Establishing secure connection…Loading editor…Preparing document…

GDPR Compliance Statement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

GDPR Compliance Statement

This GDPR Compliance Statement is entered into as of Effective Date: by and between Controller Name: with registered address: and Processor Name: with registered address: (each a "Party" and together the "Parties").

RECITALS

WHEREAS, Controller determines the purposes and means of Processing of Personal Data and seeks assurances that Processing activities will comply with applicable data protection obligations, including but not limited to the General Data Protection Regulation relating to the protection of natural persons with regard to the Processing of Personal Data; and

WHEREAS, Processor provides services to Controller which necessarily involve access to or Processing of Personal Data on behalf of Controller and will implement and maintain appropriate technical and organizational measures to protect such Personal Data; and

WHEREAS, the Parties desire to set forth their respective roles, responsibilities and commitments to ensure that Processing is performed in accordance with applicable data protection law.

NOW THEREFORE, in consideration of the mutual covenants herein, the Parties agree as follows:

1. DEFINITIONS

1.1. "Personal Data" means any information relating to an identified or identifiable natural person that is provided to Processor or accessed by Processor in connection with the services described in this Statement.

1.2. "Processing" and related terms shall have the meanings given in applicable data protection law.

2. SCOPE AND PURPOSE OF PROCESSING

2.1. Processor shall Process Personal Data only for the specific documented purposes described as:

2.2. The categories of data subjects and categories of Personal Data to be Processed are set out as follows:

3. TECHNICAL AND ORGANIZATIONAL MEASURES

3.1. Processor represents that it has implemented and will maintain appropriate technical and organizational measures appropriate to the risk, including measures to ensure ongoing confidentiality, integrity, availability and resilience of Processing systems and services.

3.2. The Parties acknowledge that Processor's security measures shall include, at a minimum, the following categories. Processor shall mark each item below to confirm implementation:

Access control and authentication mechanisms (logical access restrictions, MFA where applicable)

Encryption of data at rest and in transit where feasible

Pseudonymisation and minimisation procedures

Documented incident response and breach notification procedures

4. DATA SUBJECT RIGHTS

4.1. Processor shall assist Controller, taking into account the nature of Processing and available information, by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Controller's obligation to respond to requests from data subjects exercising their rights under applicable data protection law.

4.2. Processor shall promptly notify Controller if it receives a request from a data subject relating to Personal Data and shall not respond to such request except on Controller's documented instructions or as required by applicable law.

5. SUB-PROCESSING

5.1. Processor shall not engage another processor (sub-processor) without prior written authorization from Controller. Where authorized, Processor shall ensure by contract that the sub-processor is subject to obligations at least equivalent to those imposed on Processor under this Statement.

6. INTERNATIONAL TRANSFERS

6.1. Processor shall not transfer Personal Data outside the European Economic Area or to any country that does not ensure an adequate level of protection, except on the basis of appropriate safeguards permitted by applicable law and with Controller's prior written authorization. Any permitted transfers shall be documented and Controller will be informed of the destination jurisdictions.

7. SECURITY INCIDENTS AND BREACH NOTIFICATION

7.1. Processor shall notify Controller without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach affecting Controller's Personal Data. Such notification shall include, to the extent possible, a description of the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences and measures taken or proposed.

8. AUDITS AND RECORDS

8.1. Processor shall maintain records of Processing activities and shall, upon reasonable request and subject to confidentiality restrictions, make available to Controller evidence of compliance with this Statement, including audit reports or certifications. Controller may, subject to reasonable notice and during normal business hours, conduct audits or inspections where such audits are necessary to verify compliance.

9. RETENTION AND DELETION

9.1. Processor shall retain Personal Data only for the period necessary to fulfill the documented purposes or as required by law. Upon termination or expiry of the relationship, Processor shall, at Controller's choice, return or securely delete Personal Data and certify deletion where feasible.

10. CONFIDENTIALITY

10.1. Processor shall ensure that all personnel authorized to Process Personal Data are under appropriate confidentiality obligations and have received suitable privacy and security training.

11. LIABILITY AND INDEMNIFICATION

11.1. Each Party shall be liable for breaches of this Statement to the extent caused by its own acts or omissions. Processor shall indemnify Controller for direct losses resulting from Processor's material breach of this Statement, including failure to implement appropriate technical and organizational measures, subject to any limitations agreed in the parties' main services agreement.

12. GOVERNING LAW; ENTIRE AGREEMENT; SEVERABILITY

12.1. This Statement shall be governed by the laws of the jurisdiction specified by Controller: .

12.2. This Statement constitutes the entire agreement between the Parties with respect to the subject matter herein and supersedes prior writings and understandings relating to GDPR compliance commitments. Any amendment must be in writing and signed by authorized representatives of both Parties.

12.3. If any provision of this Statement is held invalid or unenforceable, the remainder of this Statement shall remain in full force and effect and the invalid or unenforceable provision shall be replaced by a valid provision that most closely reflects the Parties' original intent.

13. NOTICES; AMENDMENTS; COUNTERPARTS

13.1. Notices under this Statement shall be given in writing to the contact details set forth below. Amendments shall be effective only if documented in writing and signed by both Parties. This Statement may be executed in counterparts, each of which shall constitute an original and all of which together shall constitute one agreement.

CERTIFICATION

Each Party certifies that the information provided in and attached to this Statement is true, complete and accurate to the best of its knowledge and that it will comply with the obligations set forth herein. The undersigned persons warrant that they are authorized to execute this Statement on behalf of the Party for whom they sign.

Controller:

By:

Date:

Processor:

By:

Date:

Enter text✕

What a GDPR Compliance Statement Is and When It’s Used

A GDPR Compliance Statement is a concise document that describes how an organization handling European Union personal data meets key requirements of the EU General Data Protection Regulation (GDPR). It typically summarizes data categories processed, legal bases for processing, retention periods, third‑party recipients and international transfer mechanisms, data subject rights and contact details for the data controller or EU representative. U.S.-based organizations use this statement to demonstrate transparency, support contractual commitments, and inform data subjects, regulators and partners about privacy practices when EU personal data is involved.

Why a Clear GDPR Compliance Statement Matters

A clear statement increases transparency, reduces regulatory and contractual ambiguity, and documents the organization’s chosen legal bases and safeguards for processing EU personal data.

Why a Clear GDPR Compliance Statement Matters

Organizations and Roles That Typically Prepare This Statement

The GDPR Compliance Statement is commonly completed by privacy, legal, compliance, or IT teams in organizations processing EU personal data.

  • Privacy and legal teams — Draft and approve lawful-basis language and retention policies, coordinate with in-house counsel and external advisors.
  • IT and security teams — Describe technical and organizational measures used to protect data in transit and at rest.
  • Data protection officers (DPOs) — Maintain the statement, handle data subject queries, and liaise with supervisory authorities.

For smaller organizations, a single privacy lead or external counsel may compile and certify the statement on behalf of the company.

Core Sections to Include in a Professional GDPR Compliance Statement

A well-structured statement covers identity, processing activities, legal basis, safeguards for transfers, data subject rights, and retention. Each section should be concise, accurate and aligned with internal records and contracts.

Controller Identity

Name and contact details of the data controller and EU representative, if any.

Processing Summary

Clear description of categories of personal data and processing purposes.

Legal Basis

Specify the GDPR legal basis (consent, contract, legitimate interest, etc.).

Transfers & Safeguards

Describe international transfers and safeguards (SCCs, adequacy, etc.).

Data Subject Rights

Explain rights and how to exercise them, including contact details.

Retention & Security

State retention periods and technical/organizational measures protecting data.

Security and Compliance Details to Record

Encryption: TLS 1.2/1.3 in transit; AES-256 at rest
Certifications: ISO 27001; SOC 2 Type II available
Privacy Frameworks: GDPR compliant; EU‑U.S. Data Privacy Framework
Regulated Controls: 21 CFR Part 11; PCI DSS where applicable
Health Data: HIPAA support with BAA required
Accessibility: WCAG 2.0 Level AA conformance

Step‑by‑Step: Preparing and Publishing the Statement

Follow a structured workflow: gather facts, draft, review with stakeholders, finalize signoff, and publish where data subjects can access it.

  • 01
    Map Processing: Inventory data categories and processing activities across systems.
  • 02
    Draft Statement: Write concise sections using mapped facts and chosen legal bases.
  • 03
    Internal Review: Have legal, security and business owners validate accuracy.
  • 04
    Publish & Record: Post the statement and retain a signed copy for audit trails.

How to Configure an Online Statement Workflow

Set up a reproducible online workflow that enforces required fields, captures audit data, and stores the signed statement securely.

Field Configuration
Required Fields Make controller, purpose, legal basis and retention mandatory
Authentication Use email or stronger MFA for signers and reviewers
Audit Trail Enable timestamp, IP capture, and action log retention
Document Storage Encrypt at rest and restrict access by role

Where to Send or Publish the Final Statement

Distribute the finalized GDPR Compliance Statement to internal owners, external partners, and make an accessible public copy when required.

  • Internal Record: Store signed copy with compliance and legal teams
  • Data Subjects: Publish a public summary on the website
  • Contractual Partners: Share via secure link or contract annex
  • Supervisory Authority: Provide on request during investigations or audits

Digital Signing and eSubmission: Platform Requirements

Use an eSignature platform that captures a robust audit trail, supports secure storage, and meets applicable compliance needs.

  • Audit Trail: Timestamps, IP, signer attribution
  • Integrations: CRM, cloud storage, and identity providers
  • Security Controls: Encryption, role-based access

Ensure the chosen provider supports regulatory certifications and contractual terms required for international transfers and data protection.

Key Timelines and Response Expectations

Certain timelines are critical for regulatory compliance and incident management; align internal SLAs with legal requirements where they apply.

Breach Notification:

72 hours (GDPR Article 33) from becoming aware of a personal data breach

Data Subject Requests:

Respond without undue delay and within one month under GDPR

Review Cadence:

Review statement annually or when processing changes occur

Recordkeeping:

Retain versioned signed statements for audit and contractual proof

Contract Updates:

Amend supplier clauses before new processing begins

Common Mistakes to Avoid When Preparing the Statement

  • Using vague legal bases such as 'business purposes' without documenting the specific legitimate interest and balancing test.
  • Failing to list third‑party recipients and transfers, which can lead to non‑compliance with transparency obligations.
  • Neglecting to update the statement after operational or vendor changes, creating mismatches with internal records.
  • Omitting retention specifics or tying retention to vague phrases like 'until no longer needed', which invites regulatory scrutiny.

Consequences of an Incorrect or Missing Statement

Regulatory Fines: Significant administrative fines and sanctions
Breach Costs: Notification and remediation expenses
Contract Risk: Loss of contracts or supply chain restrictions
Reputational Harm: Customer trust erosion
Litigation: Civil claims and class actions
Operational Delays: Blocked international transfers

Typical eSignature Pricing and Compliance: signNow First

For organizations delivering a GDPR Compliance Statement, compare basic pricing, trial availability, bulk send features, audit trails and HIPAA support when evaluating eSignature vendors.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by vendor Varies by vendor Varies by vendor Varies by vendor
Bulk Send Yes (premium) Yes Yes Yes Varies by plan
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes (BAA) Yes Yes No No

Practical Examples from Real Organizations

These brief examples show how organizations summarize processing and controls without disclosing sensitive operational detail.

Optica Ventures (COO)

Optica summarized processing for investor communications and HR records in a single page statement to improve transparency.

  • They listed categories, legal bases and transfer safeguards.
  • The concise public statement reduced repeated ad hoc requests and helped standardize vendor assessments across the portfolio.

Fertility Centers of Illinois (Founder)

The center used a short statement describing patient data categories and retention tied to medical record rules.

  • It referenced HIPAA safeguards and access controls.
  • Publishing this statement alongside patient forms clarified responsibilities and streamlined requests from partner clinics and insurers.

Practical Tips for Accurate, Efficient Completion

Follow these best practices to reduce risk, speed approvals, and maintain clarity across teams and external stakeholders.

Base on Inventory
Draft the statement using an up-to-date data inventory; undocumented processing leads to omissions and regulatory exposure.
Keep It Concise
Use plain language and avoid legalese. Regulators and data subjects need clear, understandable information.
Version Control
Apply formal versioning and store signed copies with timestamps to demonstrate historical compliance at audit time.
Coordinate Contracts
Align the statement with vendor contracts, Data Processing Agreements and any SCCs or transfer mechanisms in use.

FAQs and Troubleshooting for GDPR Compliance Statements

Answers to common questions about scope, legal basis, signing, and cross-border concerns when preparing a GDPR Compliance Statement.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users