Compliance

Compliance means adhering to all legal, regulatory, and internal requirements. In a messaging context it spans GDPR/data protection, industry-specific regulation, contract clauses (DPA), and technical security standards. Compliance is not a checkbox — it's an ongoing state.

What does compliance mean?

Compliance is the umbrella term for an organization's duty to follow all relevant rules — statutory, regulatory, and voluntarily adopted. In messaging contexts that means: data may only be processed within the scope law and contract allow, and that must be demonstrable at any time.

Compliance is broader than GDPR-compliant messaging: GDPR is the main pillar, but next to it stand IT-security standards, industry-specific regulation (e.g., banking supervision for fintechs), labor-law requirements, and internal corporate policies.

Key compliance domains for messaging

DomainWhat it coversWho audits
Data protection (GDPR)Collection, storage, use of personal dataSupervisory authorities; internal: data protection officer
IT securityEncryption, access control, backups, incident responseAudits (ISO 27001, SOC 2), internal audit
Processor agreementsDPA with every provider that processes data on your behalfContract compliance, supervisors
TelecommunicationsNational rules for SMS, calls, marketing messagesNational regulators
Industry complianceSector-specific: healthcare (HIPAA), finance, child safetyIndustry oversight

Compliance requirements in everyday messaging

  • Opt-in before any marketing message: See double opt-in for the clean implementation.
  • Identifiable sender: Every message must make it clear who is sending it (imprint logic).
  • Opt-out option: Every marketing recipient must be able to unsubscribe with one click (or a stop word like "STOP").
  • Redacted logs: Server logs must not contain unintentional personal data (e.g., full message contents).
  • Data processing agreement: Sign one with every provider before first use.
  • Data deletion: On request, data must be deleted within 30 days — no back doors.

Compliance standards SMBs should know

  • GDPR — EU-wide General Data Protection Regulation.
  • ISO 27001 — international standard for information security management.
  • SOC 2 Type II — audit standard for service providers, important for US customers.
  • BSI C5 — cloud computing compliance catalog from the German Federal Office for Information Security.
  • EU AI Act — phased in from 2026, regulates AI systems including chatbots.

Data residency: where data lives is compliance

For many European SMBs, EU data residency is not only legal but also a strategic concern. It covers:

  • Servers in EU data centers (Frankfurt, Amsterdam, Dublin)
  • Backup replicas also in the EU
  • Support staff accessing data also located in the EU
  • Sub-processors are likewise GDPR-compliant and contractually bound

SendSeven hosts exclusively in Germany (Frankfurt), lists sub-processors in the privacy policy, and provides a DPA that can be signed digitally before contract start.

What compliance is not

Compliance is not a marketing statement or a checkbox. "We are GDPR-compliant" by itself is worthless without demonstrable processes. Real compliance means:

  1. Named responsibilities (data protection officer, security officer)
  2. Documented processing activities (Article 30 GDPR register)
  3. Regular internal audits
  4. Incident response plan for data breaches
  5. Training for staff handling personal data