Services Carry More Compliance Than You Think¶
Ask a small agency owner about compliance and they'll point at the privacy policy in the footer and move on. Ask their biggest client's procurement team, and the list is longer: GDPR record, data processing agreement, security questionnaire, insurance certificate, accessibility statement, maybe NIS2 alignment if they touch critical infrastructure, maybe ISO 27001 if they handle data.
Selling a service means complying as a company, not as a product. And most service businesses are missing half the list.
No product doesn't mean no obligations¶
Product companies carry product law: CE marking, substance restrictions, safety rules. Service companies skipped all that — and assumed they skipped compliance entirely. They didn't. The company itself is the product, and the obligations attach to it:
- GDPR applies to any business handling personal data of EU residents — client lists, email marketing, analytics. A record of processing activities is mandatory for most, not optional. We covered the data-side mechanics in the GDPR software guide.
- A Data Processing Agreement is required by Article 28 whenever you process personal data on behalf of a client. No DPA, no compliant contract — and B2B buyers increasingly refuse to sign without one.
- Security questionnaires arrive with every serious engagement. If you store client data, expect questions about access controls, backups, encryption and incident response — the territory the NIS2 guide and the ISO 27001 guide map out.
- Accessibility obligations under the European Accessibility Act apply to services offered to EU consumers, and the statement that documents them is expected by buyers, not just regulators.
- Insurance, terms, tax and banking — the boring stack a lender asks for before anything else.
None of these are a one-time project. Certificates expire, policies change, questionnaires come quarterly, and the answer to each is a document someone wants now.
The company-level fix¶
The SaaS world solved this exact problem with the trust center: publish the security reports once, let buyers self-serve. The same structure works for any service business. Company-level pages — GDPR record, DPA, insurance summary, security posture, accessibility statement — assembled under one verifiable address, each one living and dated.
When the bank asks, the answer is a link. When the procurement questionnaire arrives, you paste the same link and attach the two PDFs that need signing. The recurring emails stop, and the documents stop going stale, because they're updated in place rather than re-attached in every thread. We wrote the two-audience argument for exactly this setup.
How Sustalium Helps Service Businesses¶
- Company-level pages — GDPR records, DPAs, security documentation and accessibility statements as living, dated documents.
- One Trust Hex — the verifiable address buyers, banks and insurers check instead of emailing you.
- Updates in place — certificates and policies change behind the same URLs, so nothing goes stale quietly.
Your Company Is the Product. Publish Its Papers.
Put the service stack on living pages under one Trust Hex, and answer every questionnaire with a link. Start with a free draft: no card needed, publish the verifiable version when you are ready.
[See the Trust Hex →](/trust-hex/){ .md-button .md-button--primary }
Frequently Asked Questions¶
Do small agencies really need all this?
The obligations apply by activity, not size: GDPR applies to a two-person agency handling client data, and buyer questionnaires don't shrink with your headcount. What changes with size is how much of it you can publish instead of managing in email.
What's the minimum starting set?
A GDPR record, a DPA template, a security posture page and your insurance summary. That covers most first conversations with buyers and lenders.
How do I keep it current?
Company-level living pages: update in place, keep expiry dates visible, and point every questionnaire at the same address.
Related Articles¶
- GDPR Compliance Software: Tools for Data Privacy — the data protection foundation
- NIS2 Compliance Software: Automate Cybersecurity — when security questionnaires get serious
- ISO 27001 Certification: ISMS & Buyer Sharing — the certificate buyers recognise
Last updated: September 2, 2026
Global Digital Trust & Compliance
Sustalium is the digital-first platform for managing complex business certificates and sustainability declarations across global supply chains.
- Digital Product Passport (DPP)
- Carbon & Water Footprint
- Circularity & Reuse (ISO 14021)
- De-Forestation Free
- FSMA 204 (FDA Traceability)
- REACH & RoHS Compliance
- PFAS-Free & VOC Declarations
- Prop 65 & TSCA Title VI
- ISO 26000 Responsibility
- Modern Slavery Statements
- UFLPA Forced Labor Traceability
- Ethical Labor Declarations
- Swiss Made & Origin Claims
- GDPR & AI Ethics (EU AI Act)
- CE Marking & UKCA Conformity
- Bill S-211 (Canada) Reporting
Have questions about a specific standard?
Contact our compliance team at compliance@sustalium.com