Glossary
GDPR
The GDPR is regulation (EU) 2016/679, the European text on personal data protection that has applied since 25 May 2018. It sets the principles for processing personal data, requires security measures appropriate to the risk, and gives you 72 hours to notify your supervisory authority after a personal data breach.
How it works
Being a regulation and not a directive, the GDPR applies directly in every member state with no national transposition. Enforcement is national: the CNIL in France, the AEPD in Spain, the federal and state authorities in Germany, coordinated through the EDPB.
Article 5 holds the six principles that frame everything: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. Article 6 sets the legal bases. Article 32 is the one IT teams live with daily: security appropriate to the risk, naming pseudonymisation and encryption, the ability to restore availability, and regular testing of the measures.
Two clocks start after an incident. Article 33 gives 72 hours to notify the supervisory authority of a personal data breach, counted from when you became aware. Article 34 adds telling the people affected when the risk to them is high, unless the data was encrypted in a way that leaves it unintelligible. Fines under article 83 reach 20 million euros or 4 % of worldwide annual turnover.
Why it matters for a fleet
A lost phone with a mail client, synced contacts and a cached CRM is a breach the moment you cannot show it was protected. The proof is a device record: storage encrypted, passcode enforced, wipe command issued and confirmed. Without it, the safe advice from your DPO is to notify, and you are doing that on a 72-hour deadline with no facts.
BYOD raises the harder question. The device belongs to the employee, so their photos and messages are their own personal data and a full wipe is out of bounds. The CNIL's BYOD guidance is blunt about it: the employer's control must stay limited to professional data. A work profile or a managed app container is what turns that limit into something technical instead of a sentence in a policy.
Then there are transfers. Since the Schrems II ruling of July 2020, sending personal data to a US-hosted service means documenting a transfer tool and a risk assessment. Data kept in the EU avoids that work entirely.
How Appaloosa handles it
Appaloosa acts as your processor under article 28 and holds no certification. It does not make you GDPR compliant: the controller duties remain yours. What it gives you is the technical half of article 32 on mobile, meaning enforced storage encryption and passcode, a compliance state per device, selective wipe that removes work data only, and logs of when each command was sent and applied.
The platform runs on infrastructure in France qualified SecNumCloud by ANSSI (version 3.2 of the framework, which covers immunity to non-European legislation), and customer data stays inside the EU, so you have no transfer mechanism to document. Minimisation is part of the design: the console collects inventory and compliance signals rather than location or browsing history, and your mobile device management record is where a DPO can read what happened to a given device.
Book a demo
See Appaloosa run on your fleet
A 20-minute call on your real setup. Enrollment, private apps, security.
Book a demo →See the full platform Explore Appaloosa