GDPR Processor and Controller Framing for MSP SaaS

Updated 2026-06-14

European Union GDPR Article 28 processor and Article 32 security evidence for MSP script orchestration-program framing without compliance badge claims.

GDPR Processor and Controller Framing for MSP SaaS

Visual anchor before the full guide below.

Healthcare IT professional using tablet in a clinical environment

compliance

GDPR Processor and Controller Framing for MSP SaaS

European Union GDPR Article 28 processor and Article 32 security evidence for MSP script orchestration-program framing without compliance badge claims.

  • Reproduce steps in trial
  • Export audit evidence
  • Attach to GRC binder
1session reproduction target
Start free trial

Published 2026-06-14 · Pillar: compliance

European Union and EEA buyers evaluating MSP SaaS platforms operate under GDPR obligations spanning controller accountability, Article 28 processor contracts, Article 32 security of processing, and cross-border transfer rules.

Trustholm typically acts as a processor for personal data processed on behalf of MSP tenants-administrator identities, audit metadata, operational telemetry subject to configuration-while MSPs and end customers often remain controllers for their respective processing purposes.

We do not claim GDPR product compliance badges, certification marks, or outcomes that belong to the controller's compliance program documented with legal counsel.

This resource helps EU procurement teams, DPOs, and MSP vCISOs frame vendor evidence for DPIAs, processor registers, and security questionnaires. It complements /compliance/eu/gdpr-processor-framing with MSP buyer narrative emphasizing honest Shipped/Gap disclosure and contractual terms confirmed during onboarding-not inferred from marketing copy alone.

Processor vs controller in MSP multi-tenant models

Trustholm as processor: Operational data necessary to deliver script orchestration-tenant administrator accounts, security audit rows attributing actions to identities, agent metadata, support artifacts when submitted-processed on documented instructions from the MSP tenant.

MSP as controller (typical): Determines purposes for managing customer estates via the platform, configures retention, instructs subprocessors, and responds to end-customer contractual terms.

End customer as controller (often): Owns personal data in managed endpoints and may impose processor chain requirements on the MSP.

Legal classification varies by deployment. Confirm roles with counsel; marketing pages cannot substitute for DPA schedules.

Article 28 processor obligations-vendor inputs

Published subprocessors appear at /trust/subprocessors with update notification terms for paid customers. Data Processing Agreement terms are negotiated during commercial onboarding. Trial terms are not a substitute for Article 28 processor agreements in regulated procurement.

Processor register entries should cite: subprocessors URL, architecture overview from trust pack downloads, security questionnaire pre-fill, and incident notification terms in enterprise contracts.

Article 32 - security of processing

Technical measures Trustholm ships today:

Schema-per-tenant isolation: Dedicated PostgreSQL schema per tenant namespaces script content, audit history, and configuration-structural separation beyond a shared table with tenant_id alone.

JWT tenant binding: Portal users cannot access arbitrary tenants via header manipulation when JWT TenantId mismatches resolved tenant-returns 403.

Authentication controls: MFA options, OIDC/SAML SSO, RBAC for administrative functions.

Signed script policy and audit export: Integrity enforcement before execution; exportable security audit for assessor and DPO review windows.

Organisational measures-personnel access reviews, penetration testing cadence, incident response execution, backup governance-remain customer and MSP obligations. Trustholm documents platform architecture and support terms; you operate the compliance program.

Data subject rights and export workflows

Subject access, erasure, restriction, and portability workflows execute within the controller's program. Trustholm provides export APIs and tenant-scoped data boundaries; MSPs configure retention, legal bases, and response procedures. Do not claim the product automates all GDPR rights outcomes without customer policy context.

Document in DPIAs: which categories flow through Trustholm (admin identities, audit metadata) versus customer content embedded in script bodies (customer responsibility for data minimisation).

Cross-border transfers and residency

Transfer mechanisms-Standard Contractual Clauses, adequacy decisions, supplementary measures-are documented in enterprise DPA schedules. Marketing pages describe launch region options; exact residency for your contract is confirmed during onboarding via security@trustholm.com.

EU buyers should not assume residency from hero banners alone. Attach DPA transfer schedules to processor register entries.

What we do not claim

Avoid RFP language such as "GDPR certified," "GDPR compliant product," or badges implying regulatory attestation. Compliance is a program outcome for the controller/processor relationship you document with legal counsel.

Gap honesty: WORM audit immutability and native SIEM connector remain backlog. Hash-chain append-only guarantees are not claimed for database-backed audit tables-document compensating controls in DPIA annexes.

MSP positioning in EU procurement

Include Trustholm vendor evidence in your customer's DPIA and processor register entries. Clarify processing purposes: script orchestration audit metadata versus potentially personal data in script parameters (customer minimisation duty).

Financial sector clients may also require DORA ICT register inputs-pair this article with /compliance/eu/dora-ict-risk and EU trust downloads at /trust/downloads.

Trial diligence checklist for EU buyers

Week one: (1) review subprocessors list; (2) export security audit sample; (3) capture IAM and MFA configuration; (4) request DPA draft via security@trustholm.com; (5) document transfer mechanism questions for legal review; (6) attach Shipped/Gap table from trust hub to ICT register draft.

Workshop agenda for DPO and security engineering

Ninety-minute session: map processing purposes to data categories; assign controller/processor roles per tenant model; draft processor register entry template; list Article 32 measures with Trustholm vs customer ownership; schedule quarterly subprocessors review when vendor list updates. Revisit on DPA renewal or major product releases.

Trust hub cross-reference

See /compliance/eu/gdpr-processor-framing for Article 28/32 tables and /trust/subprocessors for live subprocessor list. GDPR compliance badges are not claimed.

Appendix: evidence reproduction steps

Assign a reviewer to open trial tenant, navigate documented UI paths, and capture screenshots with timestamps. Export audit JSON for same session.

Store in immutable GRC folder. Compare results to this article quarterly.

When Shipped/Gap rows change in trust hub, re-run reproduction within ten business days. Attach limitations memo for WORM audit and Sentinel connector backlog.

Include DB operator access policy from hosting provider. Pair technical evidence with customer governance documents-policies, pentest summaries, IR runbooks.

Never substitute marketing copy for reproduced checks in front of assessors. Treat this appendix as a living runbook section owned by security engineering, not a one-time audit artifact.

Schedule annual refresh aligned with trust hub version stamps and major product releases. Link each reproduction run to a change ticket for traceability.

Distribute updated article PDFs to customer-facing teams when dateModified changes. Archive prior versions for twelve months to support assessor lookback questions.

When citing this article externally, include dateModified and pillar metadata in footnotes so readers know content freshness. Internal enablement should link pillar tags to trust hub sections for consistent customer messaging.

Add article slug to internal wiki index for sales engineering quick lookup during live questionnaire calls.

Frequently asked questions

Is Trustholm a controller or processor?

Typically processor for tenant operational data; MSPs and end customers often remain controllers for their processing purposes. Confirm with legal counsel for your deployment.

Where is the subprocessors list?

Published at /trust/subprocessors with update terms for paid customers.

Do you provide a DPA?

Yes during enterprise onboarding. Trial terms are not a substitute for Article 28 processor agreements in regulated procurement.

How do data subject requests work?

Controllers operate subject rights programs. Trustholm provides export within tenant scope; MSPs configure procedures and legal bases.

What about cross-border transfers?

Transfer mechanisms are documented in DPA schedules. Request residency detail via security@trustholm.com during evaluation.

Can we claim GDPR compliance on RFP responses?

Avoid product-level GDPR compliance claims. Cite technical measures, DPA readiness, and subprocessors transparency instead.