Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

Intellectual Property and Data7 min read

GDPR processing in SaaS: how to draft a compliant DPA

GDPR DPA for SaaS: Article 28 obligations, essential clauses, transfers outside the EU, audits, security and subprocessors. A practical, compliant guide.

In every B2B SaaS model, you process personal data on behalf of your clients. The GDPR therefore requires a Data Processing Agreement (DPA) to be signed between the controller (your client) and you, the processor. This is a legal obligation under GDPR Article 28, with mandatory minimum clauses and high risks if omitted or non-compliant (fines of up to €20 million or 4% of worldwide turnover, art. 83) (EUR‑Lex, GDPR).

1) Before drafting: correctly identify roles and scope

Everything starts with correctly identifying roles. The client determines the purposes and essential means: it is the controller. The SaaS provider performs operations on its behalf: it is the processor. Avoid treating genuine product co-development as processing on behalf of a controller: you could become a joint controller. Refer to the EDPB guidelines on the concepts of “controller” and “processor” to resolve borderline cases (integrations, advanced analytics, AI, etc.) (EDPB, Guidelines 07/2020).

Also check whether national rules apply in addition (e.g. health, education, public sector). The French Data Protection Act (Loi Informatique et Libertés) continues to govern certain processing in France (Legifrance, Law no. 78‑17).

2) Mandatory DPA clauses (GDPR Article 28)

Article 28(3) requires a series of minimum provisions that your DPA must include (EUR‑Lex, GDPR art. 28) and (CNIL, Processor guide):

  • Subject matter and duration of processing, nature and purposes, type of data, categories of data subjects.
  • Obligation to process only on the controller's documented instructions.
  • Confidentiality: commitments from your staff and anyone authorised to process data.
  • Processing security: technical and organisational measures compliant with Article 32.
  • Assistance to the controller in responding to rights requests and with DPIAs (impact assessments).
  • Data breach notification: the processor informs the controller “without undue delay” after becoming aware of a breach (the 72-hour deadline concerns notification by the controller to the authority, GDPR art. 33).
  • Data handling at the end of the contract: deletion or return at the controller's choice, and deletion of copies unless otherwise required by law.
  • Making all necessary information available and allowing audits.
  • Governance of subprocessors (prior authorisation, identical “flow-down” obligations; initial processor's liability, art. 28(4)).

The CNIL details these requirements and provides operational examples for processors (CNIL, Processor guide), and its website summarises the key obligations (CNIL).

3) DPA requirements specific to multi-tenant SaaS

Expected security measures (TOMs annex, art. 32)

  • Encryption at rest and in transit, key management/rotation (BYOK/HYOK where relevant), logical tenant isolation.
  • Strong access controls (MFA, RBAC), logging and traceability, regular review of permissions.
  • Vulnerability management, regular penetration testing, patch policy, CI/CD pipeline security.
  • Business continuity: encrypted backups, tested disaster recovery/business continuity plans, documented RPO/RTO.
  • Support confidentiality: temporary access, access records, environment segregation.

Describe these measures in a versioned technical annex. Provide a mechanism for updating TOMs, with notification and a reasonable right to object.

Subprocessors (cloud, email, monitoring…)

  • General authorisation with a right to object, or specific authorisation for each subprocessor.
  • Up-to-date online list and advance notification of changes (e.g. 15–30 days).
  • “Flow-down” contract imposing the same obligations as the main DPA; security & confidentiality due diligence.
  • Liability: you remain fully liable to the client for performance by your subprocessors (GDPR art. 28(4)).

The CNIL and EDPB reiterate these requirements for governance of the processing chain (EDPB) (CNIL).

Transfers outside the EU/EEA and remote access

Hosting, backups, support or telemetry may involve a data transfer or access from a third country. The DPA must:

  • Identify destinations, transfer grounds (particularly Standard Contractual Clauses, Decision 2021/914) and the minimisation approach.
  • Specify the post-Schrems II supplementary measures (robust encryption, separation of roles, transparency) recommended by the EDPB.
  • Provide for documentation of a Transfer Impact Assessment (TIA).

References: Standard Contractual Clauses 2021/914 (EUR‑Lex) and EDPB Recommendations 01/2020. The Service-Public portal summarises GDPR obligations for businesses (Service Public Pro). For operational implementation of SCCs, see also our guide to post-Schrems II transfers outside the EU.

4) Practical and enforceable audit arrangements

  • Audit right on reasonable notice (e.g. 15–30 days), without excessive disruption or access to source code beyond what is necessary.
  • Combination of on-site audits, remote audits and documentary reviews (ISO/IEC 27001, SOC 2 Type II, penetration test reports).
  • Confidentiality of audit information, sensitive areas redacted, allocation of costs according to the trigger.
  • Remediation plan and correction deadlines proportionate to severity.

5) Data handling at the end of the contract

Provide a documented process: return in a structured format, secure deletion after a grace period (e.g. 30–60 days), purging backups when their cycle expires, and a deletion certificate. Legal basis: GDPR art. 28(3)(g) and art. 32 (EUR‑Lex). The CNIL details good deletion and archiving practices (CNIL).

6) Annotated DPA outline for SaaS

Essential sections

  1. Definitions and contractual hierarchy (DPA takes precedence over terms of sale in a conflict).
  2. Detailed processing description (purposes, data, people, duration, location).
  3. Documented instructions and incident notification channel.
  4. Confidentiality and staff commitments.
  5. Security measures (TOMs annex) and change management.
  6. GDPR assistance: individuals' rights, DPIAs, records.
  7. Subprocessors: authorisation, list, right to object, flow-down, liability.
  8. Transfers outside the EU: SCCs, TIA, supplementary measures and transparency.
  9. Audits: scope, frequency, arrangements, cost, confidentiality.
  10. Return/deletion at the end of the contract, backup deadlines, certificate.
  11. Cooperation with the supervisory authority and notification “without undue delay” (art. 33(2)).
  12. Liability, limitation and indemnification (aligned with the main SaaS agreement).

Good practice: align your DPA with your essential SaaS contract clauses and compliant SaaS terms of sale to avoid contradictions.

7) Common mistakes to avoid

  • Confusing the processor's “without undue delay” deadline with the controller's 72 hours to notify the authority.
  • Forgetting support/maintenance access as potential transfers.
  • Failing to provide for ongoing updates to the subprocessor list.
  • An overly vague security annex (insufficiently precise for audits and cyber insurance).
  • Unlimited, unregulated audits that a startup cannot manage.

8) Quick method for producing a compliant DPA

  1. Map your processing and data: maintain up-to-date records (see our processing records template).
  2. List all your subprocessors and their locations, assess transfers.
  3. Draft the processing description and your internal instructions (incident runbooks, escalation channels).
  4. Prepare the TOMs annex: encryption, access, backups, tests, disaster recovery/business continuity plans.
  5. Include SCCs where necessary and carry out a TIA for each flow outside the EU (post-Schrems II SCC guide).
  6. Formalise audit arrangements and your security reporting schedule.
  7. Provide the end-of-contract procedure (export, purge, certificate).
  8. Align your DPA with your privacy policy and, for a broader overview, our complete DPA guide.

9) Negotiation points with enterprise clients

  • Audits: favour reliance on certifications/third-party reports, with on-site audits as a last resort.
  • Incident notification: commitment to prompt initial information (e.g. 24–48 hours), then iterative reports.
  • Subprocessor objections: specify a severity threshold and mitigation plan before any termination.
  • Limitation of liability: consistent with the SaaS agreement, excluding intentional violations or serious breaches of art. 32.
  • Transfers: transparent mapping of destinations and an exit timetable if major regulatory changes occur.

10) Sample useful wording

The Processor shall notify the Controller of any personal data breach without undue delay after becoming aware of it, communicating at least the nature of the incident, the categories and volumes of data potentially affected, and the measures taken or proposed to remedy it and mitigate its effects.

The Controller has a right to object with reasons to changes in Subprocessors, notified at least 30 days in advance. In the event of a reasonable objection, the Parties shall cooperate in good faith to find a solution; failing this, the Controller may terminate the affected part of the service without penalty.

Penalties and authorities

Failure to comply with DPA and Article 28 requirements may lead to inspections and penalties. Refer to the GDPR text (EUR‑Lex) and practical CNIL recommendations (CNIL). Professional summaries also provide an accessible overview (FrenchWeb) and (Witik).

Quick FAQ

  • Is a DPA always mandatory? Yes, whenever a provider processes data on behalf of a client, GDPR art. 28 (EUR‑Lex).
  • Do you need a specific DPA for each client? You can offer a standard DPA annexed to your terms of sale/SaaS agreement, adapted to the service and the client's options.
  • Does the 72-hour deadline apply to the processor? No. The processor notifies the controller “without undue delay”; the 72 hours concern the controller's notification to the authority, GDPR art. 33.
  • How do you govern transfers outside the EU? Use SCCs 2021/914 and supplementary measures following a TIA (EUR‑Lex) (EDPB).
  • Can audits be limited? Yes, by providing a proportionate mechanism (certifications, reports, audits on notice) without depriving the audit right of its substance.

Further reading

Related resources

Frequently asked questions

FAQ

My SaaS exposes only technical metadata: do I need a DPA?

Yes if that metadata is personal data (e.g. identifiers, IPs, logs linkable to a person). A DPA is required whenever processing is performed on behalf of the client (GDPR art. 28).

Can I impose my standard DPA on all clients?

Yes, provided it covers GDPR Article 28(3) and the client's specific circumstances. Provide modular annexes (subprocessor list, TOMs, locations).

Must the processor notify a breach within 72 hours?

No. It must notify the controller without undue delay. The 72-hour deadline concerns notification by the controller to the authority (GDPR art. 33).

How should the end of the contract be handled?

Provide structured export, a grace period, secure deletion (including backups at the end of their cycle) and a deletion certificate, unless otherwise required by law.

Are SCCs sufficient for transfers outside the EU?

They are often necessary but insufficient: carry out a TIA and add supplementary technical/organisational measures (EDPB 01/2020).

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles