Does your SaaS comply with the GDPR?
The GDPR (Regulation (EU) 2016/679) regulates the processing of personal data in the SaaS model. The most critical aspects are:
Controller and processor (Art. 28): The relationship between the customer (controller) and the SaaS (processor) is governed by a data processing agreement. The contract must establish: subject matter, duration, nature and purpose of processing, type of data, categories of data subjects, processor obligations (documentation, security, sub-processors, return/deletion).
Sub-processors (Art. 28(2)-(4)): The processor may only engage a sub-processor with the controller's prior specific or general authorisation. In case of general authorisation, it must inform of any changes. The sub-processor is subject to the same obligations as the processor through a contract or other binding legal act.
International transfers (Arts. 44-49): If the SaaS uses cloud providers outside the EEA (AWS US, GCP US, Azure US), it must comply with transfer rules: adequacy decision (EU-US Framework 2023), SCCs 2021, BCRs, or codes of conduct/certifications. In addition, a TIA (Transfer Impact Assessment) must be carried out.
Security (Art. 32): Technical and organisational measures appropriate to the risk: encryption, pseudonymisation, access control, resilience, restoration, security testing.
DPIA (Art. 35): Mandatory for high-risk processing, such as large-scale processing of special categories of data or systematic large-scale monitoring.
DPO (Art. 37): Mandatory if core activities consist of processing operations requiring systematic and large-scale monitoring.
- Processor contract (Art. 28) — We draft GDPR-compliant DPAs that protect the SaaS
- Sub-processor management — We implement the authorisation and change notification flow
- International transfers — SCCs, BCRs, adequacy decision and TIA for cloud providers
- Cloud security — We assess and improve Art. 32 measures
- SaaS DPIA — We carry out the Art. 35 Impact Assessment for high-risk processing
GDPR obligations for SaaS
GDPR obligations for a SaaS depend on its role (controller or processor) and the type of data processed:
As a processor:
- Process data only according to the controller's documented instructions (Art. 29)
- Not use the data for own purposes without authorisation
- Ensure staff confidentiality (Art. 28(3)(b))
- Implement security measures (Art. 32)
- Respect sub-processor conditions (Art. 28(2)-(4))
- Assist the controller in complying with its obligations (DPIA, breach notification, rights)
- Return or delete data at the end of the service (Art. 28(3)(g))
- Allow audits and inspections by the controller (Art. 28(3)(h))
As a controller (if the SaaS processes data on its own account):
- Identify the Art. 6 legal basis
- Inform data subjects (Arts. 13-14)
- Guarantee data subject rights (Arts. 15-21)
- Carry out DPIA where appropriate (Art. 35)
- Designate DPO where appropriate (Art. 37)
- Notify breaches within 72 hours (Art. 33)
International transfers:
- Identify all cloud providers and sub-processors outside the EEA
- Implement the appropriate mechanism (SCCs, BCRs, adequacy, certification)
- Carry out TIA to verify the destination country's level of protection
- Monitor changes in adequacy decisions (e.g. EU-US Framework)
Fines: Up to €20 million or 4% of global turnover (upper level). Up to €10 million or 2% (lower level).
Most relevant GDPR articles for SaaS
| Article | Topic | Application in SaaS |
|---|---|---|
| Art. 28 | Processor | DPA between customer and SaaS |
| Art. 28(2)-(4) | Sub-processors | Prior or general authorisation, change notification |
| Art. 29 | Controller instructions | Process data only according to documented instructions |
| Art. 32 | Security | Encryption, access control, resilience |
| Art. 35 | DPIA | High-risk processing |
| Art. 37 | DPO | Systematic and large-scale monitoring |
| Arts. 44-49 | Transfers | Cloud providers outside the EEA |
| Arts. 13-14 | Information | SaaS privacy policy |
Official guidance for SaaS
- AEPD — Guide for clients contracting cloud computing: AEPD
- AEPD — Guidance for cloud computing providers: AEPD
- EDPB — Guidelines 07/2020 on controller and processor concepts: EDPB
- AEPD — GDPR compliance for AI processing (2020): AEPD
- EDPB — Recommendations 01/2020 on supplementary measures (TIA): EDPB
GDPR compliance checklist for SaaS
- Identify the SaaS role (controller, processor, both)
- Draft Art. 28(3)-compliant DPA for all customers
- Implement sub-processor authorisation flow (Art. 28(2)-(4))
- Document controller instructions (Art. 29)
- Implement Art. 32 security measures (encryption, access, resilience)
- Identify all cloud providers and sub-processors outside the EEA
- Implement transfer mechanisms (SCCs, BCRs, adequacy, certification)
- Carry out TIA for transfers to countries without adequacy
- Carry out DPIA if processing is high-risk (Art. 35)
- Designate DPO where appropriate (Art. 37)
- Establish 72-hour breach notification procedure (Art. 33)
- Implement data subject rights mechanisms (Arts. 15-21)
- Draft clear privacy policy (Arts. 13-14)
- Allow controller audits (Art. 28(3)(h))
Related resources
- GDPR Hub — Resource centre on the GDPR
- GDPR Glossary — 45+ key terms with article references
- AI Act vs GDPR — Comparative table of both regulations
- GDPR Compliance Checker — Self-assess your compliance
- AI & Data Regulation Service — Integrated advisory
- AI Act for SaaS — Sectoral AI Act guide for SaaS
- DPO as a Service — External Data Protection Officer
- GDPR Training for Product Managers — Practical workshop
This page is general information, not legal advice. Each data processing operation must be analysed individually. Fines cited are based on public AEPD decisions.