GDPR Compliance Checklist for SaaS Startups
If your software processes personal data of EU residents, GDPR applies — regardless of where your company is incorporated. This checklist covers what B2B and B2C SaaS companies need to have in place, from legal bases and privacy notices to processor agreements and breach notification.
Phase 1 — Establish Legal Bases for Processing
Before processing any personal data, identify your legal basis under Article 6. You need a different basis for each processing activity, and you cannot switch bases freely after the fact.
- Map every processing activity to a legal basis: contract, legitimate interests, or consent
- For contract: processing must be strictly necessary to perform the contract — not merely convenient
- For legitimate interests: complete a Legitimate Interests Assessment (LIA) documenting your interests, the necessity of processing, and that your interests override user rights
- For consent: collect separately, unbundled from terms; record when/how consent was given; provide a mechanism to withdraw
- For processing special categories of data (health, biometric, political views): a second legal basis under Article 9 is also required
Phase 2 — Privacy Notice and Transparency
Articles 13 and 14 require clear, accessible privacy information provided at or before the time of collection.
- Identity and contact details of the controller (and DPO if applicable)
- Purposes and legal basis for each processing activity
- Legitimate interests pursued (if that is the basis)
- Recipients or categories of recipients (including subprocessors)
- Retention periods for each category of data
- All data subject rights, including the right to withdraw consent and to lodge a complaint with a supervisory authority
- Whether automated decision-making or profiling is used, and its logic and consequences
- For data not collected directly from the subject: the source
Phase 3 — Data Processor Agreements
Article 28 requires a binding Data Processing Agreement between every controller and every processor they engage. For B2B SaaS, this means:
- Upstream: your customer is the controller; you (as SaaS provider) are the processor. You need a DPA with every business customer before processing their users' data.
- Downstream: for every third-party tool you use that processes customer data on your behalf (AWS, Stripe, Intercom, Mixpanel) — you need to verify those vendors have GDPR-compliant DPAs available. Most major providers do; check their compliance documentation.
A DPA must specify: subject matter and duration of processing, nature and purpose, type of personal data, categories of data subjects, obligations and rights of the controller. It must prohibit subprocessing without prior authorization and require the processor to assist with data subject requests and breach notification.
Phase 4 — Data Subject Rights
GDPR grants individuals a set of rights you must be able to fulfill, typically within one month of receiving a request:
- Right of access (Art. 15): provide a copy of all personal data held about the individual, plus supplementary information
- Right to rectification (Art. 16): correct inaccurate data without undue delay
- Right to erasure (Art. 17): delete personal data in specified circumstances (consent withdrawn, data no longer necessary for the original purpose, etc.)
- Right to data portability (Art. 20): provide data in a structured, machine-readable format where processing is based on consent or contract
- Right to object (Art. 21): where processing is based on legitimate interests, individuals can object; you must stop unless you can demonstrate compelling legitimate grounds
- Rights related to automated decision-making (Art. 22): if you make automated decisions with significant effects on individuals, specific rights and safeguards apply
Phase 5 — Data Breach Response
Every SaaS company needs a documented breach response procedure before a breach occurs:
- Maintain an internal breach register documenting all breaches, even those not requiring notification
- Within 72 hours of becoming aware of a notifiable breach: notify the lead supervisory authority (typically in the country where you have your main EU establishment, or where affected individuals are located if you have no EU establishment)
- Notification must include: nature of the breach, categories/approximate number of individuals and records affected, contact details of DPO or other contact point, likely consequences, and measures taken or proposed to address the breach
- If the breach is likely to result in high risk to individuals: notify those individuals directly without undue delay
- Processors must notify controllers without undue delay upon becoming aware of a breach, enabling controllers to meet their own 72-hour window
Phase 6 — International Data Transfers
Transferring personal data outside the EEA is only permitted where an appropriate safeguard is in place:
- Adequacy decision: the EU Commission has recognized certain countries as providing adequate protection (UK under a bridging mechanism, Japan, Canada for commercial transfers, among others). The US has the EU-US Data Privacy Framework (DPF) — US companies can self-certify to receive adequacy treatment.
- Standard Contractual Clauses (SCCs): the standard transfer mechanism for transfers to countries without an adequacy decision. You must use the 2021 EU SCCs and complete a Transfer Impact Assessment (TIA) for high-risk destinations.
- Binding Corporate Rules: approved internal policies for international transfers within a corporate group; requires supervisory authority approval — typically impractical for startups.
Phase 7 — Records of Processing Activities (ROPA)
Article 30 requires organizations with 250+ employees to maintain written records of processing activities. For smaller organizations, records are required if processing is likely to result in a risk to data subjects, if processing is not occasional, or if processing includes special categories of data.
In practice, most SaaS companies should maintain a ROPA regardless of size — it is the foundational accountability document, required in any regulatory investigation, and useful for managing data subject requests. A ROPA entry for each processing activity should include: purpose, legal basis, categories of data, categories of data subjects, recipients, retention periods, and any international transfers.
Review your vendor and customer agreements for GDPR gaps
DocAI scans DPAs, SaaS agreements, and privacy terms for missing GDPR provisions, incomplete processor clauses, and unlawful transfer mechanisms. $97 per contract, results in minutes.
Scan a Contract — $97Frequently Asked Questions
Does GDPR apply to my SaaS company if we are not based in the EU?
Yes. GDPR applies to any organization that processes personal data of individuals in the EU, regardless of where the company is established. If you have EU users, you are subject to GDPR. This extraterritorial scope (Article 3) is one of the most important features of the regulation.
What is a legal basis for processing under GDPR?
Before processing any personal data, you need a valid legal basis under Article 6. The most common bases for SaaS: (1) Contract — processing necessary to perform a contract with the user; (2) Legitimate interests — your interests in operating the service outweigh user rights (must document the balancing test); (3) Consent — explicit, freely given, specific, informed consent that can be withdrawn.
Do I need a Data Processing Agreement (DPA) with my customers?
Yes, if your customers are businesses (B2B) and you process their users' personal data on their behalf. Under Article 28, a DPA is mandatory whenever a data controller engages a data processor. As a SaaS company, you are typically a processor relative to your business customers, who are controllers. A DPA must be in place before you start processing.
What must I do if there is a data breach?
Under Article 33, if a personal data breach is likely to result in a risk to the rights and freedoms of individuals, you must notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Under Article 34, if the breach is likely to result in a high risk to individuals, you must also notify those individuals without undue delay.
What are the GDPR fines?
There are two tiers: up to €10 million or 2% of total worldwide annual turnover (whichever is higher) for violations of administrative provisions such as processor requirements; and up to €20 million or 4% of total worldwide annual turnover for violations of core principles including lawfulness, data subjects' rights, and international transfers. The 4% tier applies to the most serious violations.
Do I need a Data Protection Officer (DPO)?
A DPO is mandatory if you are a public authority, if your core activities involve large-scale systematic monitoring of individuals, or if you process special categories of data (health, biometric, etc.) on a large scale. Most B2B SaaS companies do not process special categories and are not public authorities, so a DPO is typically not required — but appointing one voluntarily or engaging a fractional DPO can help demonstrate accountability.