GDPR · SaaS

GDPR Compliance for SaaS Companies

Processor obligations, DPAs, and enterprise-buyer trust for B2B SaaS

SaaS companies are processors for customer data and controllers for their own — two GDPR postures in one business. Enterprise buyers audit both. TruePrivacy operationalises Article 28 obligations, sub-processor governance, and the DSAR-assist duties your DPAs promise.

What GDPR requires of saas

Article 28 processor contracts

Every customer relationship needs a DPA covering instructions, confidentiality, security, sub-processing, and deletion — and your operations must match its terms.

Sub-processor transparency

Customers must be able to object to sub-processor changes — requiring an accurate public list and advance notice mechanics.

DSAR assistance duties

When your customer receives a DSAR, your DPA obliges you to assist — locating, exporting, and deleting their data subject's records on request.

Controller obligations for your own data

Marketing, product analytics, and employee data make you a controller — with lawful bases, notices, and DSARs of your own.

International transfers

Hosting, support, and sub-processors outside the EEA need SCCs, TIAs, and supplementary measures your enterprise customers will audit.

Breach notification to controllers

Processors must notify controllers without undue delay — your incident process feeds every customer's 72-hour clock.

How TruePrivacy helps

01

DPA obligation tracking

Commitments across your customer DPAs mapped to operational controls — so deletion terms, audit rights, and assistance duties are met, not just signed.

02

Sub-processor lifecycle management

A governed public list with change notifications, objection windows, and onboarding diligence records for every vendor in the chain.

03

Tenant-level data operations

Locate, export, and delete a specific data subject's records within a customer tenant — turning DSAR-assist requests from engineering tickets into workflows.

04

Dual-posture inventory

Processor and controller processing mapped separately, with your own lawful bases, RoPA, and DSAR workflows alongside customer-facing duties.

05

Security questionnaire acceleration

Audit-ready evidence for transfers, retention, and breach process — cutting enterprise procurement cycles from weeks to days.

Every enterprise deal used to stall on the privacy questionnaire. Now our sub-processor list, transfer assessments, and deletion evidence are export-ready — our last security review closed in four days, and the DPA terms we sign are terms we can actually execute.

Hannah Lindqvist
General Counsel, Relaystack

Frequently asked questions

Are we a processor or a controller?

Both. For data your customers put into the platform you're a processor under their instructions; for marketing, billing, product analytics, and HR data you're a controller. TruePrivacy maintains both postures in one inventory so neither gets governed by accident.

What happens when a customer's data subject contacts us directly?

As processor you don't answer DSARs on the controller's behalf — you redirect to your customer and assist as the DPA requires. TruePrivacy logs the request, routes the notification, and tracks your assistance to completion.

How do we manage sub-processor objections?

Your DPAs typically promise advance notice and an objection window before adding sub-processors. TruePrivacy versions your sub-processor list, fires customer notifications, tracks objection periods, and records the diligence behind each addition.

Can we train product models on customer data?

Only within your customers' instructions — most DPAs don't authorise it, and aggregate or de-identified carve-outs need real anonymisation. TruePrivacy documents what each DPA permits and classifies your analytics pipelines against those terms before they ship.

Get GDPR-ready

Book a 30-minute demo and see how TruePrivacy handles GDPR compliance for saas.

Free 14-day trial · No credit card required · Setup in minutes