Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

Practical Legal Situations5 min read

SaaS in Europe: your practical GDPR obligations

Selling SaaS to European customers? Your practical GDPR obligations in 2026: DPAs, security, records, non-EU transfers, rights, DPO and representative.

I sell my SaaS to European customers: what are my practical GDPR obligations?

If your SaaS processes EU residents' personal data, the GDPR applies whether you are established in Europe or not (EUR‑Lex — Regulation 2016/679). Your role varies by processing activity: often processor for data customers store in your platform, but also controller for user accounts, billing and prospecting.

1) Map processing and determine your roles

  • Data controller: account creation, billing, support, anti-fraud measures, own analytics, newsletter.
  • Data processor: hosting and operations on data customers upload to the application.

Document these roles in your processing records (art. 30) and reflect them in contracts. To structure these records, follow our GDPR processing-records template.

2) Key SaaS GDPR obligations (practical and verifiable)

2.1 Lawful basis and principles (art. 5 and 6)

  • Lawful basis: contract performance (art. 6(1)(b)) to provide the service; legitimate interests (art. 6(1)(f)) for security/fraud; consent for cookies/trackers and electronic marketing where applicable (CNIL guidance). References: EUR-Lex (GDPR art. 5, 6), CNIL – GDPR, CNIL – Cookies and trackers.
  • Minimisation (art. 5(1)(c)): collect only what your purposes require.
  • Storage limitation (art. 5(1)(e)): set periods and automate deletion.

2.2 Mandatory data processing agreement (DPA) (art. 28)

For every customer for whom you act as processor, attach a DPA specifying subject matter, duration, nature, purposes, data categories and data subjects, security obligations, rights assistance, subprocessor management, audits and contract end (deletion/return). Refer to the complete SaaS DPA guide and our focus on GDPR processing in SaaS. Legislation: EUR-Lex (GDPR art. 28).

2.3 Transparency and information (art. 12–14)

Update your privacy policy: purposes, lawful bases, recipients, transfers, periods, rights, DPO/EU representative contact, supervisory-authority complaints. In 2026, the EDPB targets transparency in a coordinated enforcement action; expect increased inspections: EDPB – CEF 2026. For drafting, follow our privacy policy guide.

2.4 Privacy by design/default (art. 25)

  • Non-intrusive defaults, encryption at rest/in transit, pseudonymisation where possible.
  • Limited logs, segregated environments, least privilege.
  • Ongoing design reviews and security tests. Ref.: EUR-Lex (GDPR art. 25).

2.5 Security, incidents and logging (art. 32–34)

  • Proportionate technical/organisational measures (inspired by ISO 27001): MFA, key management, hardening, encrypted backups, role‑based access, quarterly access reviews. Ref.: EUR-Lex (GDPR art. 32).
  • Data breach: the processor notifies the customer without undue delay (art. 33(2)); the controller notifies the authority within 72h (art. 33(1)) and individuals if risk is high (art. 34). Guide: CNIL – Breach notification.

2.6 Individual rights (art. 15–22)

  • Self‑service in the product for export/rectification/deletion, request log, response SLA.
  • Objection mechanism for optional marketing/analytics. Ref.: EUR-Lex (GDPR rights).

2.7 Processing records (art. 30)

Keep updated records covering purposes, lawful bases, data/recipient categories, transfers, periods and security measures. Ref.: EUR-Lex (GDPR art. 30). Practical template: processing records — template.

2.8 Transfers outside the EU (Schrems II)

  • Map hosts and tools (logs, emails, support). For transfers to third countries, use SCCs 2021/914 and perform a TIA. Sources: EUR-Lex – SCCs 2021/914, CNIL – Transfers outside the EU.
  • Supplementary measures: client-side encryption, European key management, minimisation.
  • Provide clear information in the privacy policy (art. 13(1)(f)).

For step-by-step implementation, see our guide Standard contractual clauses after Schrems II.

2.9 DPO and EU representative

  • DPO if you perform large-scale regular and systematic monitoring or process special categories on a large scale (art. 37). Ref.: CNIL – DPO.
  • EU representative if you are outside the EU but target it (art. 27). Ref.: EUR-Lex (GDPR art. 27).

2.10 DPIA (impact assessment) for high risk

E.g. systematic surveillance, sensitive data, significant profiling. CNIL method: CNIL – PIA.

3) SaaS B2B specifics not to miss

  • Cookies/analytics SDKs: prior consent for non-strictly-necessary trackers, including some product metrics. See CNIL – Cookies.
  • Support and debugging: avoid clear-text data in tickets/logs; automatic masking.
  • Administrative access: logged and approved break‑glass procedures.
  • Subprocessing chain: maintain a public list of downstream subprocessors and an objection mechanism. Good practice recommended by SaaS practitioners: Aetherio – SaaS GDPR obligations.

4) DPA: clauses to negotiate and document

  • Security: technical schedule detailing encryption, hardening, backups, BCM/DRP, penetration testing.
  • Subprocessors: advance notice + right to object, flow‑down of obligations.
  • Audits: reasonable periodic audits, with independent certification reports (ISO/SOC) to limit intrusiveness.
  • Assistance: cooperation on rights/DPIAs, response times, contact points.
  • Contract end: exit arrangements and data deletion/return, erasure certificates.

Legal basis: EUR-Lex (GDPR art. 28(3)). For operational drafting, use our SaaS DPA guide.

5) Transfers outside the EU: quick method

  1. Identify flows (host, analytics, email, logs, support).
  2. Check adequacy/third-country status, then SCCs 2021/914 if necessary (EUR‑Lex).
  3. Perform a TIA (country law, authority access) and add technical measures (CNIL).
  4. Provide information in the privacy policy (art. 13/14).

6) 30/60/90-day compliance roadmap

Day +30

  • Map processing and roles, initial records, subprocessor inventory.
  • Updated privacy policy and cookie banner compliant with CNIL guidance.
  • GDPR clauses in terms of sale/SaaS contract and standard DPA ready.

Day +60

  • MFA everywhere, access management, incident response plan + notification procedure.
  • An individual-rights process and self-service portal.
  • Review non-EU transfers, signed SCCs + documented TIAs.

Day +90

  • Penetration tests, encrypted backups and restoration tests.
  • A privacy by design programme and product reviews.
  • DPIA if needed, DPO decision, and where applicable EU representative.

7) Risks and inspections in 2026

Breaches (transparency, transfers, security) expose you to fines of up to €20m or 4% of worldwide turnover (GDPR art. 83: EUR‑Lex). The EDPB announced coordinated transparency enforcement for 2026: take care with information provided to individuals (EDPB). In France, the CNIL centralises practical resources and incident procedures: CNIL.

8) Beyond GDPR: Data Act and interoperability

The Data Act requires interoperability and switching of cloud services, with smoother portability and exit requirements: anticipate these commitments in your SLA and exit clauses (European Commission – Data Act). For AI embedded in your SaaS, see regulatory impacts in our AI Act guide for startups.

Common mistakes to avoid

  • Confusing notification deadlines: 72h is the controller's deadline to notify the authority, not the processor's.
  • Forgetting indirect transfers (analytics, support, logs).
  • Failing to publish the downstream subprocessor list and an objection mechanism.
  • Overly generic privacy policy, misaligned with actual processing.

Short FAQ

My SaaS is B2B: does GDPR still apply?

Yes, whenever personal data is involved (e.g. users, customers' employees). B2B does not exempt you from GDPR (CNIL).

Must I always have a DPA?

Yes, whenever you act as processor (art. 28). Include a DPA in your SaaS contract (EUR‑Lex).

EU hosting: am I exempt from SCCs?

No, if external tools process data outside the EU (support, emails, analytics). Map flows and apply SCCs 2021/914 if needed (EUR‑Lex).

Is a DPO required?

Only if you meet the criteria (large-scale regular and systematic monitoring, etc.). See the CNIL DPO guide (CNIL).

For more on contracts, see our resources on essential SaaS contract clauses and transfers outside the EU after Schrems II.

Further reading

Related resources

Frequently asked questions

FAQ

I sell B2B SaaS: does the GDPR really concern me?

Yes. GDPR applies whenever personal data is involved (users, customers' employees), even in B2B and outside the EU if you target the European market.

Is a DPA mandatory with European customers?

Whenever you act as processor, GDPR requires a processing agreement (art. 28) attached to the contract, covering security, subprocessors, assistance and contract end.

Must I notify the CNIL within 72 h of a breach?

The processor notifies the customer without undue delay. The controller notifies the authority within 72 h if the breach poses a risk to individuals.

Is European hosting enough to avoid SCCs?

No. If other tools involve transfers to third countries (support, emails, analytics), you must assess and, where applicable, use SCCs and supplementary measures.

Must I appoint a DPO for my SaaS?

Only if you meet statutory criteria (large-scale regular and systematic monitoring, large-scale sensitive data, etc.). Otherwise appoint a privacy lead.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles