By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies
Continuously improve upon the security program while continuing to grow the business.
Compyl works with the technology your organization works with.
Begin building a scalable security program.
Build and maintain a robust risk management process.
Manage vendor due diligence and risk assessments.
Mature your security program quickly.
Create and centralize policies, standards, and procedures.
Securely store and monitor all contracts.
Streamline security with automated efficiencies.
Establish and monitor permissions for all users.
Catalog, access, and track all IT Assets.
Demonstrate the ability to effectively safeguard customer data's security, integrity, confidentiality, and privacy.
Prove the strength of your Information Security Management System to prospects and customers worldwide.
Organizations handling health information need to have measures in place & follow them.
Improve the security posture of information systems used within the federal government.
Guidelines to encourage best practices among financial institutions in Singapore.
This global security and privacy framework provides comprehensive information, risk, and regulatory protection.
We proactively monitor for the latest frameworks to ensure our customers environments remain secure at all times. Contact us and learn about the additional frameworks Compyl supports.
Let Us Guide You Through Your InfoSec & Compliance Journey.
Learn how to use the Compyl Platform.
Watch all Security Session Episodes
Real-world stories on how we help our customers.
Our mission and purpose are unique, just like the solution we created.
We are very serious about our security. See the measures we take.
Join our diverse team of intelligent, respectful, and passionate individuals.
We are ready to secure your organization today!
The General Data Protection Regulation is a wide-ranging set of information security and consumer privacy laws aimed at protecting personal data and privacy. The European Union officially implemented GDPR in May of 2018 to empower EU citizens with control over their data and prevent abusive data collection practices. One of the most common questions for U.S. businesses is who GDPR applies to. Is your company required to comply with GDPR guidelines?
GDPR applies to any organization that processes the personal data of EU citizens or residents. This includes several main groups:
In case you’re wondering, data processing refers to collecting, storing, analyzing, sharing, or otherwise using the information. There are even GDPR rules around deleting consumer data. Basically, GDPR is applicable in the U.S. whenever your company handles private data from EU residents.
For companies with major customers in Europe, it’s fairly obvious that complying with GDPR is necessary. It’s easier for e-commerce businesses to violate GDPR guidelines without realizing it. If any of the following situations apply to your website or e-commerce store, you need to learn about GDPR compliance ASAP:
In other words, even if your primary business activities revolve around U.S. customers, branching out to European markets requires carefully investigating your obligations and complying with GDPR.
GDPR protections can apply to U.S. citizens who are living in an EU member country, even temporarily. Citizenship isn’t a requirement, as GDPR applies based on residency in an EU country. GDPR is a region-based set of regulations, not an ID-based law.
Imagine that your company headquarters are in Miami, but you have offices in Berlin. You decide to transfer several employees from Miami to Germany. Even though they are U.S. citizens, they will live in Berlin for months or years.
GDPR would apply to all of them. You would have to follow GDPR guidelines when it comes to obtaining consent for data processing, videoconferencing, mobile tracking, and similar elements.
The same goes for U.S. citizens who purchase products in the EU while visiting They enjoy the same personal data protections as residents.
What if an EU citizen travels to the U.S.? Does your business have to treat them differently than other customers? No. EU citizens don’t enjoy any special protections when traveling abroad. You only need to follow U.S. consumer protection laws in this situation.
While GDPR always applies to businesses in the EU, the same isn’t always the case for companies that are located in the United States. For example, it doesn’t apply to incidental or occasional transactions.
Say that your e-commerce business sells products in the United States. All of your marketing focuses on an American audience. Of course, the internet means you can’t control who visits your website. Just because a few people in France browsed your website or decided to order a few products, you’re not suddenly obligated to comply with GDPR.
That said, you have to be careful if you use paid search advertising with website cookies. Some Google and Facebook tools allow you to target website visitors with ads, and this can break GDPR requirements. To get around this problem, set regional advertising restrictions.
There are also GDPR exceptions for small businesses. Any company with fewer than 250 employees is not usually required to create a record of data processing activities (unless your business revolves around data collection or the information is likely to hurt consumers if leaked). You would still need to get consent before gathering or using EU consumer data, however.
The GDPR has 99 articles and dozens of pages of requirements, so it’s important to carefully review your obligations if you sell in the EU. Some of the main principles involve:
Not surprisingly, many enterprises employ legal professionals to understand the scope of their responsibilities under GDPR, and to coordinate compliance.
The key factor that determines whether GDPR applies to a business is where its customers reside. If you operate, sell products, or market your services in the EU, then GDPR compliance is a must. Compyl can make complying with GDPR requirements easier by helping you set objectives, follow data security best practices, track progress, and create automated workflows around data gathering. Get GDPR compliant and grow your business in the EU safely.