Compliance / GDPR

General Data Protection Regulation for MSPs

The EU's comprehensive data-protection law — reaching a US-based MSP the moment a client processes personal data belonging to EU residents, regardless of where the client or the MSP is physically located.

Why this reaches an MSP, not just the client

GDPR's extraterritorial reach doesn't require an EU office — a US client running an e-commerce site that ships to EU customers, or a SaaS product with EU users, is processing EU personal data and can fall under GDPR, which means the MSP managing that client's systems is handling regulated data too, whether or not anyone framed it that way at contract signing.

What the Nexus compliance module tracks

  • Posture tracked against GDPR's core technical requirements — access control, encryption, breach-notification readiness, data-processing records — using the same three-state model (implemented, partial, planned) as every other framework here
  • Evidence attached directly to the control it supports, the same evidence model used across the compliance module rather than a GDPR-specific process to learn separately
  • Data subject rights handling (access, deletion, portability requests) tracked as its own control, not folded into a generic "privacy" checkbox
  • A QBR rollup that gives a client's own GDPR accountability owner — often not a dedicated privacy officer at this size — a straight answer instead of a compliance guess

This describes what the module tracks against GDPR — not a claim that Nexus or any client on it is certified or audited against it. See the compliance & QBR module for the full picture, or read the blog for more on how we think about compliance tooling.

Ready to see GDPR posture tracked for real?

Join the design-partner cohort and we'll walk through the control mapping for your own clients.