Kuulo
← Trust Centre
EU GDPR mark

Data protection

EU General Data Protection Regulation

For a cross-border system, compliance depends on the actual data path and operating model—not the location of a marketing team. The system needs a clear explanation of what is collected, where it goes and which party is responsible at each step.

Applied through data-protection by designEUR-Lex regulation

The framework

What EU GDPR is for.

The EU General Data Protection Regulation is the European framework for protecting personal data. It sets requirements around lawful processing, data-subject rights, security, accountability, international transfers and controller or processor responsibilities.

How we work with it

Make the obligation usable.

  • Identify the data path and the responsibilities of each organisation involved.
  • Design for minimisation, purpose limitation, access control and reviewable processing.
  • Prepare the records, risk assessment and contractual answers required for the use case.

What we can leave behind

Evidence a reviewer can follow.

  • Data-flow and role map
  • DPIA support
  • Processor and security questionnaire support
Request documentation →

Concrete delivery evidence

How this showed up in client work.

Public project material records GDPR requirements in the CRM platform and a DPIA plus client security review in the regulated health platform. The evidence is presented as delivery work shaped around the client's data flows, not as a one-size-fits-all legal conclusion.

Keep the map connected

Need this mapped to your system?

Start with the evidence your review needs.

Talk to us →