GDPR you can demonstrate, not just claim.
Article 5(2) puts the burden on you to show compliance, not assert it. We build the records, the agreements, and the rights machinery that make that showable - and run the security obligations underneath.
- Records of processing under Article 30 that match what your systems actually do
- A DPA chain that survives an EU customer's legal review, sub-processors included
- Data subject requests and the 72-hour breach clock as processes, not fire drills















The burden of proof is on the controller. And on you.
GDPR has no certificate to hang on a wall. What it has is an accountability principle - you must be able to demonstrate compliance on request. Everything we build for you exists to make that demonstration possible.
Records that match reality
Article 30 records built from what your systems actually process, not from a workshop where someone guessed. Reviewed as the product changes.
A DPA chain that survives legal review
Your customers' DPAs, your processor terms, and every sub-processor beneath you - tracked with dates and flow-down obligations that actually match.
Data subject rights as a process
Access, erasure, portability, and objection handled inside the one-month deadline, with the identity verification and search path documented before the first request lands.
Transfers you can actually justify
Standard Contractual Clauses, transfer impact assessments, and a documented basis for every route personal data takes out of the EEA.
What GDPR actually asks you to hold.
The obligations that matter for a software company are concentrated in a handful of articles - and they are documentation obligations as much as security ones.
Records of processing
art. 30What personal data you process, why, on what lawful basis, who you share it with, where it goes, and how long you keep it.
Processor agreements
art. 28Contracts with the controllers above you and every sub-processor below, with the mandatory Article 28 terms flowed down intact.
Data subject rights
arts. 12-23Access, rectification, erasure, restriction, portability, and objection - answered within one month, extendable to three with reasons.
Security of processing
art. 32Appropriate technical and organisational measures judged against the risk - encryption, resilience, restoration, and regular testing of their effectiveness.
Breach notification
arts. 33-34Supervisory authority notified within 72 hours of awareness where the breach is likely to risk rights and freedoms; data subjects notified when the risk is high.
DPIAs and transfers
art. 35 - ch. VImpact assessments for high-risk processing, and a lawful basis - adequacy, SCCs, or a derogation - for every transfer out of the EEA.
GDPR has no certification scheme in general use, so nobody can hand you a GDPR certificate. Article 5(2) instead requires demonstrable accountability, which is what your customers' legal teams review and what we build to.
From scoping call to demonstrable accountability.
Two phases are gated - the data mapping and the transfer basis. Both are the questions an EU customer's counsel opens with, and both are cheapest to answer correctly the first time.
Map the personal data
Every processing activity, its lawful basis, its recipients, its retention, and its destination. This mapping is the source of the Article 30 records and everything downstream.
Fix the transfer story
Where personal data leaves the EEA and under what mechanism. SCCs executed, transfer impact assessments written, sub-processor list published and kept accurate.
Implement Article 32 security
The technical and organisational measures, tested rather than asserted - which is the part of GDPR that overlaps almost entirely with the security work already in your plan.
Run rights, breaches, and reviews
DSR handling inside the deadline, the 72-hour breach process rehearsed with our incident response team, and DPIAs when new processing warrants one.
GDPR is $3,000 a year.
The security department is the rest.
Every other vendor in this category makes you book a demo to learn what GDPR costs. Here it is. Your whole security department is one flat price, and compliance is the only thing we bill per framework.
The people who already handed it over.
"Jarred, Andrew, and their team are trusted partners - extensive penetration testing, code analysis, and security reviews that protect our users. We share a vision of prioritizing customer security above all else."
"Sythe Labs was great to work with. Extremely knowledgeable, responsive, and trustworthy. I'd recommend them to anyone looking for security or penetration testing."
"The strategic security recommendations from Sythe Labs have been invaluable. Their expertise helped us put real protection in place while keeping us moving fast."
Real engagements. Real outcomes.
The same programme, run for teams who had no security function when they started.
A four-person team with payment data, no security function, and a Series A closing.
Read the case studyechowinHIPAA attestation held and SOC 2 underway, with the whole department owned by us.
Read the case studyThe Academy of Charter SchoolsA penetration test their IT team rode along on, plus a roadmap of what to harden.
Read the case studyGDPR, honestly answered.
The questions that come up on every GDPR scoping call, answered before you have to ask them.
- Can we be GDPR certified?
- Not in any way your customers will recognise. Article 42 anticipates certification schemes but none is in general use, so nobody can issue you a meaningful GDPR certificate. What you can hold is demonstrable accountability, which is what legal reviews actually examine.
- We are a processor, not a controller. What is on us?
- Article 28 terms, Article 30(2) records of the processing you carry out on controllers' behalf, Article 32 security, assisting controllers with data subject requests, notifying them of breaches without undue delay, and controlling your own sub-processor chain.
- Do we need an EU representative or a DPO?
- A representative under Article 27 if you have no EU establishment but target or monitor people in the EU, with narrow exemptions. A DPO under Article 37 in specific cases - public authorities, large-scale systematic monitoring, or large-scale special-category data. We assess both during scoping.
- How does GDPR relate to ISO 27001 or SOC 2?
- The Article 32 security obligations overlap heavily with both, so evidence collected once carries across. What GDPR adds is the documentation layer - records, agreements, rights, transfers - which neither security framework requires.
- What about UK GDPR?
- The UK regime is substantially aligned, with its own supervisory authority and its own transfer mechanism. We run them together rather than as two programmes.
Pass the DPA review the first time.
A 30-minute call. We will tell you what your Article 30 records are missing, where your transfer basis is thin, and what demonstrable accountability actually costs - whether or not you hire us.