GDPR and CCPA require lawful basis for processing, transparency about what you collect, support for data-subject requests, and breach notification. turgo provides the infrastructure; you're responsible for the lawful basis and the privacy notice.
What turgo provides
Data residency in the EU when needed, encryption at rest and in transit, comprehensive audit logs, support for access and deletion requests, a data-subject-request workflow, a sub-processor list, and a signed DPA available on Growth+ plans. These satisfy the technical requirements.
What you're responsible for
- Documenting lawful basis for processing each data class (legitimate interest is most common for B2B).
- Maintaining a privacy notice that's accurate.
- Providing opt-out mechanisms (turgo enforces these).
- Responding to data-subject requests within statutory timeframes.
- Breach notification — turgo notifies you if turgo has a breach; you notify regulators.
Lawful basis for B2B outreach
Most B2B outbound is legitimate interest, which requires balancing your interest in marketing against the recipient's reasonable expectations. The discipline: keep targeting tight (ICP-relevant), make opt-out easy, and don't outreach in regions where consent-required rules apply (Germany, France in some cases) without explicit opt-in.
Handling subject access requests
When someone asks what data you hold on them: Data → Subject Requests → New → enter email → Generate Report. Produces a complete record export covering all of turgo's data on that person. Delivery to the subject is your responsibility.
Geography-aware behavior
turgo applies stricter defaults per region — EU prospects get GDPR-compliant treatment automatically, California residents get CCPA defaults, Canadian prospects get CASL defaults. Settings → Compliance → Geography lets you tune per region.