GDPR Processor Framing

European Union GDPR Article 28 processor and Article 32 security evidence.

European Union buyers document Trustholm as a processor with subprocessors transparency and security measures-we do not claim GDPR product compliance badges.

GDPR Processor Framing

Framework evidence framing before detailed tables below.

European corporate office tower representing GDPR and EU compliance buyers

Compliance framing

GDPR Processor Framing

Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.

  • Reproduce audit export in trial
  • Download trust pack for binders
  • Regional hub cross-links
Gaprows published openly
Download trust pack

This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.

European Union and EEA buyers evaluate MSP SaaS under GDPR Article 28 processor obligations and shared responsibility for Article 32 security of processing. Trustholm typically acts as a processor for personal data processed on behalf of MSP tenants (administrator identities, audit metadata, operational telemetry subject to configuration).

MSPs and end customers often remain controllers for their respective processing purposes.

Processor role and subprocessors

Published subprocessors appear at /trust/subprocessors with update notification terms for paid customers. Data Processing Agreement terms are negotiated during commercial onboarding-not inferred from marketing copy alone. Architecture overview and trust pack downloads support ICT third-party registers required by regulated customers.

Article 32 - security of processing

Technical measures include schema-per-tenant isolation, JWT tenant binding for portal users, MFA options, signed script policy, and exportable security audit trails. Organisational measures-personnel access reviews, incident response runbooks, penetration testing cadence-remain customer and MSP obligations.

Data subject rights

Subject access, erasure, and restriction workflows execute within the controller's program. Trustholm provides export APIs and tenant-scoped data boundaries; MSPs configure retention, legal bases, and response procedures. Do not claim the product automates all GDPR rights outcomes without customer policy context.

Cross-border transfers

Transfer mechanisms (SCCs, adequacy, supplementary measures) are documented in enterprise DPA schedules. Marketing pages describe launch region options; exact residency for your contract is confirmed during onboarding via security@trustholm.com.

MSP positioning in EU procurement

Include Trustholm vendor evidence in your customer's DPIA and processor register entries. Clarify processing purposes: script orchestration audit metadata vs customer content in scripts (customer responsibility for data minimisation in script bodies).

What we do not claim: GDPR product compliance badges or certification marks. Compliance is a program outcome for the controller/processor relationship you document with legal counsel.

Procurement tip: Attach subprocessors list and architecture overview from /trust/downloads to your DPIA appendix before legal review cycles begin. Request enterprise DPA drafts via security@trustholm.com.

TopicEvidenceStatusNotes
Processor role clarityDPA terms; subprocessors list at /trust/subprocessorsShipped-
Security of processing (Art. 32)Tenant isolation, audit export, MFA, signing policyShipped-
Data subject rights toolingCustomer-operated export/erasure in tenant boundaryPartialMSP configures retention and subject workflows
GDPR product compliance badgesCompliance is program outcome; we do not claim product badgesGap-

Frequently asked questions

Is Trustholm a controller or processor?

Typically processor for tenant operational data; MSPs and end customers often remain controllers for their processing purposes. Confirm with legal counsel for your deployment.

Where is the subprocessors list?

Published at /trust/subprocessors with update terms for paid customers.

Do you provide a DPA?

Yes during enterprise onboarding. Trial terms are not a substitute for Article 28 processor agreements in regulated procurement.

How do data subject requests work?

Controllers operate subject rights programs. Trustholm provides export within tenant scope; MSPs configure procedures and legal bases.

What about cross-border transfers?

Transfer mechanisms are documented in DPA schedules. Request residency detail via security@trustholm.com during evaluation.

Can we claim GDPR compliance on RFP responses?

Avoid product-level GDPR compliance claims. Cite technical measures, DPA readiness, and subprocessors transparency instead.