Framework reference
GDPR for EU B2B software companies.
GDPR applies when a company processes personal data of people in the EU. For B2B software companies, that usually includes customer users, employees, prospects, support contacts, product analytics, logs, and vendor data from the first day of EU operations.
- Kaamos support
- Supported in Kaamos
- Category
- Binding EU regulations
- Obligation
- Binding
- Last updated
The obligation, in the act's words
…the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk…
Appropriate to the risk, not appropriate to a template. The standard is set by your processing, so the evidence has to describe your processing.
Who it applies to
- Any company processing personal data of people in the EU.
- SaaS companies with EU customers, employees, or users.
- Processors and controllers that need to show security and accountability.
What you need to do
- Appropriate technical and organizational security measures.
- Processor and vendor management, data-subject rights, breach response, and records of processing.
- Evidence that privacy controls and security controls are actually operating.
How Kaamos helps
- Connects privacy-relevant assets, vendors, and controls into one operating view.
- Keeps GDPR security work aligned with ISO 27001, NIS2, and customer questionnaires.
- Maintains evidence for security controls without screenshot scrambling.
Sources
Company profiles this applies to
- EU B2B SaaS company with 15-100 employees — plans for GDPR now.
- EU fintech or software supplier to financial customers — plans for GDPR now.
- EU SaaS company building or embedding AI — plans for GDPR now.
- Finnish public-sector software supplier — plans for GDPR now.
Supported in Kaamos
Manage GDPR controls, owners and evidence in Kaamos. Talk to us about the framework scope and connected systems you need.