Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

Intellectual Property and Data5 min read

GDPR and SaaS startups: the 5 essential documents from launch

SaaS startups: secure GDPR compliance from day 0 with 5 key documents (record, policy, DPA, mapping, breach procedures) and avoid fines.

From your first customer, your SaaS processes personal data. GDPR then requires transparency, security and traceability — with penalties reaching €20m or 4% of worldwide turnover (art. 83) under Regulation (EU) 2016/679. The good news: 5 foundational documents cover 80% of customer, investor and supervisory-authority expectations. The CNIL also advises startups to turn compliance into a product advantage from the design stage.

The 5 GDPR documents to implement from day 0

1) Record of processing activities (ROPA) — mandatory (art. 30)

The record is the heart of compliance. It lists every processing activity (e.g. customer onboarding, billing, analytics) and details purposes, legal bases, data categories, recipients, transfers, retention periods and security measures (art. 30 of the GDPR). Even businesses with fewer than 250 employees must keep one if processing is not “occasional” — as with a continuously operated SaaS (art. 30§5).

  • Minimum content: controller/DPO, purposes, legal basis, categories of individuals and data, recipients, transfers, retention, security measures.
  • Scope: create sheets for product (app), marketing (website, email), HR (employees), support, billing.
  • Format: versioned spreadsheet + links to evidence (security policies, contracts, logs).

To start quickly, use our guide with a ready-to-use template: GDPR processing records: template and compliance.

2) Privacy policy — user information (art. 13–14)

Accessible from the footer and at collection, it explains clearly who processes data, why, under what legal basis, for how long, with whom it is shared, any transfers outside the EU, GDPR rights and how to exercise them, and the right to complain to the CNIL (art. 13–14 of the GDPR).

  • Good practice: version, date and segment by audience (end users, prospects, applicants).
  • Alignment: your policy must accurately reflect the processing record and data map.
  • Cookies/trackers: provide a banner and purpose-based settings compliant with CNIL guidance (startup guide).

Follow our privacy policy drafting guide step by step to avoid common inconsistencies.

3) Data processing agreements (DPAs) — art. 28 and the processing chain

A SaaS is often both controller (website visitors, billing) and processor for B2B customers (hosting and processing their users' data). In both cases, GDPR requires a compliant contract (Data Processing Agreement) with each processor (e.g. cloud host, email, support), including Article 28 clauses and appropriate security measures (art. 32) of the GDPR.

  • Key clauses: documented instructions, confidentiality, security, assistance with rights, breach notification, audits, data fate (return/deletion), regulation of sub-processing.
  • Transfers outside the EU: if a tool entails a transfer, add a valid mechanism (SCCs/Standard Contractual Clauses) and supplementary measures under EDPB guidance (Recommendations 01/2020).
  • Due diligence: check certifications (e.g. ISO 27001), location, audit logs, security SLAs.

Refer to our DPA guide for SaaS startups and tutorial on transfers outside the EU and post-Schrems II SCCs to regulate providers properly (e.g. US cloud).

4) Data mapping — the plan of your flows

Data mapping makes flows visible, from collection points to storage locations, via APIs and processors. It underpins minimisation (art. 5§1c) and privacy by design (art. 25) under the GDPR and is consistently recommended by the CNIL for startups (integrating GDPR).

  • 5-step method: 1) source inventory (app, SDK, logs), 2) categories and purposes, 3) legal bases, 4) storage/retention, 5) recipients/transfers.
  • Deliverable: flow diagram + tabular inventory linked to the record; update for every new feature.
  • Product impact: remove non-essential fields, enable encryption at rest, separate roles.

Tip: build it jointly with engineering; the map becomes a living legal ops document as well as a guide for the tech team.

5) Data breach management procedures — 72 hours to respond

An incident happens sooner or later. GDPR requires notifying the supervisory authority within 72 hours of awareness where risk is established (art. 33), and informing individuals for high risk (art. 34) — see GDPR. The EDPB publishes detailed guidance on assessment and action (EDPB), and the CNIL reiterates mandatory breach records (art. 33§5).

  • Minimum playbook: detection (SIEM/alerts), triage (data type, encryption, exposure), risk assessment, remediation, CNIL/customer notification, post-mortem.
  • Include: roles (incident manager/DPO), severity criteria, email templates, incident register, evidence-retention instructions.
  • Reduced risk: strong encryption and pseudonymisation may avoid notification to individuals if harm is unlikely.

30-day action plan for pragmatic implementation

  • Week 1 — Rapid mapping: identify 10–15 main flows, legal bases and processors. Decide what to do with non-essential data.
  • Week 2 — Record (v1): create priority processing sheets (product, marketing, support, billing). Define retention periods.
  • Week 3 — Policy & cookies: publish your policy, implement a compliant banner and purpose-based preferences page.
  • Week 4 — DPAs & incidents: sign/attach DPAs with key providers (cloud, email, support) and draft a breach playbook.

If fundraising or a customer audit is approaching, plan ahead with our startup legal audit checklist.

Costly common mistakes (and how to avoid them)

  • Confusing B2B with exemption from GDPR: your users remain natural persons — information and security obligations apply.
  • Forgetting the record because “<250 employees”: SaaS processes continuously; the Article 30§5 exception does not apply.
  • Generic copied-and-pasted policy: it must reflect actual flows. Base it on your map and record.
  • Incomplete DPA: without art. 28/32 clauses and transfer safeguards, you create contractual and regulatory non-compliance.
  • No incident procedure: without a playbook, you miss the 72-hour deadline and increase exposure to risk (and penalties).

Special cases to anticipate

Transfers outside the EU and non-European hosting providers

Assess actual data and support-access locations. Use the Commission's Standard Contractual Clauses and supplementary measures under EDPB guidance (Recommendations 01/2020). Also see our practical post-Schrems II SCCs guide.

Is a DPO mandatory?

A DPO is required in certain cases (art. 37 GDPR), for example large-scale regular and systematic monitoring. Otherwise, appoint an internal GDPR lead. Refer to the CNIL for practical criteria.

Precisely document the legal basis per purpose (contract, legitimate interest with a balancing test, consent). Non-essential trackers require prior, specific consent (CNIL). Consider privacy by design (art. 25 GDPR) from the product roadmap stage.

Useful references

For local and sector guidance, consult the French Data Protection Act, Service Public Pro practical guides and, for a SaaS overview, this practical dossier on cloud providers' GDPR obligations (Aetherio).

Summary checklist

  • Processing record (art. 30) up to date and covering app, marketing, HR, support, billing.
  • Clear, accessible privacy policy aligned with flows (art. 13–14).
  • DPAs signed with all processors (art. 28/32), transfers regulated.
  • Complete, versioned data map linked to the record.
  • Breach management procedure: roles, thresholds, templates, register (art. 33–34).

Finally, remember that compliance is ongoing: governance, product updates and team training. It is also a powerful commercial argument for customers and investors (CNIL).

Further reading

Related resources

Frequently asked questions

FAQ

Must a small startup (&lt;250 employees) keep a processing record?

Yes, if processing is not occasional (SaaS processes continuously), or concerns sensitive/high-risk data. This is the exception to the exception under GDPR art. 30§5.

Is a privacy policy needed for B2B-only activity?

Yes. GDPR protects natural persons (users, customer administrators). You must inform them (art. 13–14), even if the contract is between businesses.

Must I sign a DPA with AWS, Stripe or my email tool?

Yes. They are processors under art. 28. The DPA must cover instructions, security, subprocessors, assistance, contract end, transfers outside the EU and audits.

When must I notify the CNIL of a data breach?

Within 72 hours of awareness if risk to individuals is established (art. 33). Also inform individuals for high risk (art. 34) and maintain an incident register.

Must I appoint a DPO from launch?

Only if you meet art. 37 criteria (e.g. large-scale regular and systematic monitoring). Otherwise, appoint a GDPR lead and equip your governance.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles