Every app in your stack processes data. Here's a systematic approach to GDPR compliance that scales as your estate grows.
GDPR compliance for SaaS is not a one-time project — it's an ongoing programme that needs to keep pace with your evolving software estate. Every new tool your organisation adopts is potentially a new data processor, and GDPR requires you to have a Data Processing Agreement (DPA) in place with every processor handling EU personal data.
Data processor inventory: Maintain a list of every SaaS tool that processes personal data, along with the categories of data processed, the legal basis for processing, and data residency information. This is your Article 30 record of processing activities.
DPAs in place: Every tool on your data processor inventory should have a signed DPA. Most major SaaS vendors provide standard DPAs available for download from their privacy or legal pages. Track signature dates and review cycles.
Data residency: If you have EU data subjects, verify that personal data is stored in the EU or in a country with an adequacy decision. For US-based vendors, check whether they operate under the EU-US Data Privacy Framework or have Standard Contractual Clauses in place.
Retention and deletion: Your contracts should specify how long the vendor retains your data after termination and how deletion is confirmed. Review these terms against your own retention policies.
The compliance burden grows linearly with the number of tools you use. The only way to manage it at scale is to build GDPR review into your procurement process — every new tool goes through a data processing assessment before adoption, not after.
A lightweight Data Processing Assessment (DPA review, not to be confused with the Data Processing Agreement of the same acronym) should be completed for every new SaaS tool before adoption. It should answer: what categories of personal data will this tool process? What is the legal basis for processing? Where will data be stored? How long will it be retained? Who are the vendor's sub-processors? This assessment takes 15–30 minutes per tool when templates are pre-built and the vendor's privacy documentation is accessible — most mature SaaS vendors publish comprehensive privacy and security documentation precisely to facilitate this kind of review.
Store the completed assessment alongside the contract in your vendor records. When your DPO conducts an annual compliance review or an auditor requests evidence of third-party risk management, the assessment record is your primary evidence. Having it pre-completed saves significant effort at audit time compared to conducting the assessment retrospectively under time pressure.
GDPR requires you to be aware of the sub-processors your vendors use — the third parties to whom your data processor (the SaaS vendor) further discloses your data. Most SaaS vendors publish their sub-processor list on their privacy or legal page and notify customers of changes. Subscribe to these notifications for all critical vendors and review each sub-processor addition with the same lens as the primary vendor assessment.
Under GDPR, you have the right to object to a new sub-processor within a defined window (typically 30 days after notification). In practice, objecting is rare — but the notification and review process ensures you're aware of where your data flows and can flag cases where a new sub-processor creates a data residency or adequacy concern that needs to be resolved before the sub-processor relationship begins.
GDPR requires data controllers to notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it. This requires a clear internal breach response process: who is responsible for receiving breach notifications from vendors, who assesses severity, who makes the notification decision, and who drafts and files the notification. The SaaS tool that is breached will notify you; how you respond in the following 72 hours is your compliance obligation.
Ensure your vendor contracts specify the vendor's obligation to notify you of a breach within a timeframe that gives you enough time to assess and notify. Standard market terms typically require vendor notification within 24–48 hours of the vendor becoming aware — sufficient to meet your 72-hour regulatory window if your internal response process is clear and well-rehearsed.
Track every licence, cut waste, and automate renewals — in one platform.
Comments are moderated before appearing publicly.
No comments yet. Be the first to share your thoughts.
Ronke
Liceo product guide · AI assistant
Hi, I'm Ronke, Liceo's product guide. I can help you understand how we bring licence, vendor, and spend visibility together, or walk through plans and integrations. What are you trying to solve today?