Go back

Video data that cannot say where it lives or who can access it: what GDPR requires

A team evaluating a video platform for use across a European workforce or customer base eventually runs into a question that a product demo doesn’t answer: where does this data actually go, who processes it, and what happens if something goes wrong. GDPR isn’t a single checkbox, it’s a specific set of obligations around exactly these questions, and a vendor’s answers need to be documented, not just assured verbally.

What GDPR actually requires

The General Data Protection Regulation governs how personal data belonging to people in the EU is collected, processed, and stored. For a B2B vendor like a video platform, this typically means acting as a data processor on behalf of the customer, who remains the data controller. As a processor, the vendor is required to process personal data only on the customer’s documented instructions, implement appropriate technical and organizational safeguards, disclose which sub-processors it relies on, and support the customer in meeting its own obligations to the people whose data is involved, including responding to data subject requests and notifying the customer of any data breach without undue delay.

Why “GDPR compliant” isn’t a single, simple claim

Unlike a certification such as SOC 2 or ISO 27001, GDPR compliance isn’t something a vendor gets audited and certified against by a third party in the same way. It’s a legal framework a vendor demonstrates alignment with through specific contractual and operational commitments, most concretely, a Data Protection Addendum that spells out exactly how the vendor handles personal data on the customer’s behalf. When a vendor says they’re “GDPR compliant,” the meaningful next question is what specific documentation backs that claim, not whether the general statement is technically true.

The specific documentation to request

A Data Protection Addendum, or DPA. This is the legal document that defines the vendor’s obligations as a data processor, including what data it processes, for what purpose, and under what restrictions.

Standard Contractual Clauses, or an equivalent transfer mechanism. If the vendor processes data outside the EU, GDPR requires an approved legal mechanism for that transfer, most commonly SCCs, sometimes supplemented by a UK-specific addendum for UK data.

A current sub-processor list. GDPR requires transparency about which additional vendors, cloud infrastructure providers, AI model providers, specialized service vendors, have access to the data, along with reasonable advance notice before new sub-processors are added.

A breach notification commitment with a specific timeframe. Confirm the vendor commits to notifying you within a defined window, commonly within 72 hours of becoming aware of an incident, which aligns with GDPR’s own notification requirements to regulators.

Where the data actually lives, and why that’s a separate question from compliance

Data residency, the physical location where data is processed and stored, is related to GDPR compliance but isn’t the same question. GDPR permits data to be processed outside the EU when appropriate legal safeguards, like SCCs, are in place, so a vendor processing data in the United States isn’t automatically non-compliant. That said, some organizations have their own internal policies or specific regulatory obligations requiring EU-only data residency regardless of what GDPR itself technically permits, which makes this worth verifying directly and separately from the general compliance question, rather than assuming compliance implies a specific storage location.

Why data subject rights matter beyond the initial compliance check

GDPR gives individuals specific rights over their own data, including the right to access what’s held about them, request corrections, and in many cases request deletion. As a data processor, a vendor needs to be able to support the customer, who remains the data controller responsible for fulfilling these requests, in locating and acting on personal data within its systems when such a request comes in. For a video platform, this means confirming the vendor has a real, workable process for identifying and removing personal data tied to a specific individual from generated content, source material, and any derived assets, rather than only being able to address data held in a single, obvious location.

Why this differs from SOC 2 in what it actually verifies

It’s worth distinguishing GDPR compliance from a certification like SOC 2, since the two are sometimes conflated. SOC 2 is verified through an independent audit against a defined set of trust service criteria. GDPR compliance is a legal and contractual posture, demonstrated through documentation like a DPA and transfer mechanisms, rather than a single audited certificate a vendor can produce on request. A vendor can reasonably hold one without the other, and a security or legal review focused on European data protection will generally want the GDPR-specific documentation directly, rather than accepting a SOC 2 report as a substitute for it.

What this looks like for a video platform specifically

Video content frequently includes personal data without it being immediately obvious, a screen recording that captures someone’s name in an email client, a document used as source material that includes employee details, a customer’s name and situation referenced in support content. This means a video platform’s GDPR posture matters even for teams that don’t think of their content as touching personal data directly, since source material commonly does.

Velo’s approach

Velo operates as a data processor under a Data Protection Addendum incorporating Standard Contractual Clauses and a UK Addendum for lawful international data transfers, commits to notifying customers of a data breach within 72 hours, maintains a documented sub-processor list with advance notice before changes, and does not use customer personal data to train or fine-tune AI models without explicit written authorization. Review the current Data Protection Addendum directly to confirm these terms meet your organization’s specific requirements.

Why this deserves attention even outside Europe

Teams sometimes assume GDPR only matters if the organization is based in the EU or has EU customers, but the regulation applies more broadly, covering any processing of personal data belonging to people located in the EU, regardless of where the company itself is headquartered. A US-based company with even a handful of European employees or customers is within scope, which means GDPR-related documentation is worth having in place well before a specific deal or audit makes it urgent, rather than treating it as a concern exclusive to explicitly EU-headquartered organizations.

Ask for the documentation, not the assurance

A vendor telling you they take data privacy seriously isn’t a substitute for the specific documents, a DPA, a transfer mechanism, a sub-processor list, that GDPR compliance actually rests on. Request these directly, read them rather than skimming for a single reassuring sentence, and confirm they cover your specific use case before a rollout depends on a vendor’s data handling meeting requirements nobody has actually verified.

Try Velo for free · See how it works


About the author

Ritu Parakh is Growth Lead at Velo, the AI video messaging platform that turns a screen recording, a deck, or a URL into a polished, narrated video - and an editable written doc. She writes about video for demos, onboarding, training, and enablement. Connect on LinkedIn

Velo operates as a data processor under a Data Protection Addendum that incorporates Standard Contractual Clauses and the UK Addendum, with documented sub-processors and a 72-hour breach notification commitment. Review the current DPA directly for your specific requirements.

GDPR requires a vendor acting as a data processor to process personal data only on the customer's documented instructions, maintain appropriate safeguards, disclose sub-processors, and support the customer's own obligations to data subjects.

Not automatically. GDPR allows data transfers outside the EU when appropriate safeguards, like Standard Contractual Clauses, are in place, but this needs to be verified directly against a specific vendor's actual infrastructure and legal documentation.

Video platforms often process source material, screen recordings, documents, sometimes customer or employee information, that constitutes personal data under GDPR, making the platform's role as a data processor directly relevant to compliance.

Bring the video layer to your product team