Blog · Learn hub · 3 August 2026

What is GDPR-compliant software?

GDPR-compliant software handles personal data the way the EU's General Data Protection Regulation requires: it collects only what it needs, secures it, can export or delete it on request, and comes with a data-processing agreement stating who processes what, and where. Compliance is a property of how a vendor operates — not a badge — so the real test is asking where your data lives and who could be compelled to hand it over.

“GDPR-compliant” appears on a lot of pricing pages and means anything from “we did the work” to “our lawyer said we could write this”. Since the regulation — the EU’s General Data Protection Regulation, in force since May 2018 — has no official product logo, it’s worth knowing what the claim should actually cash out to.

What does the GDPR actually require of software?

The regulation binds organisations, and your software vendors act as your processors — companies handling personal data on your instructions. For a tool to support your compliance rather than undermine it, a few things must be true: it collects no more data than the job needs; access is controlled and logged; data can be exported and genuinely deleted when someone exercises their rights; breaches can be detected and reported; and the vendor signs a data-processing agreement (DPA) — the Article 28 contract that lists what is processed, where, and by which sub-processors.

What should you ask a vendor?

QuestionWhy it matters
Where is the data physically hosted?Determines which transfer rules apply at all
Will you sign a DPA?Without one, using the tool is itself a violation
Who are your sub-processors?Your data flows to them too — you’re accountable for the chain
Can we export and delete everything?Access and erasure rights have deadlines
Is the parent company outside the EU?Foreign law may reach the data regardless of where it sits

A vendor that answers these in writing is doing compliance. A vendor that answers with a badge is doing marketing.

Why does hosting location matter so much?

Because law follows the company as well as the server. The US CLOUD Act (2018) lets American authorities compel US-based providers to produce data they control even when it’s stored in Europe — which is why “EU region available” from a US parent is a weaker statement than it sounds. EU–US transfers themselves have been legally unstable for a decade: the Safe Harbor and Privacy Shield frameworks were each struck down by the EU Court of Justice (the second in the 2020 Schrems II ruling), and today’s Data Privacy Framework (2023) is the third attempt. Hosting with an EU provider under EU jurisdiction doesn’t make every question disappear, but it removes the two biggest ones.

Where Lyto stands

Lyto is EU-built and EU-hosted, with no US parent company — so the CLOUD Act question doesn’t arise, and GDPR wasn’t retrofitted for a checkbox; it’s the environment the product was built in. We’d still tell you to apply the table above to us like anyone else: the honest vendors are the ones who welcome it.

Frequently asked

Does the GDPR apply to companies outside the EU?

Yes, when they process personal data of people in the EU — the regulation follows the data subject, not the company's address. A US or UK tool with EU users is in scope. That's why "we're not an EU company" is never, on its own, an answer to a GDPR question.

Does using US-based software break the GDPR?

Not automatically. Transfers to the US can be lawful — since July 2023 the EU–US Data Privacy Framework provides a legal basis for certified companies. But that framework is the successor to two arrangements courts struck down, so teams that want to avoid re-doing transfer paperwork each time the ground shifts often simply prefer EU-hosted vendors.

Is there an official GDPR certification for software?

There is no EU-wide "GDPR certified" stamp a product can simply buy. Certification schemes under Article 42 exist but are still narrow in practice, so vendor claims mostly rest on their DPA, their hosting and sub-processor list, and audits like ISO 27001 — documents you can ask for, rather than a logo you have to trust.

Built for teams of 1–10

One connected suite — all seven apps on every plan, from €10 / seat / mo, billed annually.

Start free

14-day free trial · card required · cancel in one click