
Compliance framing
GDPR Processor Framing
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
- Reproduce audit export in trial
- Download trust pack for binders
- Regional hub cross-links
European Union GDPR Article 28 processor and Article 32 security evidence.
European Union buyers document Trustholm as a processor with subprocessors transparency and security measures-we do not claim GDPR product compliance badges.
Framework evidence framing before detailed tables below.

Compliance framing
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.
European Union and EEA buyers evaluate MSP SaaS under GDPR Article 28 processor obligations and shared responsibility for Article 32 security of processing. Trustholm typically acts as a processor for personal data processed on behalf of MSP tenants (administrator identities, audit metadata, operational telemetry subject to configuration).
MSPs and end customers often remain controllers for their respective processing purposes.
Published subprocessors appear at /trust/subprocessors with update notification terms for paid customers. Data Processing Agreement terms are negotiated during commercial onboarding-not inferred from marketing copy alone. Architecture overview and trust pack downloads support ICT third-party registers required by regulated customers.
Technical measures include schema-per-tenant isolation, JWT tenant binding for portal users, MFA options, signed script policy, and exportable security audit trails. Organisational measures-personnel access reviews, incident response runbooks, penetration testing cadence-remain customer and MSP obligations.
Subject access, erasure, and restriction workflows execute within the controller's program. Trustholm provides export APIs and tenant-scoped data boundaries; MSPs configure retention, legal bases, and response procedures. Do not claim the product automates all GDPR rights outcomes without customer policy context.
Transfer mechanisms (SCCs, adequacy, supplementary measures) are documented in enterprise DPA schedules. Marketing pages describe launch region options; exact residency for your contract is confirmed during onboarding via security@trustholm.com.
Include Trustholm vendor evidence in your customer's DPIA and processor register entries. Clarify processing purposes: script orchestration audit metadata vs customer content in scripts (customer responsibility for data minimisation in script bodies).
What we do not claim: GDPR product compliance badges or certification marks. Compliance is a program outcome for the controller/processor relationship you document with legal counsel.
Procurement tip: Attach subprocessors list and architecture overview from /trust/downloads to your DPIA appendix before legal review cycles begin. Request enterprise DPA drafts via security@trustholm.com.
| Topic | Evidence | Status | Notes |
|---|---|---|---|
| Processor role clarity | DPA terms; subprocessors list at /trust/subprocessors | Shipped | - |
| Security of processing (Art. 32) | Tenant isolation, audit export, MFA, signing policy | Shipped | - |
| Data subject rights tooling | Customer-operated export/erasure in tenant boundary | Partial | MSP configures retention and subject workflows |
| GDPR product compliance badges | Compliance is program outcome; we do not claim product badges | Gap | - |
Typically processor for tenant operational data; MSPs and end customers often remain controllers for their processing purposes. Confirm with legal counsel for your deployment.
Published at /trust/subprocessors with update terms for paid customers.
Yes during enterprise onboarding. Trial terms are not a substitute for Article 28 processor agreements in regulated procurement.
Controllers operate subject rights programs. Trustholm provides export within tenant scope; MSPs configure procedures and legal bases.
Transfer mechanisms are documented in DPA schedules. Request residency detail via security@trustholm.com during evaluation.
Avoid product-level GDPR compliance claims. Cite technical measures, DPA readiness, and subprocessors transparency instead.