Compliance/05 - GDPR

GDPR you can demonstrate, not just claim.

Article 5(2) puts the burden on you to show compliance, not assert it. We build the records, the agreements, and the rights machinery that make that showable - and run the security obligations underneath.

  • Records of processing under Article 30 that match what your systems actually do
  • A DPA chain that survives an EU customer's legal review, sub-processors included
  • Data subject requests and the 72-hour breach clock as processes, not fire drills
Trusted by teams shipping in regulated markets
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess
EchoWin
Maru AI
Naked Denver
Weird Gloop
Destination Dutchess

The burden of proof is on the controller. And on you.

GDPR has no certificate to hang on a wall. What it has is an accountability principle - you must be able to demonstrate compliance on request. Everything we build for you exists to make that demonstration possible.

Records that match reality

Article 30 records built from what your systems actually process, not from a workshop where someone guessed. Reviewed as the product changes.

- art. 30 - maintained

A DPA chain that survives legal review

Your customers' DPAs, your processor terms, and every sub-processor beneath you - tracked with dates and flow-down obligations that actually match.

- art. 28 - upstream + down

Data subject rights as a process

Access, erasure, portability, and objection handled inside the one-month deadline, with the identity verification and search path documented before the first request lands.

- arts. 12-23 - 1 month

Transfers you can actually justify

Standard Contractual Clauses, transfer impact assessments, and a documented basis for every route personal data takes out of the EEA.

- chapter V - SCCs + TIA

What GDPR actually asks you to hold.

The obligations that matter for a software company are concentrated in a handful of articles - and they are documentation obligations as much as security ones.

Records of processing

art. 30

What personal data you process, why, on what lawful basis, who you share it with, where it goes, and how long you keep it.

Processor agreements

art. 28

Contracts with the controllers above you and every sub-processor below, with the mandatory Article 28 terms flowed down intact.

Data subject rights

arts. 12-23

Access, rectification, erasure, restriction, portability, and objection - answered within one month, extendable to three with reasons.

Security of processing

art. 32

Appropriate technical and organisational measures judged against the risk - encryption, resilience, restoration, and regular testing of their effectiveness.

Breach notification

arts. 33-34

Supervisory authority notified within 72 hours of awareness where the breach is likely to risk rights and freedoms; data subjects notified when the risk is high.

DPIAs and transfers

art. 35 - ch. V

Impact assessments for high-risk processing, and a lawful basis - adequacy, SCCs, or a derogation - for every transfer out of the EEA.

GDPR has no certification scheme in general use, so nobody can hand you a GDPR certificate. Article 5(2) instead requires demonstrable accountability, which is what your customers' legal teams review and what we build to.

From scoping call to demonstrable accountability.

Two phases are gated - the data mapping and the transfer basis. Both are the questions an EU customer's counsel opens with, and both are cheapest to answer correctly the first time.

Phase 01 - gated

Map the personal data

Every processing activity, its lawful basis, its recipients, its retention, and its destination. This mapping is the source of the Article 30 records and everything downstream.

Activities mapped - basis set
Phase 02 - gated

Fix the transfer story

Where personal data leaves the EEA and under what mechanism. SCCs executed, transfer impact assessments written, sub-processor list published and kept accurate.

SCCs executed - TIAs on file
Phase 03

Implement Article 32 security

The technical and organisational measures, tested rather than asserted - which is the part of GDPR that overlaps almost entirely with the security work already in your plan.

Measures evidenced - tested
Phase 04

Run rights, breaches, and reviews

DSR handling inside the deadline, the 72-hour breach process rehearsed with our incident response team, and DPIAs when new processing warrants one.

Rights served - clock rehearsed
Pricing

GDPR is $3,000 a year.
The security department is the rest.

Every other vendor in this category makes you book a demo to learn what GDPR costs. Here it is. Your whole security department is one flat price, and compliance is the only thing we bill per framework.

Startup plan + GDPR
$20,000 / year

For companies under $5M revenue or 50 staff. The whole department, included.

  • Penetration testing
  • Vulnerability management
  • Monitoring & detection 24/7
  • Incident response
  • Compliance & GRC support
  • A named human on call
  • The Sythe Labs platform, run by us
+ $3,000 / yr for GDPR - scoping, evidence, gap closure, and the path to demonstrable accountability. Add other frameworks at the same rate, only when you need them.
Book a call
Enterprise
Custom

Over $5M revenue or 50 staff. Negotiated to your scale and obligations.

  • Everything in Startup
  • Dedicated security lead
  • Custom SLAs & response times
  • Audit & board reporting
  • Scaled to your headcount
  • Procurement & MSA support
Talk to us
IncludedArticle 32 requires regularly testing the effectiveness of your security measures. Your penetration testing is already in the flat plan - which is most of that obligation, evidenced.
Compliance billed per framework - no per-seat fees, ever. Auditor and certification-body fees are billed by them, not by us.

The people who already handed it over.

"Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else."
EchoWin
"Sythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing."
Maru AI
"The strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast."
Naked Denver

GDPR, honestly answered.

The questions that come up on every GDPR scoping call, answered before you have to ask them.

Can we be GDPR certified?
Not in any way your customers will recognise. Article 42 anticipates certification schemes but none is in general use, so nobody can issue you a meaningful GDPR certificate. What you can hold is demonstrable accountability, which is what legal reviews actually examine.
We are a processor, not a controller. What is on us?
Article 28 terms, Article 30(2) records of the processing you carry out on controllers' behalf, Article 32 security, assisting controllers with data subject requests, notifying them of breaches without undue delay, and controlling your own sub-processor chain.
Do we need an EU representative or a DPO?
A representative under Article 27 if you have no EU establishment but target or monitor people in the EU, with narrow exemptions. A DPO under Article 37 in specific cases - public authorities, large-scale systematic monitoring, or large-scale special-category data. We assess both during scoping.
How does GDPR relate to ISO 27001 or SOC 2?
The Article 32 security obligations overlap heavily with both, so evidence collected once carries across. What GDPR adds is the documentation layer - records, agreements, rights, transfers - which neither security framework requires.
What about UK GDPR?
The UK regime is substantially aligned, with its own supervisory authority and its own transfer mechanism. We run them together rather than as two programmes.

Pass the DPA review the first time.

A 30-minute call. We will tell you what your Article 30 records are missing, where your transfer basis is thin, and what demonstrable accountability actually costs - whether or not you hire us.