We are a team of 7 based in Moscow licensing 3D model optimization software to industrial designers. We've mostly operated locally until now, but over the last 8 months we gained enterprise clients from Germany and France. Nearly a third of our roughly 450,000 ruble monthly license revenue now comes from these European companies.
Last week, a major Paris-based studio sent us an extensive security questionnaire prior to their annual enterprise subscription, explicitly requiring GDPR compliance and a signed Data Processing Agreement (DPA). We are a legal entity registered within the Russian Federation and store all data on local servers.
Does this regulation really apply to us directly when we have zero presence or legal entity within the European Union? How can we handle this cleanly and cost-effectively without losing the client or running afoul of Russian data localization laws?