What is GDPR?

The EU's data-protection regulation governing how personal data is collected, processed, stored, and erased.

The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU law that defines the rights of data subjects (information, access, erasure, portability, objection) and the obligations of controllers and processors. It applies to any business that processes EU residents' data, regardless of where the business is based. PDF Verified is GDPR-compliant: data hosted in EU regions on request, signed DPA available, full export and erasure tooling, and a 72-hour breach-notification protocol.

GDPR and eSignatures

eSignature platforms process personal data — signer names, emails, IPs, biometrics if KYC is enabled. GDPR requires lawful basis (typically contract performance), data minimization, storage limitation, and the right to erasure (with carve-outs for legal-evidence retention).

Right to erasure vs audit retention

GDPR Article 17 grants the right to erasure but allows exceptions for legal claims and statutory record-keeping. PDF Verified honours erasure requests for accounts, with documented carve-outs for contracts where the law requires retention (typically 6-7 years for commercial agreements).

DPA and SCCs

A signed Data Processing Agreement (DPA) is available on every PDF Verified paid plan. For non-EU data flows, we use Standard Contractual Clauses (SCCs) as updated in June 2021.