{"id":1157,"date":"2026-09-10T13:23:48","date_gmt":"2026-09-10T13:23:48","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1157"},"modified":"2026-09-10T13:23:48","modified_gmt":"2026-09-10T13:23:48","slug":"gdpr","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/gdpr\/","title":{"rendered":"GDPR"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: GDPR\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">GDPR reaches companies that have never had an office in Europe. If you sell software to EU customers, the question is not whether it applies but which role you are in when it does.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Compliance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>GDPR is the General Data Protection Regulation, the EU law governing how personal data is handled. It applies wherever the data subjects are in the EU, regardless of where the company processing that data sits. It is a legal obligation with a security component, not a certification you obtain, and there is no such thing as a GDPR certificate issued by a regulator.<\/p>\n<\/div>\n\n<p>Most of what a founder needs to resolve about GDPR comes down to five questions, and only two of them are technical.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#applies\">Does GDPR apply to you<\/a><\/li>\n    <li><a href=\"#roles\">Controller or processor<\/a><\/li>\n    <li><a href=\"#security\">What GDPR requires technically<\/a><\/li>\n    <li><a href=\"#breach\">The 72 hour clock<\/a><\/li>\n    <li><a href=\"#dpdp\">GDPR and the DPDP Act<\/a><\/li>\n    <li><a href=\"#osto\">How Osto helps with GDPR<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"applies\">Does GDPR apply to you<\/h2>\n\n<p>Article 3 sets the territorial scope, and it is deliberately wide. A company registered in Bengaluru with no European entity can still be squarely in scope.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 176\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Three territorial scope tests that bring a company into GDPR scope.\">\n  <rect x=\"12\" y=\"22\" width=\"238\" height=\"88\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"131\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">Established in the EU<\/text>\n  <text x=\"131\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">An entity, branch or staff<\/text>\n  <text x=\"131\" y=\"89\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#b9c1e6\">based in a member state<\/text>\n\n  <rect x=\"260\" y=\"22\" width=\"238\" height=\"88\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"379\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Offering goods or services<\/text>\n  <text x=\"379\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Selling to people in the EU,<\/text>\n  <text x=\"379\" y=\"89\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">paid or free<\/text>\n\n  <rect x=\"508\" y=\"22\" width=\"240\" height=\"88\" rx=\"13\" fill=\"#e9ecfa\"\/>\n  <text x=\"628\" y=\"50\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">Monitoring behaviour<\/text>\n  <text x=\"628\" y=\"72\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Analytics, tracking or<\/text>\n  <text x=\"628\" y=\"89\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">profiling of people in the EU<\/text>\n\n  <rect x=\"12\" y=\"122\" width=\"736\" height=\"42\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"380\" y=\"148\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#3a6f5d\">Any one of the three is enough. Two of them require no European presence at all.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"roles\" class=\"c-sage\">Controller or processor<\/h2>\n\n<p>This is the distinction that decides what you owe, and most B2B SaaS companies are in both roles at once without having written it down.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th><\/th><th>Controller<\/th><th>Processor<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Who it is<\/td><td>The party deciding why and how data is processed<\/td><td>The party processing it on the controller&#8217;s instructions<\/td><\/tr>\n    <tr><td>Typical SaaS example<\/td><td>Your own marketing lists, employee records, prospect data<\/td><td>Your customer&#8217;s end-user data sitting in your product<\/td><\/tr>\n    <tr><td>Main duties<\/td><td>Lawful basis, notices, handling data subject requests, deciding retention<\/td><td>Process only as instructed, secure the data, assist the controller, report incidents to them<\/td><\/tr>\n    <tr><td>Contract needed<\/td><td>Puts the data processing agreement in place<\/td><td>Signs it, and is bound by it<\/td><\/tr>\n    <tr><td>Sub-processors<\/td><td>Approves them<\/td><td>Must disclose them and pass obligations down<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The processor role is what buyers audit<\/p>\n  <p>When an EU customer sends a data processing agreement and a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-questionnaire\/\">security questionnaire<\/a>, they are contracting with you as their processor. The questions are about your controls, your sub-processors and your breach reporting, not about your own marketing list. Companies that prepare for GDPR as a controller and then meet a processor review find they have documented the wrong half.<\/p>\n<\/div>\n\n<h2 id=\"security\" class=\"c-plum\">What GDPR requires technically<\/h2>\n\n<p>Article 32 covers security of processing. It names measures rather than prescribing products, and it asks that they be appropriate to the risk.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>What Article 32 names<\/th><th>What it looks like in practice<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Pseudonymisation and encryption<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">Encryption at rest<\/a> and in transit, plus <a href=\"https:\/\/www.osto.one\/resources\/glossary\/disk-encryption\/\">disk encryption<\/a> on the endpoints data reaches<\/td><\/tr>\n    <tr><td>Confidentiality and integrity<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">Access control<\/a>, least privilege, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">data loss prevention<\/a> and logging<\/td><\/tr>\n    <tr><td>Availability and resilience<\/td><td>Backups, recovery objectives and evidence they have been tested<\/td><\/tr>\n    <tr><td>Ability to restore access<\/td><td>A restoration test with a date on it, not a documented intention<\/td><\/tr>\n    <tr><td>Regular testing and evaluation<\/td><td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">Penetration testing<\/a>, vulnerability management and a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">risk assessment<\/a> that gets revisited<\/td><\/tr>\n    <tr><td>Appropriate to the risk<\/td><td>The measures scale with the sensitivity and volume of what you hold<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>None of this is unfamiliar territory if you already run an <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a>. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> both cover most of Article 32, which is why they are the usual answer when an EU buyer asks how you satisfy it.<\/p>\n\n<h2 id=\"breach\" class=\"c-sky\">The 72 hour clock<\/h2>\n\n<p>A controller must notify its supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in risk. Where risk to individuals is high, the individuals must be told as well.<\/p>\n\n<p>For a processor the obligation is different and tighter in practice: notify the controller without undue delay. Your customer cannot start their own 72 hour clock until you tell them, so a contractual window measured in hours is common in data processing agreements. That makes detection speed a commercial commitment, not just a security aspiration, and it is why <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">incident response<\/a> readiness gets sampled during vendor review.<\/p>\n\n<h2 id=\"dpdp\">GDPR and the DPDP Act<\/h2>\n\n<p>Indian companies increasingly answer to both. The concepts rhyme, the vocabulary does not.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th><\/th><th>GDPR<\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a><\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>The individual<\/td><td>Data subject<\/td><td>Data principal<\/td><\/tr>\n    <tr><td>The decider<\/td><td>Controller<\/td><td>Data fiduciary<\/td><\/tr>\n    <tr><td>The vendor<\/td><td>Processor<\/td><td>Data processor<\/td><\/tr>\n    <tr><td>Lawful bases<\/td><td>Six, including legitimate interests<\/td><td>Consent and specified legitimate uses<\/td><\/tr>\n    <tr><td>Breach reporting<\/td><td>72 hours to the supervisory authority, risk-based<\/td><td>Notification to the Board and affected principals<\/td><\/tr>\n    <tr><td>Security wording<\/td><td>Appropriate technical and organisational measures<\/td><td>Reasonable security safeguards<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The practical consequence is that one control set can serve both. The security measures overlap heavily. What differs is consent handling, notices and the legal paperwork sitting above them.<\/p>\n\n<h2 id=\"osto\">How Osto helps with GDPR<\/h2>\n\n<p>Osto covers the security half. Article 32 measures run as live controls, access, encryption, logging, testing and monitoring, and the compliance module maps them to GDPR alongside <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP<\/a> and over 200 other frameworks from the same control set. Evidence comes out of the platform running the controls rather than from screenshots collected before a review.<\/p>\n\n<p>The half a platform cannot do is worth stating plainly. Lawful basis, privacy notices, data processing agreements, records of processing, international transfer mechanisms, whether you need a data protection officer and how you handle data subject requests are legal and operational decisions. A control platform supports them with evidence. It does not make them for you, and anyone claiming a product delivers GDPR compliance on its own is overstating what a product can do.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">One control set, many frameworks<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Article 32 measures running as live controls, mapped to GDPR, DPDP, SOC 2 and ISO 27001 at the same time. Evidence from the platform that enforces them. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">200+ frameworks mapped &middot; Evidence from live controls &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>Does GDPR apply to a company outside the EU?<\/summary>\n  <p>Yes, if it offers goods or services to people in the EU or monitors their behaviour. No European entity or office is required. An Indian SaaS company with EU customers is typically in scope through the offering test.<\/p>\n<\/details>\n\n<details>\n  <summary>Can you get GDPR certified?<\/summary>\n  <p>No regulator issues a GDPR certificate. Certification schemes exist under Article 42 but adoption is limited. In practice EU buyers accept <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> or <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> plus a signed data processing agreement as evidence of the security measures.<\/p>\n<\/details>\n\n<details>\n  <summary>Are we a controller or a processor?<\/summary>\n  <p>Most B2B SaaS companies are both. You are a processor for the customer data held in your product, and a controller for your own marketing, prospect and employee data. The obligations differ, so both need to be written down.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the 72 hour rule?<\/summary>\n  <p>A controller must notify its supervisory authority within 72 hours of becoming aware of a personal data breach unless risk is unlikely. A processor must tell the controller without undue delay, which contracts often reduce to a fixed number of hours.<\/p>\n<\/details>\n\n<details>\n  <summary>Does GDPR compliance cover the DPDP Act?<\/summary>\n  <p>Partly. The security measures overlap substantially, so one control set can serve both. Consent handling, notices and terminology differ, and the DPDP Act has its own obligations that GDPR work does not automatically satisfy.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident Response<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-questionnaire\/\">Security Questionnaire<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">Encryption at Rest<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>GDPR reaches companies that have never had an office in Europe. If you sell software to EU customers, the question\u2026<\/p>\n","protected":false},"author":8,"featured_media":1158,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[560,561,562],"class_list":["post-1157","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-gdpr","tag-gdpr-compliance","tag-gdpr-for-indian-companies"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1157","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1157"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1157\/revisions"}],"predecessor-version":[{"id":1159,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1157\/revisions\/1159"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1158"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1157"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1157"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}