Back to Articles & Documents

GDPR Compliance Guide

LegalAugust 29, 2026

This guide describes the practical controls Kairos uses to support responsible handling of personal data under the General Data Protection Regulation.

Scope and roles

GDPR responsibilities depend on the activity. A client may act as controller for its product, while Kairos may act as processor when handling data on documented client instructions.

The applicable role, purposes, data categories, and instructions should be confirmed for each engagement before processing begins.

We keep processing limited to defined purposes and avoid collecting information that is not needed for the service.

Records, notices, and contracts should describe the processing clearly enough for people and organizations to understand it.

This guide supports, but does not replace, a project-specific data protection assessment.

Core GDPR principles

Kairos aligns its process with lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability.

Security measures should be proportionate to the nature, scope, context, and risk of the processing.

Data subject rights

We support processes for access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where those rights apply.

Requests should be routed to the responsible controller and handled within applicable legal deadlines.

Processors assist controllers with reasonable information and technical measures, but the controller remains responsible for deciding the purpose and legal basis.

Incident response

We maintain a process for identifying, containing, investigating, and documenting suspected personal-data incidents.

Where a client is the controller, Kairos will notify the client without undue delay in line with the agreed contract and incident procedure.

Access is reviewed on a need-to-know basis, and credentials should be removed when a person no longer needs them.

International transfers

If personal data is transferred outside the EEA, the parties should identify an appropriate legal mechanism and document the relevant safeguards.

Vendor review should consider location, subprocessors, security controls, and whether the transfer is necessary for the service.

Governance

We review privacy practices as services and risks change, keep appropriate records, and use contractual terms to clarify responsibilities with clients and providers.

Practical next step

Before processing personal data, confirm the roles, purpose, categories, retention, access, vendors, transfer locations, and incident contacts for the specific project.

This guide is general information, not legal advice or a guarantee of compliance for every processing activity.

Conclusion

A qualified privacy professional should review the project context, records, contracts, and controls before relying on this guide.

We build and improve digital products for real operating workflows.

Tell us where the product is now and where it needs to go. We’ll help define the clearest next step. See all FAQs