Signatu aims to be an all-purpose GDPR compliance tool

The General Data Protection Regulation is coming in 2018. You know it, I know it, and Torgeir Hovden and Georg Philip Krog know it, too.

Hovden and Krog are the co-founders of Signatu, a cloud service aiming to provide a range of solutions to help privacy pros, data protection officers, and lawyers ensure their organization will be in compliance with the GDPR once it comes into effect.

“We would like to provide a toolset to enable companies to basically follow all the rules without hiring a lot of people and lawyers and so forth,” said Hovden, Signatu’s CEO. 

Hovden and Krog, Signatu’s chief privacy officer and general counsel, sat down with Privacy Tech to demo the Signatu tools and the variety of ways it could help companies ensure GDPR compliance.

We first looked at the privacy policy generator tool. When using Signatu, an individual will register as a data controller and begin to create their policy. Signatu will ask the controller a number of questions to determine the company’s data processing model, while relating each question to the law requirements in the GDPR.

Organizations can choose the amount of questions they wish to answer. Signatu offers an advanced version featuring more voluntary questions, while a simpler version offers the required questions needed to form a compliant privacy policy. Krog said completing the advanced version of the questionnaire could take less than two hours, while the shorter version can be done in a single hour. Once a company has completed the questionnaire, making alterations becomes much easier.


An example of the Signatu tool in action.

“If you change parts of your data processing activity, you need to maintain and update that policy, as that is the requirement in the law,” said Krog. “You need to reflect in your policy your current state of affairs. If there is a gap, then you risk being penalized. You can very easily move to the step you need to update and then publish. It takes less than five minutes if you just want to change some small things.”

The service offers a multitude of different resources to help users comprehend details of the regulation. Each question comes with help text allowing the user to understand the context of the question in relation to the GDPR. Krog, for example, displayed the Article 29 Working Party’s guidance on data portability.

Signatu has also culled together a network of data protection law professionals from each member state of the European Union. “Once there is a legal development that affects one of the clauses, we will have an immediate report and add that information into the comments,” said Krog. "Then we know which controllers have policy clauses that are affected by the legal development, and we will send a notification to each of those controllers saying that they should update their policy.”

While currently only supporting English, Signatu plans on expanding their language capabilities to encompass all 28 EU member states.

Generating privacy policies isn’t the only way Signatu helps companies comply with the GDPR. Hovden and Krog also demonstrated a tool designed to automatically detect all the third parties running on a website.

“Today, if you are building a website, you are typically using maybe 10 to 20 to as many as 50 different third parties or ad providers on your site. There will be a requirement to inform the end user about this,” said Hovden. “Most companies will have a big pain trying to keep all that information up to date and integrated into their policies. Our idea is to provide tools to detect these third parties and automatically include that information into the policy.”

Hovden used the tool to identify the third parties on DN.no, a Norwegian news site. Within seconds, a list of dozens of third parties appeared, including Google Adwords, SpotX, Adobe, Twitter, and DoubleClick.

“If you go and ask any of these companies what third parties do you actually use on your websites, most of them will not be able to answer,” said Hovden. “Hopefully, we can help them mapping this out and as an added bonus, keep the privacy policy up to date.”

Signatu is also planning to create a tool designed for tracking consent.

“There will be a requirement in the regulation for companies to be able to prove that consent has been given,” said Hovden.  “If you are running and tracking consent on your own systems, you need audits in order to prove that nobody has tampered the consent. We believe that these companies will find it attractive that Signatu can take care of that as an independent third party.”

Outside of their goal to become the all-purpose GDPR tool, Hovden and Krog are working to present these policies using different types of content.

“We can produce a lot of very precise legal text, and we will do that as well, but the goal is to have something that can be read by normal users and understood by normal users, including kids in the longer term,” said Hovden. “We are experimenting with different media types for the different clauses. Our policy engine is very flexible in that we can provide alternative representations in videos, using icons and pictures.”

Creating content to simplify the complicated legislation fits in with Signatu's long-term goals. While the service is aimed toward privacy professionals, data protection officials and lawyers, Hovden wants Signatu to be an easy-to-use self-service for non-professionals.

Signatu is currently piloting with customers and receiving feedback on the service. Their network of data protection law professionals are working to ensure Signatu has quality reviews of the policy text and the service from all the 28 member states. The company is preparing for their second language, as demand has prompted the creation of a Norwegian version of the tool. Krog said they believe the 28 state reviews will give them the feedback needed to craft accurate policy text, and give companies the tool they need for the 2018 GDPR implementation. 

photo credit: DesignRecipe European Union Flags 2 via photopin (license)

Written By

Ryan Chiavetta


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

Latin America Dashboard Digest

A roundup of the top privacy news from Latin America

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Get more News »

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find a KnowledgeNet Chapter Near You

Talk privacy and network with local members at IAPP KnowledgeNet Chapter meetings, taking place worldwide.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

The Privacy Core™ Library Has Evolved

Privacy Core™ e-learning essentials just expanded to include seven new units for marketers. Keep your data safe and your staff in the know!

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

Upcoming Web Conferences

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Team

Get your team up to speed on privacy by bringing IAPP training to your organization.

Let’s Get You DPO Ready

There’s no better time to train than right now! We have all the resources you need to meet the challenges of the GDPR.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

FIP Designation

Recognizing the advanced knowledge and issue-spotting skills a privacy pro must attain in today’s complex world of data privacy.

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.


The IAPP’S CIPP/E and CIPM are the ANSI/ISO-accredited, industry-recognized combination for DPO readiness. Learn more today.

Learn more about IAPP certification »

IAPP-OneTrust Website Scanning & Cookie Compliance Tool

Scan your website for cookies, tags, forms and policies and create a custom, dynamically updated cookie policy based on the results of your scans.

Are You Ready for the GDPR?

Check out the IAPP's EU Data Protection Reform page for all the tools and resources you need.

Privacy Vendor List

Find a privacy vendor to meet your needs with our filterable list of global service providers.

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

More Resources »

Global Privacy Summit 2017

The world’s premier privacy conference returns with the sharpest minds and unparalleled programs—plus a whole new spin on Active Learning!

Canada Privacy Symposium 2017

The Symposium returns to Toronto! Take advantage of Early Bird rates before March 31 and join your fellow privacy pros for a stellar program.

The Privacy Bar Section Forum 2017

The Privacy Bar Section Forum is SOLD OUT and the wait list is closed. If you got on the wait list, we'll keep in touch about your status. Good luck!

Asia Privacy Forum 2017

Join us in Singapore for exclusive networking and intensive education on data protection trends and challenges in the Asia Pacific region.

Privacy. Security. Risk. 2017

We're bringing the best of the best in privacy and infosecurity to sunny San Diego. Early registration for P.S.R. opens in May.

Europe Data Protection Congress 2017

Your source for European policy debate, multi-level strategic thinking and thought-provoking discussion. Registration opens in early June.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»