GDPR Compliance Statements & Reports

Compliance

Generate compliance statements and activity reports for your GDPR records

6 min read
Intermediate
Updated 29 August 2026
Back to Guides
GDPR Compliance Statements & Reports

GDPR Compliance Statements & Reports

Generate a downloadable statement of the technical and organisational measures FileSeal applies to your documents, plus activity reports, for your own compliance records.

What this is, and is not. The statement describes FileSeal's measures as your data processor, under UK GDPR Articles 28 and 32. It is the kind of document a client's compliance officer, an insurer or a due-diligence questionnaire is usually asking for. It is not a certification under Article 42 UK GDPR, it confers no certification mark, and it does not certify that your own organisation is GDPR compliant. Responsibility for that remains with you as data controller.

Before You Begin

Ensure you have:

  • ✅ Active FileSeal professional account
  • ✅ Access to Settings > Compliance section
  • ✅ Understanding of your compliance obligations

GDPR Compliance Features

Built-in Data Protection

  • Data Protection by Design: Client-side encryption applied before transmission
  • Data Protection by Default: All documents automatically deleted after download
  • Data Minimisation: Only essential metadata retained for audit trails
  • Purpose Limitation: Data processing limited to secure document sharing
  • Storage Limitation: Automatic deletion prevents unnecessary data retention

UK-Based Processing

  • All data processed within UK borders
  • EU GDPR and UK GDPR compliant infrastructure
  • Neon PostgreSQL AWS eu-west-2 (London) hosting
  • Vercel UK (London) deployment region

Downloading Your GDPR Compliance Statement

Step 1: Access Compliance Section

  1. Navigate to your Settings page from the dashboard
  2. Scroll down to Compliance & Reports section
  3. Locate the GDPR Compliance Statement option

Step 2: Generate the Statement

  1. Click "Download Statement"
  2. System validates your account compliance status
  3. PDF statement automatically generated
  4. Download begins automatically

Statement Contents

Your GDPR compliance statement includes:

  • Account Details: Your professional information
  • Technical and Organisational Measures: The controls FileSeal applies to your documents
  • Technical Measures: Security and encryption details
  • Data Processing: UK-based processing confirmation
  • Issue Date: When the statement was generated
  • Reference: A reference a third party can check; the full verification link is printed in the statement's footer

Generating Activity Reports

Step 1: Configure Report Parameters

  1. In Settings > Compliance section
  2. Select Activity Report option
  3. Choose date range (7, 30, 90 days, or custom)
  4. Select format (PDF recommended for audits)

Step 2: Generate Report

  1. Click "Generate Activity Report"
  2. System compiles your request and send activity
  3. Report generated with compliance metadata
  4. Download automatically starts

Report Contents

The activity report is built from your requests and sends, one row each, plus summary totals. It includes:

  • History: Every request and send in the selected period
  • Status for each: Where it got to, its expiry, and its download count

It is NOT an export of the audit log. The underlying upload, download and collection rows exist and we can produce them if a regulator asks, but they are not what this report contains.

Using Your Statement

For Client Records

  • Provide the statement to clients asking how their documents are handled
  • Include in your data protection policy documentation
  • Attach to compliance questionnaires and RFPs
  • Share with compliance officers and legal teams

For Regulatory Audits

  • Include the statement in your processor due-diligence records
  • Include in annual compliance reporting
  • Use activity reports as a record of the requests and sends you created
  • Demonstrate ongoing compliance monitoring

For Professional Standards

Your regulator sets requirements for your practice, and no document from a supplier satisfies them on your behalf. What this statement does is evidence one part of the picture: how a supplier you rely on handles client documents. Bodies including the SRA and Law Society, ICAEW, the FCA and RICS all expect firms to carry out due diligence on suppliers who process client data, and this statement is the artefact to file against that.

  • Use it as your supplier due-diligence record for FileSeal
  • Check what your own regulator expects of your practice; this statement covers FileSeal's measures, not your compliance

Best Practices

Keeping It Current

  • Download a fresh statement if your details or our measures change
  • Keep previous statements for your compliance history
  • Share the current statement with key stakeholders

Activity Report Management

  • Generate reports before client meetings
  • Create monthly reports for internal compliance reviews
  • Use reports for incident investigation if required
  • Archive reports according to your retention policy

Documentation Storage

  • Store statements in your compliance documentation system
  • Maintain both digital and physical copies if required
  • Keep statements accessible for audits
  • Consider integration with practice management software

Compliance Support

Technical Questions

  • Review our Security Documentation
  • Contact support for technical compliance queries
  • Request additional compliance documentation if needed

Legal Guidance

  • Consult with your legal advisors on GDPR obligations
  • Consider professional data protection training
  • Stay updated on regulatory changes and requirements

Professional Standards

  • Check specific requirements for your profession
  • Check what your regulatory body expects from a processor; this statement covers FileSeal's measures, not your own compliance
  • Consider additional compliance measures if required

Troubleshooting

Statement Generation Issues

  • Ensure your account is in good standing
  • Check browser allows PDF downloads
  • Try generating the statement from a different browser
  • Contact support if persistent issues occur

Report Generation Problems

  • Verify date range selection is valid
  • Check you have activity in selected period
  • Ensure sufficient browser memory for large reports
  • Try smaller date ranges if reports are too large

Next Steps

After setting up GDPR compliance documentation:

  1. Review Security Features - Understand technical protections
  2. Professional Customization - Brand your compliance
  3. Contact Support - Get compliance assistance

Keep your records current: Download a fresh statement when your details change, and keep activity reports with your own records. Your compliance remains your responsibility as data controller; these documents evidence how FileSeal handles the documents you process through it.

Guide Stats

6 min read
Intermediate Level
Visual Guide
Need More Help?

Can't find what you're looking for in this guide?

Contact Support →