GDPR Compliance for SaaS Companies
Processor obligations, DPAs, and enterprise-buyer trust for B2B SaaS
SaaS companies are processors for customer data and controllers for their own — two GDPR postures in one business. Enterprise buyers audit both. TruePrivacy operationalises Article 28 obligations, sub-processor governance, and the DSAR-assist duties your DPAs promise.
What GDPR requires of saas
Article 28 processor contracts
Every customer relationship needs a DPA covering instructions, confidentiality, security, sub-processing, and deletion — and your operations must match its terms.
Sub-processor transparency
Customers must be able to object to sub-processor changes — requiring an accurate public list and advance notice mechanics.
DSAR assistance duties
When your customer receives a DSAR, your DPA obliges you to assist — locating, exporting, and deleting their data subject's records on request.
Controller obligations for your own data
Marketing, product analytics, and employee data make you a controller — with lawful bases, notices, and DSARs of your own.
International transfers
Hosting, support, and sub-processors outside the EEA need SCCs, TIAs, and supplementary measures your enterprise customers will audit.
Breach notification to controllers
Processors must notify controllers without undue delay — your incident process feeds every customer's 72-hour clock.
How TruePrivacy helps
DPA obligation tracking
Commitments across your customer DPAs mapped to operational controls — so deletion terms, audit rights, and assistance duties are met, not just signed.
Sub-processor lifecycle management
A governed public list with change notifications, objection windows, and onboarding diligence records for every vendor in the chain.
Tenant-level data operations
Locate, export, and delete a specific data subject's records within a customer tenant — turning DSAR-assist requests from engineering tickets into workflows.
Dual-posture inventory
Processor and controller processing mapped separately, with your own lawful bases, RoPA, and DSAR workflows alongside customer-facing duties.
Security questionnaire acceleration
Audit-ready evidence for transfers, retention, and breach process — cutting enterprise procurement cycles from weeks to days.
“Every enterprise deal used to stall on the privacy questionnaire. Now our sub-processor list, transfer assessments, and deletion evidence are export-ready — our last security review closed in four days, and the DPA terms we sign are terms we can actually execute.”
Frequently asked questions
Are we a processor or a controller?
Both. For data your customers put into the platform you're a processor under their instructions; for marketing, billing, product analytics, and HR data you're a controller. TruePrivacy maintains both postures in one inventory so neither gets governed by accident.
What happens when a customer's data subject contacts us directly?
As processor you don't answer DSARs on the controller's behalf — you redirect to your customer and assist as the DPA requires. TruePrivacy logs the request, routes the notification, and tracks your assistance to completion.
How do we manage sub-processor objections?
Your DPAs typically promise advance notice and an objection window before adding sub-processors. TruePrivacy versions your sub-processor list, fires customer notifications, tracks objection periods, and records the diligence behind each addition.
Can we train product models on customer data?
Only within your customers' instructions — most DPAs don't authorise it, and aggregate or de-identified carve-outs need real anonymisation. TruePrivacy documents what each DPA permits and classifies your analytics pipelines against those terms before they ship.
Get GDPR-ready
Book a 30-minute demo and see how TruePrivacy handles GDPR compliance for saas.
Free 14-day trial · No credit card required · Setup in minutes