What is GDPR? A practical evidence guide for SaaS teams

The General Data Protection Regulation (GDPR) is the EU legal framework governing how personal data is collected, used, shared, secured and retained. It creates rights for individuals and obligations for organisations that process personal data within its territorial scope.

Who this is for: For technology teams learning what GDPR means or connecting privacy obligations to day-to-day security evidence.

What GDPR covers

GDPR applies to processing of personal data within its territorial scope and is built around principles including lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability.

  • Personal-data processing
  • Individual rights
  • Controller and processor accountability

Turn obligations into records

Operational evidence can include data maps and records of processing, lawful-basis decisions, notices, processor agreements, data-subject request logs, DPIAs, breach assessments, retention decisions and security-control records.

Track processors and suppliers

Vendor records should show the service owner, processing context, personal-data categories, contract or DPA status, subprocessors, security review and reassessment date.

Connect privacy and security evidence

Access reviews, incident records, encryption notes, policies and vendor reviews help show how technical and organisational measures operate. Legal interpretation and final applicability decisions remain with qualified privacy advisers.

Common questions

What is GDPR in simple terms?

GDPR is an EU regulation that protects personal data. It gives individuals rights and requires organisations within its scope to process personal data lawfully, transparently, securely and accountably.

Who does GDPR apply to?

GDPR applies to organisations established in the EU and can also apply to organisations outside the EU when they offer goods or services to, or monitor the behaviour of, people in the EU. Exact applicability should be confirmed with qualified advice.

Is GDPR a certification standard?

No. GDPR is a law, not a management-system certification standard like ISO/IEC 27001. Certifications may support assurance in limited contexts, but they do not replace compliance with the regulation.

What GDPR evidence should a SaaS company keep?

Common records include processing activities, lawful-basis decisions, privacy notices, processor agreements, vendor reviews, DPIAs where needed, data-subject request logs, breach assessments, retention decisions and security-control evidence.

Does Trustega provide legal advice?

No. Trustega helps organise operational privacy and security records. Legal interpretation, territorial scope and regulatory decisions should be handled by qualified privacy counsel or a data-protection specialist.

Primary sources

Related practical guides