Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →The GDPR, or General Data Protection Regulation, is the European Union's data protection law governing how organizations collect, use, and safeguard the personal data of people in the EU. It grants individuals rights over their data and requires a lawful basis for processing. It applies to any organization handling EU residents' data, regardless of where the organization is based.
GDPR applies extraterritorially, so a company anywhere can fall under it by serving EU users. Core obligations include a lawful basis for processing, honoring data-subject rights, data protection by design, and breach notification within 72 hours.
Penalties are significant: up to 20 million euros or 4 percent of global annual revenue, whichever is higher. Many of its concepts map closely to other modern privacy laws, including Quebec Law 25.
traztech delivers privacy and data-protection readiness for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
GDPR shows up as a DPA to sign, a data subject request you have to answer inside a deadline, or a security questionnaire asking where personal data is stored and who can reach it.
The work that pays off is upstream of policy text: knowing what personal data you hold, where it flows, who processes it on your behalf and what your lawful basis is. Everything else is downstream of that.
It can. If you offer goods or services to people in the EU or monitor their behaviour, it applies regardless of where you are established.
A controller decides why and how personal data is processed. A processor acts on the controller's instructions. Most B2B SaaS companies are processors for customer data and controllers for their own staff and prospect data.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.