GDPR · SaaS

GDPR for SaaS: Processor, Sub-processor and Transfers

The GDPR regulates the controller-processor relationship (Art. 28), sub-processors, international transfers and cloud security. Learn the specific obligations for SaaS companies with AEPD and EDPB sources.

Does your SaaS comply with the GDPR?

The GDPR (Regulation (EU) 2016/679) regulates the processing of personal data in the SaaS model. The most critical aspects are:

Controller and processor (Art. 28): The relationship between the customer (controller) and the SaaS (processor) is governed by a data processing agreement. The contract must establish: subject matter, duration, nature and purpose of processing, type of data, categories of data subjects, processor obligations (documentation, security, sub-processors, return/deletion).

Sub-processors (Art. 28(2)-(4)): The processor may only engage a sub-processor with the controller's prior specific or general authorisation. In case of general authorisation, it must inform of any changes. The sub-processor is subject to the same obligations as the processor through a contract or other binding legal act.

International transfers (Arts. 44-49): If the SaaS uses cloud providers outside the EEA (AWS US, GCP US, Azure US), it must comply with transfer rules: adequacy decision (EU-US Framework 2023), SCCs 2021, BCRs, or codes of conduct/certifications. In addition, a TIA (Transfer Impact Assessment) must be carried out.

Security (Art. 32): Technical and organisational measures appropriate to the risk: encryption, pseudonymisation, access control, resilience, restoration, security testing.

DPIA (Art. 35): Mandatory for high-risk processing, such as large-scale processing of special categories of data or systematic large-scale monitoring.

DPO (Art. 37): Mandatory if core activities consist of processing operations requiring systematic and large-scale monitoring.

  • Processor contract (Art. 28) — We draft GDPR-compliant DPAs that protect the SaaS
  • Sub-processor management — We implement the authorisation and change notification flow
  • International transfers — SCCs, BCRs, adequacy decision and TIA for cloud providers
  • Cloud security — We assess and improve Art. 32 measures
  • SaaS DPIA — We carry out the Art. 35 Impact Assessment for high-risk processing

GDPR obligations for SaaS

GDPR obligations for a SaaS depend on its role (controller or processor) and the type of data processed:

As a processor:

  • Process data only according to the controller's documented instructions (Art. 29)
  • Not use the data for own purposes without authorisation
  • Ensure staff confidentiality (Art. 28(3)(b))
  • Implement security measures (Art. 32)
  • Respect sub-processor conditions (Art. 28(2)-(4))
  • Assist the controller in complying with its obligations (DPIA, breach notification, rights)
  • Return or delete data at the end of the service (Art. 28(3)(g))
  • Allow audits and inspections by the controller (Art. 28(3)(h))

As a controller (if the SaaS processes data on its own account):

  • Identify the Art. 6 legal basis
  • Inform data subjects (Arts. 13-14)
  • Guarantee data subject rights (Arts. 15-21)
  • Carry out DPIA where appropriate (Art. 35)
  • Designate DPO where appropriate (Art. 37)
  • Notify breaches within 72 hours (Art. 33)

International transfers:

  • Identify all cloud providers and sub-processors outside the EEA
  • Implement the appropriate mechanism (SCCs, BCRs, adequacy, certification)
  • Carry out TIA to verify the destination country's level of protection
  • Monitor changes in adequacy decisions (e.g. EU-US Framework)

Fines: Up to €20 million or 4% of global turnover (upper level). Up to €10 million or 2% (lower level).

Most relevant GDPR articles for SaaS

ArticleTopicApplication in SaaS
Art. 28ProcessorDPA between customer and SaaS
Art. 28(2)-(4)Sub-processorsPrior or general authorisation, change notification
Art. 29Controller instructionsProcess data only according to documented instructions
Art. 32SecurityEncryption, access control, resilience
Art. 35DPIAHigh-risk processing
Art. 37DPOSystematic and large-scale monitoring
Arts. 44-49TransfersCloud providers outside the EEA
Arts. 13-14InformationSaaS privacy policy

Official guidance for SaaS

  • AEPD — Guide for clients contracting cloud computing: AEPD
  • AEPD — Guidance for cloud computing providers: AEPD
  • EDPB — Guidelines 07/2020 on controller and processor concepts: EDPB
  • AEPD — GDPR compliance for AI processing (2020): AEPD
  • EDPB — Recommendations 01/2020 on supplementary measures (TIA): EDPB

GDPR compliance checklist for SaaS

  • Identify the SaaS role (controller, processor, both)
  • Draft Art. 28(3)-compliant DPA for all customers
  • Implement sub-processor authorisation flow (Art. 28(2)-(4))
  • Document controller instructions (Art. 29)
  • Implement Art. 32 security measures (encryption, access, resilience)
  • Identify all cloud providers and sub-processors outside the EEA
  • Implement transfer mechanisms (SCCs, BCRs, adequacy, certification)
  • Carry out TIA for transfers to countries without adequacy
  • Carry out DPIA if processing is high-risk (Art. 35)
  • Designate DPO where appropriate (Art. 37)
  • Establish 72-hour breach notification procedure (Art. 33)
  • Implement data subject rights mechanisms (Arts. 15-21)
  • Draft clear privacy policy (Arts. 13-14)
  • Allow controller audits (Art. 28(3)(h))

This page is general information, not legal advice. Each data processing operation must be analysed individually. Fines cited are based on public AEPD decisions.

Featured Services

Frequently Asked Questions

What should a processor contract (DPA) contain?

Art. 28(3) GDPR establishes that the contract must contain: the subject matter, duration, nature and purpose of processing, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. In addition, the processor must: ensure staff confidentiality, implement security measures (Art. 32), respect sub-processor conditions, assist the controller with DPIAs and rights, return or delete data at the end, and allow audits.

How is a sub-processor authorised?

Art. 28(2) GDPR establishes two modalities: prior specific authorisation for each sub-processor, or general authorisation allowing the processor to engage sub-processors provided it informs the controller of any changes (the controller may object). The sub-processor is subject to the same obligations as the processor through a contract or other binding legal act (Art. 28(4)). The sub-processor chain is critical in cloud and SaaS environments.

What is a TIA and when is it mandatory?

The TIA (Transfer Impact Assessment) is an analysis that the controller or processor must carry out before making an international transfer based on SCCs or BCRs, to assess whether the destination country offers an essentially equivalent level of protection to the EU. It must consider the third country's legislation (especially surveillance laws), the practices of its authorities, and supplementary measures (encryption, pseudonymisation). The EDPB issued specific recommendations in 2020.

What security measures does Art. 32 require for a SaaS?

Art. 32 GDPR requires technical and organisational measures appropriate to the risk, including: pseudonymisation and encryption of personal data, confidentiality, integrity, availability and resilience, ability to restore after an incident, procedures for testing and evaluating effectiveness. Measures must be adapted to the risk: a SaaS processing health data requires stricter measures than one processing contact data.

When is the DPIA mandatory in a SaaS?

The DPIA (Art. 35 GDPR) is mandatory for high-risk processing, including: systematic and extensive evaluation of personal aspects, large-scale processing of special categories of data (health, biometrics), and systematic large-scale monitoring. In SaaS, the DPIA is common if the product processes health data, performs systematic profiling, or monitors user behaviour at large scale.

What fines does the GDPR provide for SaaS?

The GDPR sets two levels: upper level (up to €20 million or 4% of global turnover) for breaches of basic principles, data subject rights and transfers; lower level (up to €10 million or 2%) for breaches of technical obligations, DPO, breach notification and cooperation with the authority. The AEPD fined Marina Salud €500,000 (2025) for unlawful sub-processor engagement under Art. 28.

How are international transfers made in SaaS?

If the SaaS uses cloud providers outside the EEA (AWS US, GCP US, Azure US), it must comply with transfer rules (Arts. 44-49): adequacy decision (EU-US Framework 2023), Standard Contractual Clauses (SCCs 2021), Binding Corporate Rules (BCRs), or codes of conduct/certifications. In addition, a TIA must be carried out to verify that the country offers an essentially equivalent level of protection (EDPB Recommendations 01/2020).

Which authorities supervise the GDPR in SaaS in Spain?

The AEPD (Spanish Data Protection Agency) is the competent supervisory authority in Spain. At European level, the EDPB (European Data Protection Board) coordinates enforcement between Member States. The AEPD has published specific guides for cloud computing clients and providers, and guidance on GDPR compliance for AI processing.

Contact

If you want to talk about intellectual property protection, AI and data regulation, startup formation or international expansion, write us a few lines and schedule a conversation with the team.

A2 Estudio Legal
María de Molina, 41
28006 Madrid · Spain

Tel: +34 913 451 406
Email: info@a2estudiolegal.com

Tell us briefly about your project, development stage and target countries. We will respond with the next steps to start working together.

Let's talk
Contact us