Compliance
Compliance means adhering to all legal, regulatory, and internal requirements. In a messaging context it spans GDPR/data protection, industry-specific regulation, contract clauses (DPA), and technical security standards. Compliance is not a checkbox — it's an ongoing state.
What does compliance mean?
Compliance is the umbrella term for an organization's duty to follow all relevant rules — statutory, regulatory, and voluntarily adopted. In messaging contexts that means: data may only be processed within the scope law and contract allow, and that must be demonstrable at any time.
Compliance is broader than GDPR-compliant messaging: GDPR is the main pillar, but next to it stand IT-security standards, industry-specific regulation (e.g., banking supervision for fintechs), labor-law requirements, and internal corporate policies.
Key compliance domains for messaging
| Domain | What it covers | Who audits |
|---|---|---|
| Data protection (GDPR) | Collection, storage, use of personal data | Supervisory authorities; internal: data protection officer |
| IT security | Encryption, access control, backups, incident response | Audits (ISO 27001, SOC 2), internal audit |
| Processor agreements | DPA with every provider that processes data on your behalf | Contract compliance, supervisors |
| Telecommunications | National rules for SMS, calls, marketing messages | National regulators |
| Industry compliance | Sector-specific: healthcare (HIPAA), finance, child safety | Industry oversight |
Compliance requirements in everyday messaging
- Opt-in before any marketing message: See double opt-in for the clean implementation.
- Identifiable sender: Every message must make it clear who is sending it (imprint logic).
- Opt-out option: Every marketing recipient must be able to unsubscribe with one click (or a stop word like "STOP").
- Redacted logs: Server logs must not contain unintentional personal data (e.g., full message contents).
- Data processing agreement: Sign one with every provider before first use.
- Data deletion: On request, data must be deleted within 30 days — no back doors.
Compliance standards SMBs should know
- GDPR — EU-wide General Data Protection Regulation.
- ISO 27001 — international standard for information security management.
- SOC 2 Type II — audit standard for service providers, important for US customers.
- BSI C5 — cloud computing compliance catalog from the German Federal Office for Information Security.
- EU AI Act — phased in from 2026, regulates AI systems including chatbots.
Data residency: where data lives is compliance
For many European SMBs, EU data residency is not only legal but also a strategic concern. It covers:
- Servers in EU data centers (Frankfurt, Amsterdam, Dublin)
- Backup replicas also in the EU
- Support staff accessing data also located in the EU
- Sub-processors are likewise GDPR-compliant and contractually bound
SendSeven hosts exclusively in Germany (Frankfurt), lists sub-processors in the privacy policy, and provides a DPA that can be signed digitally before contract start.
What compliance is not
Compliance is not a marketing statement or a checkbox. "We are GDPR-compliant" by itself is worthless without demonstrable processes. Real compliance means:
- Named responsibilities (data protection officer, security officer)
- Documented processing activities (Article 30 GDPR register)
- Regular internal audits
- Incident response plan for data breaches
- Training for staff handling personal data