for your program

Tell us where you are and we'll send dates, effort and one simple all-inclusive price — plus your Startup Access pricing.

No spam. One reply from a real compliance architect.

What GDPR is

The General Data Protection Regulation governs how personal data of people in the EU and EEA is collected, used, shared, stored and deleted. It applies directly as law across member states, is enforced by national supervisory authorities, and reaches companies anywhere in the world that offer goods or services to, or monitor the behaviour of, people in the EU.

  • There is no official GDPR certificate or badge
  • It applies to any organisation touching EU personal data, wherever it is based
  • Accountability is the core idea: you must be able to demonstrate compliance, not just claim it

What counts as personal data

Personal data is any information relating to an identified or identifiable person. That is far broader than most engineering teams assume — it includes IP addresses, device identifiers, cookie IDs, support tickets, product telemetry tied to a user and pseudonymised records that can be re-linked.

  • Special category data (health, biometrics, ethnicity, beliefs, sexual orientation) needs stronger justification
  • Truly anonymised data falls outside GDPR; pseudonymised data does not

The seven principles

Every obligation in GDPR traces back to seven principles. Auditors, DPAs and enterprise reviewers all frame questions around them.

  • Lawfulness, fairness and transparency
  • Purpose limitation — collect for a stated purpose only
  • Data minimisation — only what you actually need
  • Accuracy — keep records correct and current
  • Storage limitation — defined retention and deletion
  • Integrity and confidentiality — security of processing
  • Accountability — evidence that all of the above happens

Controller or processor: know your role

Most SaaS companies are processors for customer data and controllers for their own marketing, sales and HR data. Controllers decide why and how data is processed; processors act on documented instructions. Your contracts, notices and documentation differ per role, and mislabelling it is the most common finding in enterprise reviews.

Lawful bases for processing

Every processing activity needs one of six lawful bases, chosen before processing starts and recorded in your Article 30 records. For B2B SaaS, contract and legitimate interests carry most of the load; consent is required for cookies and most marketing.

  • Consent — freely given, specific, withdrawable
  • Contract — necessary to deliver the service
  • Legal obligation, vital interests, public task
  • Legitimate interests — requires a documented balancing test

Core requirements in practice

What supervisory authorities and buyers expect to see operating day to day.

  • Records of processing activities (Article 30)
  • Privacy notices that match reality, not a template
  • Data Processing Agreements with every customer and every subprocessor
  • Security of processing: encryption, access control, logging, backups, testing
  • Data protection by design and by default in new features
  • DPIAs for high-risk processing such as large-scale profiling or special category data
  • Vendor due diligence and a published subprocessor list with change notice

Data subject rights

Individuals can exercise eight rights, and you generally have one month to respond, extendable by two months for complex requests. The operational test is whether you can find every copy of a person's data across production, analytics, warehouses, support tools and backups.

  • Access, rectification, erasure ('right to be forgotten')
  • Restriction, portability, objection
  • Rights related to automated decision-making and profiling
  • As a processor, you must help your controller customers meet these deadlines

International data transfers

Moving EU personal data outside the EEA needs a transfer mechanism: an adequacy decision, standard contractual clauses, or binding corporate rules. Where SCCs are used, a transfer impact assessment documenting the destination country's laws and your supplementary safeguards is expected. Many EU buyers now additionally ask whether you can host in an EU region — decide early whether you can offer one.

Breach notification: the 72-hour rule

A personal data breach that is likely to risk people's rights must be reported to the supervisory authority within 72 hours of becoming aware of it, and to affected individuals without undue delay when the risk is high. As a processor you must notify your controller customers without undue delay. The clock starts at awareness, not at conclusion of the investigation, so a rehearsed runbook matters more than a perfect report.

Fines, enforcement and the real cost of getting it wrong

Fines run to €10 million or 2% of global annual turnover for administrative failures, and €20 million or 4% for breaches of core principles or rights. For early-stage companies, the bigger commercial risk is usually different: an EU deal stalling in procurement, or a customer's own DPO blocking the contract.

GDPR alongside ISO 27001 and SOC 2

GDPR describes obligations; ISO 27001 gives you the management system that proves you meet the security ones, and SOC 2 does the same for US buyers. The control sets overlap heavily — access control, vendor management, incident response, change management — so running them together is far cheaper than sequentially.

UK GDPR and the wider EU regime

UK GDPR mirrors the EU regulation with its own regulator (the ICO) and its own transfer paperwork (the IDTA or the UK addendum to SCCs). If you sell into both markets you need both sets of clauses. The EU AI Act and NIS2 add adjacent obligations for AI systems and certain sectors; treat them as extensions of the same governance system, not separate projects.

Common GDPR myths

Beliefs that regularly cost startups weeks in procurement.

  • "We're US-based so GDPR doesn't apply" — it applies based on whose data you process
  • "We can get GDPR certified" — no such certificate exists; you evidence compliance
  • "Consent covers everything" — most B2B processing runs on contract or legitimate interests
  • "Encryption means we don't have to report a breach" — it lowers risk, it does not remove the assessment
  • "We need a DPO" — only for large-scale monitoring or special category data at scale

How much GDPR compliance costs and how long it takes

Traditionally teams pay for legal drafting, a privacy tool, and months of internal time — with the biggest cost being engineering hours nobody invoices. With KoComply it is one simple all-inclusive price covering the agentic platform, the full program and audit support, and qualifying early-stage teams get Startup Access pricing with staged payments. Most teams reach an EU-buyer-ready posture in two to four weeks.

How KoComply's agents handle GDPR

Instead of handing you templates, agents read your actual estate and keep the paperwork true to it.

  • Vendor and Risk Agent inventories subprocessors and runs due diligence
  • Policy Agent drafts notices, DPAs, retention schedules and the Article 30 records from real processing, then rewrites them when your stack changes
  • Infrastructure and Codebase Agents evidence encryption, access control, logging and secure development
  • Trust Agent publishes a Trust Center so EU procurement self-serves
  • You review and approve — agents never sign anything on your behalf

How KoComply gets you there

Week 1

Map your data

Agents inventory systems, vendors and data flows to build the Article 30 records and subprocessor list.

Week 2

Contracts and notices

DPA, SCCs, privacy notice, cookie posture and retention schedule are drafted from your real processing.

Week 3

Operational procedures

DSR intake, breach runbook with the 72-hour clock, and vendor reviews go live with named owners.

Week 4

Buyer ready

Everything lands in a Trust Center so EU procurement self-serves before they email you.

Founders building trust with KoComply

"People tasks got auto-completed, repos were classified automatically, and evidence just appeared. The fastest path to compliance I've seen."
Deepesh JayalFounder
"KoComply gave me AWS and codebase compliance posture in one view with clear steps to fix each issue and auto-added remediation tags. Saved weeks of work figuring out what to fix to be compliant."
HarshSr. Software Engineer
"KoComply turned a confusing compliance project into a clear, agent-driven workflow. We always knew the next step and who owned it."
VitragFounder

Frequently asked questions

Can we be GDPR certified?

No. There is no official GDPR certificate. What buyers accept is evidence: a DPA, Article 30 records, a subprocessor list, transfer documentation and usually ISO 27001 or SOC 2 behind it.

Do we need an EU representative?

If you have no EU establishment but target EU users, Article 27 usually requires one. We flag it during scoping.

Do we need a DPO?

Only when you carry out large-scale monitoring or process special category data at scale. Most early-stage SaaS companies do not, but should name an accountable owner.

How fast can we be ready?

Most teams reach an EU-buyer-ready posture in 2–4 weeks with agents doing the mapping and drafting, then a review cycle with your team.

What does GDPR compliance cost with KoComply?

One simple all-inclusive price — platform, program and audit support together — with Startup Access pricing and staged payments for qualifying early-stage teams.

Is GDPR enough for EU enterprise deals?

It is the baseline. Larger buyers usually also want ISO 27001 or SOC 2 as evidence of the controls behind your claims.

Become compliance ready in 2–4 weeks

One price to KoComply covers everything — agentic GRC and the audit, all inclusive. Qualifying early-stage startups get Startup Access pricing and can pay in stages.