Skip to content

GDPR

Current Position

Agend's products currently serve Australian associations and membership organisations, and we have no EU-resident members processed through our systems today. Our applicable privacy regime today is the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) — see our Data Hosting & Sovereignty page for how we handle personal data under that framework.

When GDPR Would Apply

The EU General Data Protection Regulation (GDPR) applies extraterritorially: the moment any Agend product processes personal data belonging to an individual located in the EU — for example, an EU-resident member of an association using Agend — GDPR obligations apply immediately, regardless of whether Agend itself has any presence in the EU. This isn't triggered by a decision to enter the EU market; it's triggered by the presence of a single EU data subject in the system.

Why We're Building Toward It Now

We're proactively working toward GDPR alignment ahead of an immediate business need, for two reasons:

  1. Potential EU market reach — if an Agend client onboards an EU-resident member, GDPR obligations apply from that point, not after.
  2. The direction of Australian privacy law — the ongoing reform of the Privacy Act 1988 increasingly mirrors GDPR concepts (broader data-subject rights, stronger consent standards, automated-decision transparency). Building GDPR-aligned foundations now reduces the work needed to meet future Australian requirements too.

Aligned with, not certified to, GDPR

GDPR has no formal certification scheme in the way ISO standards do, and Agend does not claim GDPR compliance. The information below describes a genuine, active gap-analysis-driven improvement programme — it is not a completion claim.

Where we already align well, per our internal review:

  • Tenant data isolation and access controls are private-by-default across our platform architecture
  • No cardholder data is ever stored (PCI DSS SAQ-A posture) — see PCI Compliance
  • Marketing communications are gated on an authoritative, auditable consent record
  • Australian data residency is enforced at the infrastructure level — see Data Hosting & Sovereignty

What we're actively building, in priority order:

  • Data-subject rights tooling — self-service access, export, and erasure/anonymisation requests
  • A Records of Processing Activities (RoPA) register, a data retention schedule, and a published sub-processor list with transfer safeguards for any processing outside Australia
  • A review of consent defaults and international-transfer arrangements for any third-party services used for marketing and communications
  • A Data Protection Impact Assessment (DPIA) process for new features handling sensitive categories of data

This work is tracked against a dated internal remediation plan and reviewed on an ongoing basis. It is not yet complete, and we will not claim GDPR compliance until it is — including sign-off from legal counsel and, where required, a Data Protection Officer.

Questions about our privacy posture, or GDPR requirements for your specific deployment, can be directed to security@agend.com.au.