Articles

GDPR Caroline carver GDPR Caroline carver

Think GDPR Doesn’t Apply? Think Again

The GDPR was deliberately designed to reach beyond Europe's borders. Whether it applies is not determined solely by where your organisation is located or where your customers are based. Instead, it focuses on the personal information being processed, the people it relates to, and the role your organisation plays in that processing.

Read More
GDPR, Governance Caroline carver GDPR, Governance Caroline carver

Controller or Processor: Decide Early

Somewhere between the first line of code and the first paying customer, there is a quiet decision every SaaS builder makes, whether privacy is something you will design, or something you will retrofit. Most choose the latter, not out of neglect, but out of urgency to get to market.

When you build a SaaS product, you are not just creating features. You are defining relationships.

Read More
GDPR Caroline carver GDPR Caroline carver

When does the GDPR actually apply to New Zealand companies?

In conversations with New Zealand organisations about their privacy programme, one theme comes up again and again: “We’re using a processor in Europe, so the GDPR must apply to us.” Simply using an EU-based processor does not mean that GDPR applies unless other conditions are met.

Read More