Legal
GDPR Compliance at Native Keeper
How Native Keeper supports compliance with the UK GDPR and EU GDPR, including sensitive HR data, international transfers, and data subject rights.
Last updated: 10 June 2026
Overview
Quick answer for procurement teams: Native Keeper is operated by NeonStack Ltd, a UK company. We process employee and workforce data under the UK GDPR and EU GDPR. We sign a DPA with every paying customer, maintain a public Sub-processors list, support international transfers via SCCs and the UK IDTA, handle Special Category and Criminal-Offence Data on a lawful basis, and provide self-service tools for data subject rights. Skip to the Compliance Checklist or download our DPA.
What this page covers
The General Data Protection Regulation (GDPR) and its UK equivalent (UK GDPR) set the global benchmark for how Personal Data must be collected, processed, and protected. If you're using Native Keeper to hold records about employees, workers, contractors, or applicants — anywhere in the world — data protection law applies, and we're part of how you stay compliant.
This page explains:
Who we are and where we fit in the GDPR picture
What we do to comply with GDPR ourselves
How we handle sensitive HR data — including Special Category and Criminal-Offence Data
What we provide to you so you can comply with your obligations
What you (the customer) remain responsible for
How to get the documents your procurement team will ask for
If you just need the documents, jump to Resources. For everything else, read on.
1. Who plays what role under GDPR
GDPR distinguishes between Controllers (who decide why and how data is processed) and Processors (who process data on a Controller's behalf, under instruction).
In a typical Native Keeper scenario, the roles look like this:
Scenario
Controller
Processor
What this means
You add an employee's record to Native Keeper. Their DBS certificate is uploaded and tracked.
You (our customer)
Native Keeper
You decide what to collect, why, and what to do with it. We process it on your behalf under our DPA.
You sign up for a Native Keeper account. We collect your billing email and account details.
Native Keeper
—
We are the Controller for your own account data, governed by our Privacy Policy.
An employee whose records you hold in Native Keeper wants to exercise GDPR rights over their data.
You
Native Keeper
Your employee's rights are exercised against you as their employer. We help you respond using our self-service tools.
This distinction matters because GDPR places different obligations on each role. Our Data Processing Agreement sets out our obligations as Processor in detail.
2. Where Native Keeper sits geographically
Detail
Information
Legal entity
NeonStack Ltd, company number 16933096
Country of establishment
United Kingdom (England and Wales)
Registered office
The North Colchester Business Centre, 340 The Crescent, Colchester, England, CO4 9AD
Trading name
Native Keeper
ICO registration
[ICO REGISTRATION NUMBER — PENDING]
Primary supervisory authority
UK Information Commissioner's Office (ICO)
EU Representative (Art. 27)
Not currently appointed. Will be appointed before offering the Service at scale to EU Data Subjects.
Because we're established in the UK, we are subject to:
The UK GDPR
The Data Protection Act 2018
The Privacy and Electronic Communications Regulations (PECR)
When we serve customers and Data Subjects in the EEA, we additionally comply with the EU GDPR and apply appropriate safeguards for any cross-border transfer.
For customers and Data Subjects in other jurisdictions (United States, Canada, Australia, and elsewhere), we honour rights and obligations arising under applicable local data-protection law — see Section 8 below.
3.1 We have built our product to be privacy-respecting by design
GDPR Article 25 requires "data protection by design and by default". This shows up in Native Keeper as:
Access control by default. Employee records are visible only to Admin Users who have been explicitly granted access. No cross-customer visibility.
You own your data. Workforce records are yours. You can export them at any time and delete them permanently.
No reuse of workforce content for AI training. We do not use the content of employee records to train our or any third party's general-purpose AI models. See DPA, Section 9.
Customer-configurable retention. You set how long records persist — because HR data often has statutory retention obligations far longer than a typical SaaS retention window.
Encryption everywhere. All Customer Personal Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), including uploaded documents such as DBS certificates and Right to Work evidence.
Audit logs of admin actions available on supported plans.
Regional data residency available on supported plans — EU-only or UK-only storage.
3.2 We sign a DPA with every paying customer
Every customer on a paid plan automatically accepts our Data Processing Agreement at signup. The DPA includes:
Article 28 GDPR-compliant processing terms
EU Standard Contractual Clauses (SCCs) — Modules 2 and 3
UK International Data Transfer Addendum (IDTA)
Sub-processor general authorisation with 30-day prior notice for changes
72-hour breach notification commitment
Specific handling of Special Category and Criminal-Offence Data
Detailed Annexes covering processing purpose, data categories, and security measures
Enterprise customers requiring a counter-signed version can request one from legal@nativekeeper.com.
3.3 We publish a current list of Sub-processors
Every third party that may Process Customer Personal Data on our behalf is listed at nativekeeper.com/legal/sub-processors, with their purpose, location, and the safeguards applied to international transfers.
You can subscribe to email notifications and receive 30 days' prior notice of any addition or replacement.
3.4 We handle international transfers properly
For data leaving the UK or EEA, we use:
EU Standard Contractual Clauses (SCCs) — Commission Decision (EU) 2021/914
UK International Data Transfer Addendum (IDTA) issued by the ICO
EU-US Data Privacy Framework for certified US recipients (Vercel, Stripe, Resend, and others where certified)
Adequacy decisions where applicable
Supplementary technical measures including end-to-end encryption, key isolation, and access restrictions
Regional data residency (data stored exclusively within a chosen region) is available on supported plans — contact legal@nativekeeper.com.
3.5 We meet our obligations as a Processor
GDPR Obligation
How we meet it
Process only on documented instructions (Art. 28(3)(a))
Defined in your account settings, the DPA, and our Terms of Service
Confidentiality of personnel (Art. 28(3)(b))
Written confidentiality agreements; access on a need-to-know basis
Security of processing (Art. 32)
Encryption in transit (TLS 1.2+) and at rest (AES-256); RBAC; MFA; monitoring. See our Security page.
Engaging sub-processors (Art. 28(2) & (4))
General authorisation with 30 days' notice; binding flow-down terms
Assistance with Data Subject requests (Art. 28(3)(e))
Self-service tools + manual support
Assistance with security, breach notification, DPIAs (Art. 28(3)(f))
Documented incident response; DPIA support; security questionnaire on request
Deletion or return of data on termination (Art. 28(3)(g))
Export and delete tools in-product; 30-day free export window on termination
Demonstrate compliance (Art. 28(3)(h))
This page; our DPA; security questionnaires; certifications (in progress)
3.6 We respond to Data Subject rights requests
Whether you're a Native Keeper account holder or an individual whose records are held in the Service by an employer, we support the full range of rights:
Right of access
Right to rectification
Right to erasure ("right to be forgotten")
Right to restriction of processing
Right to data portability
Right to object
Right to withdraw consent
Rights related to automated decision-making
How to exercise these depends on whether we hold your data as Controller or Processor. Full details are in our Privacy Policy, Section 10 and Section 11.
3.7 We notify of breaches within 72 hours
If we become aware of a Personal Data Breach affecting Customer Personal Data, we notify affected customers without undue delay and in any event within 72 hours, with all the information GDPR Art. 33 requires. Details in our DPA, Section 5.4.
4. How we handle sensitive HR data
Native Keeper is designed to hold employment records. Depending on how you use the Service, that may include:
Special Category Personal Data (Art. 9 UK/EU GDPR): health data, sickness absence records, disability information, trade-union membership, ethnic origin (for equality monitoring), and — in future — biometric data.
Criminal-Offence Data (Art. 10 UK/EU GDPR): DBS certificates, other background-check results, and spent-conviction disclosures.
We take this responsibility seriously and build for it.
4.1 What we do
Same encryption, same controls, same audit as all Customer Personal Data. Sensitive documents are stored in the same encrypted environment with the same access controls as any other record.
No routine access by our team. Native Keeper personnel do not access the content of your workforce records in the ordinary course of providing the Service. Any access for troubleshooting or security purposes is logged and requires justification.
Access limited to Admin Users you designate. You control who in your organisation can see which records.
Audit logs of admin actions available on supported plans.
No use of sensitive data for AI training, profiling, or any purpose other than what you instruct.
4.2 What you are responsible for
Because you are the Controller of the data you upload, you are responsible for:
Having a lawful basis under Article 9 to Process Special Category Data (typically the "employment, social security and social protection" condition, which requires an appropriate policy document in the UK)
Having a lawful basis under Article 10 to Process Criminal-Offence Data (typically a condition under Schedule 1 DPA 2018 for UK Controllers)
Providing appropriate privacy notices to your workforce
Complying with any consultation, information, or notification obligations you owe to workers, works councils, or trade unions
Determining appropriate retention for each category of data, in line with your local statutory obligations
Our DPA Section 4 sets this out in full.
5. What we provide to help you comply
As our customer, GDPR makes you (the Controller) responsible for compliance, but we give you the tools and documentation to actually achieve it.
Tools in the product
Capability
What it lets you do
Self-service data export
Export all workforce data in CSV or JSON format, with attached files, in response to portability requests or for your own records
Self-service record deletion
Permanently delete individual records in response to erasure requests
Configurable retention
Set retention rules per record type to reflect statutory HR retention requirements
Access control per Admin User
Grant granular access rights so only authorised staff can see sensitive records
Audit logs
See who in your organisation accessed or modified records (on supported plans)
Regional data residency
Store workforce data exclusively within the EEA, the UK, or another supported region (on supported plans)
Compliance-expiry reminders
Automated notifications for upcoming document expiries so you never miss a legal deadline
Inspection-ready exports
Generate audit-friendly reports for regulator inspections or internal reviews
Documents we provide
Document
Where
Data Processing Agreement (DPA)
/legal/dpa — auto-accepted at paid signup; counter-signed version available on request
Sub-processors list
/legal/sub-processors — public, with email subscription for changes
Privacy Policy
Security overview
Standard Contractual Clauses
Incorporated into the DPA
UK IDTA
Incorporated into the DPA
Security questionnaire response
Available on request via legal@nativekeeper.com for enterprise procurement teams
Support for your compliance work
DPIA support — if you need information for a Data Protection Impact Assessment, contact legal@nativekeeper.com and we'll provide what's reasonably required.
Custom contractual terms — enterprise customers can negotiate variations to the DPA where required.
Audit access — satisfied through certifications (in progress) and on-request information.
6. What you remain responsible for
GDPR responsibility doesn't shift to us just because we provide the tools. As the Controller of the data you upload to Native Keeper, you are responsible for:
Identifying a lawful basis for each collection of Personal Data (typically contract of employment, legal obligation, or legitimate interest for employers)
Identifying additional lawful bases for Special Category and Criminal-Offence Data (Article 9 and Article 10)
Maintaining an appropriate policy document where required by DPA 2018 Schedule 1 for UK Controllers relying on conditions such as the "employment, social security and social protection" condition
Providing privacy notices to your workforce and applicants — including disclosing Native Keeper as your Processor
Not collecting more data than you need (data minimisation)
Honouring Data Subject rights requests from your workforce, using the tools we provide
Configuring appropriate retention for each record type in line with your statutory obligations
Consulting with workers, works councils, or trade unions where required in your jurisdiction
Conducting a DPIA where required (large-scale processing of Special Category or Criminal-Offence Data typically triggers this)
Reporting any breaches you become aware of to your supervisory authority within 72 hours where required
Complying with employment law in each jurisdiction where you operate — this is beyond data-protection law and we can't do it for you
If any of this is unfamiliar, the ICO's guide for organisations at ico.org.uk/for-organisations is the best free UK resource. EEA Controllers should consult their national supervisory authority.
7. Compliance Checklist
A one-page summary you can paste into your own procurement review.
Native Keeper compliance summary
Item
Status
Established in a jurisdiction with strong data-protection law
✅ United Kingdom
Registered with a supervisory authority
✅ ICO registration [PENDING]
Signs a GDPR Art. 28 Data Processing Agreement
✅ With every paying customer
DPA incorporates EU SCCs and UK IDTA
✅ Modules 2 and 3 + UK Addendum
DPA covers Special Category and Criminal-Offence Data
✅ Art. 9 and Art. 10 handling built in
Maintains a public list of Sub-processors
30 days' notice of Sub-processor changes
✅ With subscription option
Encryption in transit
✅ TLS 1.2+
Encryption at rest
✅ AES-256 including uploaded documents
Multi-factor authentication on employee access
✅
Self-service data export
✅
Self-service record deletion
✅
Configurable retention per record type
✅
Access controls per Admin User
✅
Audit logs (on supported plans)
✅
Breach notification within 72 hours
✅
Does not use workforce data to train AI
✅
Does not sell Personal Data
✅
Regional data residency available
✅ On supported plans
SOC 2 Type II report
🟡 In progress
ISO 27001 certification
🟡 Roadmap
Appointed DPO
❌ Not currently required (Art. 37)
Appointed EU Representative
🟡 Will appoint as required (Art. 27)
8. Other jurisdictions
Native Keeper serves customers globally. Depending on where you and your workforce are located, additional data-protection laws may apply. We aim to comply with each of them and provide the tools and safeguards you need to comply with your own obligations under them.
Law / regime
How we support it
UK GDPR + DPA 2018
Compliant; primary framework we build to
EU GDPR
Compliant; DPA includes EU SCCs; EU data residency available
Swiss FADP
DPA and safeguards support Swiss transfers
CCPA / CPRA (California)
Compliant for California residents (see Privacy Policy Section 13)
Canadian PIPEDA
Data-protection controls consistent with PIPEDA principles
Brazilian LGPD
Data-protection controls consistent with LGPD principles
Australian Privacy Act
Data-protection controls consistent with Australian Privacy Principles
Other national and sub-national laws
We honour any right or obligation applicable to you or your workforce under your local law
If your jurisdiction has specific requirements not addressed here, contact legal@nativekeeper.com and we'll walk through them with you.
9. Resources
Resource
Link
Data Processing Agreement
Sub-processors list
Privacy Policy
Security overview
Terms of Service
Cookie Policy
Acceptable Use Policy
Accessibility Statement
ICO (UK Supervisory Authority)
European Data Protection Board
10. Frequently Asked Questions
Are you GDPR compliant?
Native Keeper is operated in compliance with UK GDPR and EU GDPR obligations applicable to us as a Processor. We provide the contractual, technical, and operational mechanisms you need to use Native Keeper in a GDPR-compliant way. GDPR compliance is, however, a shared responsibility — see Section 6 above.
Can we hold DBS certificates and other criminal-offence data in Native Keeper?
Yes. Native Keeper is designed to hold such data, subject to your having a lawful basis under Art. 10 UK GDPR and (in the UK) a condition under Schedule 1 DPA 2018. Our DPA supports this processing. See DPA Section 4(e).
Can we hold sickness absence or health data?
Yes. Native Keeper supports Special Category Data under Art. 9 UK/EU GDPR, provided you have a lawful basis (typically the "employment, social security and social protection" condition in the UK). See DPA Section 4(d).
Will you sign our company's DPA instead of yours?
For enterprise customers, yes, we will review reasonable amendments to our standard DPA. For all other customers, our standard DPA — which is already designed to satisfy GDPR Art. 28 — is what we use. Contact legal@nativekeeper.com.
Where is data stored?
By default, in the EU (Frankfurt) for European customers and the United States for others. Regional data residency (EU-only, UK-only) is available on supported plans. See our Sub-processors page for full detail.
Can records be deleted on request?
Yes. You can permanently delete any record from your dashboard. Deleted data is removed from backups within 90 days.
Do you use our data to train AI?
No. We do not use Customer Personal Data — including workforce records or uploaded documents — to train any general-purpose AI model, either our own or any third party's. See DPA Section 9.
Do you sell personal data?
No. We never have and we never will. We do not share data for cross-context behavioural advertising.
What happens if there's a breach?
We notify affected customers within 72 hours of becoming aware of a Personal Data Breach, with full details as required by GDPR Art. 33. See DPA Section 5.4.
Can our employees exercise their GDPR rights against Native Keeper directly?
Because you are the Controller of your employees' data, your employees exercise their rights against you. We support you with self-service tools to fulfil those rights. If an individual is unable to reach you, they may contact us and we will help identify the correct Controller.
Are you certified to SOC 2 or ISO 27001?
SOC 2 Type II is in progress. ISO 27001 is on our roadmap. The current technical and organisational measures we apply are in DPA Annex 2 and on our Security page.
Are you also CCPA compliant?
Yes. See Privacy Policy, Section 13.
We're a US employer. Can we still use Native Keeper?
Yes. Native Keeper serves employers worldwide. Because we're a UK company processing data on your behalf, transfers of your workforce data to and within the UK are governed by SCCs and the safeguards described in our DPA. See Section 8.
We're a care provider / regulated employer. Does Native Keeper meet CQC / equivalent regulatory expectations for record-keeping?
Native Keeper provides encrypted storage, audit trails, access controls, retention configuration, and inspection-ready exports that many regulated employers use to meet record-keeping obligations. However, we don't hold a specific certification for any regulator. You remain responsible for confirming that Native Keeper meets your specific regulatory expectations. Contact us at legal@nativekeeper.com if you'd like documentation to support a regulator conversation.
Contact
For GDPR questions, DPAs, or anything privacy-related:
Email: legal@nativekeeper.com
Postal: NeonStack Ltd, The North Colchester Business Centre, 340 The Crescent, Colchester, England, CO4 9AD