Getting Started with GDPR
The General Data Protection Regulation (GDPR) has applied since May 25, 2018. It governs how organizations collect, process, store, and delete personal data of data subjects in the EU — regardless of where the organization itself is based. Non-compliance exposes organizations to fines of up to €20M or 4% of global annual turnover. Matproof’s GDPR framework maps accountability and governance controls to your policies, vendor assessments, and evidence library. It is designed to complement your GDPR documentation (RoPA, DPIAs) rather than replace dedicated privacy management tools.Activate GDPR under Settings → Frameworks → GDPR. Your control set focuses on organizational and technical measures under Article 32, accountability documentation, and vendor (processor) management.
Who Must Comply?
GDPR applies to you if:- You are established in the EU (regardless of where you process data)
- You are outside the EU but offer goods or services to data subjects in the EU
- You are outside the EU but monitor the behaviour of data subjects in the EU (e.g., analytics, tracking)
Key GDPR Roles
Most SaaS companies are both: a controller for their own employee data, and a processor for their customers’ data.
Core GDPR Requirements at a Glance
Recommended Implementation Plan
Breach Notification Quick Reference
Not all breaches require supervisory authority notification. If the breach is unlikely to result in a risk to individuals’ rights and freedoms, notification is not required — but you must still document the breach in your internal breach register (Article 33(5)).
Common Mistakes
1. Consent as the default lawful basis
Consent is one of the hardest lawful bases to maintain (it must be freely given, withdrawable, and documented). For B2B SaaS processing customer data, legitimate interests or contract is usually more appropriate for most processing activities.2. DPAs treated as a checkbox
Many organizations collect DPAs from processors but never review them. Article 28 requires DPAs to include specific provisions — collect them and verify the content.3. Ignoring employee data
GDPR applies to employee personal data too. Recruitment data, payroll, performance records, and monitoring activities all require a lawful basis and retention policy.Next Steps
- Incidents — 72-hour breach notification workflow
- Vendor Risk — DPA tracking and processor risk assessments
- People Module — employee data handling and access management
- Policy Management — privacy policy generation and acknowledgement tracking