GDPR Compliance Checklist for SaaS Companies and Startups (2026)
An auditor-grade GDPR compliance checklist for SaaS companies and startups: who is in scope, lawful bases, data subject rights, international transfers, breach rules, and a 10-step plan.
To be GDPR compliant, a SaaS company must map the personal data it processes, establish a lawful basis for each processing activity, publish a clear privacy notice, honour data subject rights (access, deletion, portability and more) within one month, keep records of processing (Article 30), sign data processing agreements with every sub-processor, secure personal data appropriately, report qualifying breaches to a supervisory authority within 72 hours, and legally cover any transfers of data outside the EEA. GDPR applies to you if you offer goods or services to people in the EU or monitor their behaviour, even if your company has no EU office.
If that sounds like a lot, it is, but it is a finite, well-defined list. This guide turns the General Data Protection Regulation (Regulation (EU) 2016/679) into an ordered checklist you can actually work through, with the specific articles, deadlines and penalties an auditor will hold you to, and a note on the reforms being debated in 2026.
Does GDPR actually apply to my SaaS?
GDPR has extraterritorial scope under Article 3. It applies to your business if either of the following is true, regardless of where you are incorporated or where your servers sit:
- You are established in the EU/EEA and process personal data in that context; or
- You are outside the EU/EEA but you offer goods or services to individuals in the EU/EEA (paid or free), or monitor the behaviour of individuals in the EU/EEA (analytics, tracking, profiling).
For a typical SaaS product, offering services to people in the EU is triggered by things like pricing in euros, serving EU customers, translating your site into an EU language, or simply signing up EU-based users. A US or Nigerian startup with EU users is squarely in scope. Merely having a website accessible from Europe is not enough on its own; the test is whether you envisage offering services to people in the EU.
Controller vs processor - know which you are. You are a controller when you decide why and how personal data is processed (your own customer and marketing data), and a processor when you handle personal data on behalf of a customer (the data your customers put into your product). Most B2B SaaS companies are both. Your obligations differ for each role, so label every dataset accordingly.
The 10-step GDPR compliance checklist for SaaS
Work through these in order. Steps 1-3 are the foundation; skipping them makes everything else guesswork.
1. Build a data map (Records of Processing Activities - Article 30)
You cannot protect what you have not inventoried. Document every category of personal data you process: what it is, why you process it, the lawful basis, who it is shared with, where it is stored, how long you keep it, and any transfers outside the EEA. This record is a hard legal requirement under Article 30 for most organisations, and it is the first document a regulator or an enterprise customer's security team will ask to see.
2. Establish a lawful basis for every processing activity (Article 6)
There is no processing without a lawful basis. GDPR gives you six, and you must pick the right one per activity - you cannot fall back to consent for everything:
- Consent - freely given, specific, informed, unambiguous, and as easy to withdraw as to give.
- Contract - necessary to deliver the service the user signed up for.
- Legal obligation - required by law (e.g. tax records).
- Vital interests - life-or-death situations (rare in SaaS).
- Public task - official authority (rare in SaaS).
- Legitimate interests - your genuine business need, balanced against the individual's rights (requires a documented balancing test).
For core product functionality, contract is usually the basis. For product analytics and most marketing you will rely on consent or legitimate interests - and for cookies and similar tracking, the ePrivacy rules mean consent is generally required.
3. Write a plain-English privacy notice (Articles 13-14)
Publish a privacy policy that tells people, in clear language, who you are, what you collect, why, your lawful basis, who you share it with, how long you keep it, their rights, and how to complain to a supervisory authority. Vague, boilerplate policies are a common enforcement trigger. Transparency is not optional decoration; it is a substantive obligation.
4. Build the machinery to honour data subject rights (Articles 15-22)
Individuals have enforceable rights, and you must respond without undue delay and within one month:
- Access - a copy of their data (Art 15)
- Rectification - correct inaccurate data (Art 16)
- Erasure - the right to be forgotten (Art 17)
- Restriction of processing (Art 18)
- Portability - their data in a machine-readable format (Art 20)
- Objection - including to direct marketing, which is absolute (Art 21)
- Automated decision-making and profiling safeguards (Art 22)
For SaaS, the practical implication is that deleting an account must genuinely delete or anonymise data (including in backups, on a defensible schedule), and you need a real workflow, not an inbox someone checks occasionally.
5. Sign a Data Processing Agreement with every sub-processor (Article 28)
Every third party that touches personal data on your behalf - cloud hosting, email, analytics, support tools, payment processors - must be bound by a Data Processing Agreement meeting Article 28 requirements. Maintain a current sub-processor list. When you act as a processor for your customers, you must sign a DPA with them and flow those obligations down. Missing DPAs are one of the most common findings in SaaS due diligence.
6. Secure the data (Article 32)
Article 32 requires appropriate technical and organisational measures: encryption in transit and at rest, access controls and least privilege, logging and monitoring, tested backups, and a vulnerability-management process. GDPR does not prescribe a specific standard, but certifying to ISO/IEC 27001 is the cleanest way to evidence Article 32 to auditors and enterprise buyers.
7. Stand up a 72-hour breach response process (Articles 33-34)
If you suffer a personal data breach that poses a risk to individuals, you must notify the relevant supervisory authority within 72 hours of becoming aware of it (Art 33). If the risk to individuals is high, you must also notify the affected individuals (Art 34). Seventy-two hours is not long - you need an incident runbook, defined roles, and a decision log before anything happens.
8. Run a DPIA for high-risk processing (Article 35)
A Data Protection Impact Assessment is mandatory before processing that is likely to result in a high risk - large-scale profiling, processing special-category data (health, biometrics), or systematic monitoring. If your SaaS does any of these, the DPIA is not optional, and it must be documented.
9. Appoint a DPO and/or EU representative where required (Articles 27 and 37)
You must appoint a Data Protection Officer (Art 37) if your core activities involve large-scale systematic monitoring or large-scale processing of special-category data. Separately, if you are established outside the EU but in scope, you generally must appoint an EU representative under Article 27 - a contactable presence inside the EU. Non-EU SaaS companies frequently miss the Article 27 obligation entirely.
10. Cover your international data transfers (Chapter V)
If personal data leaves the EEA - which it does the moment you use a US cloud provider - you need a valid transfer mechanism: an adequacy decision, Standard Contractual Clauses (SCCs), or Binding Corporate Rules, often supported by a transfer impact assessment. This is the most volatile area of GDPR in 2026 (see below), so treat your transfer basis as something to review, not set-and-forget.
International transfers in 2026: the DPF is valid but contested
Many SaaS companies rely on the EU-US Data Privacy Framework (DPF), the adequacy decision the European Commission adopted on 10 July 2023, to send data to certified US providers. As of mid-2026 the DPF remains in force and valid, but it is under active legal pressure:
- French MP Philippe Latombe's challenge was dismissed by the EU General Court in September 2025, but he appealed to the Court of Justice of the EU (CJEU), and that appeal is pending.
- A June 2026 US Supreme Court ruling touching the independence of the Federal Trade Commission - an authority the Commission expressly relied on when granting adequacy - has prompted privacy group noyb to prepare a fresh challenge.
The practical takeaway: do not rely on the DPF as your only line of defence. Keep SCCs in place as a fallback for key vendors, and monitor the CJEU, because the last two US adequacy mechanisms (Safe Harbor and Privacy Shield) were both struck down.
👉 Managing shifting transfer rules across dozens of sub-processors is exactly what a live compliance workspace is for. See how RegentComply tracks it: https://regentcomply.ai/request-demo
What GDPR non-compliance actually costs
GDPR has two tiers of administrative fines under Article 83:
- Higher tier: up to €20 million or 4% of total worldwide annual turnover, whichever is higher - for breaches of core principles, lawful basis, and data subject rights.
- Lower tier: up to €10 million or 2% of worldwide annual turnover - for breaches of obligations like security (Art 32) and records (Art 30).
These are ceilings, and regulators weigh the nature and gravity of the breach. But the figures are real: the largest single GDPR fine to date, issued to Meta in May 2023, was €1.2 billion, and it concerned international data transfers - the very area covered in step 10. For a startup, the more immediate cost is usually commercial: enterprise procurement teams will not sign without evidence of a functioning GDPR programme, so gaps directly stall revenue.
Realistic timeline and cost for a SaaS startup
For an early-stage SaaS with a straightforward product, reaching a defensible baseline typically takes 6-12 weeks of focused effort:
- Weeks 1-3: data map, lawful-basis analysis, privacy notice.
- Weeks 3-6: DPAs with sub-processors, transfer mechanisms, security baseline.
- Weeks 6-10: data subject rights workflow, breach runbook, DPIA if needed.
- Weeks 10-12: DPO/representative appointments, internal training, review.
Cost is mostly time, not licence fees. The expensive path is the one most startups take by default: ignoring GDPR until an enterprise deal or a regulator forces a scramble, then paying consultants premium rates to reconstruct records that should have been kept all along.
Common GDPR mistakes SaaS companies make
- Treating consent as the catch-all lawful basis. For most product processing, contract or legitimate interests is correct.
- No Records of Processing. Article 30 is mandatory and it is the first thing regulators and enterprise buyers request.
- Forgetting the Article 27 EU representative. Non-EU SaaS in scope almost always overlook this.
- Delete that doesn't delete. Erasure requests that leave data live in backups or analytics tools.
- Missing or generic DPAs with sub-processors, or none at all with customers.
- Set-and-forget transfers. Relying on the DPF without an SCC fallback in a year when the DPF is under challenge.
2026 reform watch: the EU Digital Omnibus (proposed, not yet law)
On 19 November 2025 the European Commission published the Digital Omnibus, the most significant proposed change to GDPR since it took effect in 2018. Among other measures, it would raise the Article 30(5) records-of-processing exemption threshold from organisations with fewer than 250 employees to fewer than 750, unless the processing is high-risk, and extend certain SME reliefs to small mid-cap companies.
Important: as of mid-2026 these are proposals, not law. They are still moving through the European Parliament and Council, with adoption not expected before late 2026 at the earliest. Build your programme against the current GDPR text, and treat the Omnibus as a horizon item. Anyone telling you the records obligation has already been relaxed is wrong.
Frequently asked questions
Does GDPR apply to a US or Nigerian startup with EU users?
Yes. Under Article 3, GDPR applies to any business offering goods or services to individuals in the EU/EEA or monitoring their behaviour, regardless of where the company is based or hosts its data.
Do I need a Data Protection Officer?
Only if your core activities involve large-scale systematic monitoring or large-scale processing of special-category data (Article 37). Many small SaaS companies do not strictly need a DPO - but if you are a non-EU company in scope, you very likely need an EU representative under Article 27, which is a separate requirement.
Is consent always required?
No. Consent is one of six lawful bases. For delivering the service a user signed up for, contract is usually correct; for analytics and marketing you may use consent or legitimate interests. Cookies and similar tracking, however, generally do require consent under the ePrivacy rules.
How fast do I have to respond to a data subject request?
Without undue delay and within one month of receiving the request. You may extend by up to two further months for complex or numerous requests, but you must tell the individual within the first month.
How long do I have to report a data breach?
Within 72 hours of becoming aware of a breach that poses a risk to individuals (Article 33). If the risk is high, you must also inform affected individuals (Article 34).
Is the EU-US Data Privacy Framework still valid in 2026?
Yes, it remains in force, but it is being challenged (the Latombe appeal is pending at the CJEU and a further challenge is being prepared). Prudent SaaS companies keep Standard Contractual Clauses in place as a fallback.
What is the maximum GDPR fine?
Up to €20 million or 4% of worldwide annual turnover, whichever is higher, for the most serious breaches (Article 83).
Turn the checklist into a living programme
GDPR compliance is not a document you write once - it is a set of records, tasks and controls you keep current as your product, sub-processors and the law change. The companies that pass enterprise due diligence quickly are the ones whose data map, DPAs, transfer bases and breach procedures are always up to date, not reconstructed under deadline pressure.
RegentComply gives compliance and founding teams a single workspace to run frameworks like GDPR, ISO 27001, DORA and NIS2 side by side - with tasks, evidence and recurring reviews tracked in one place, and AI assistance to draft the records and policies. The platform is free to start; you only pay for AI features.
Related reading on the RegentComply blog: the ISO 27001 readiness checklist, the DORA compliance requirements guide, and the MiCA compliance checklist.
👉 Request a demo and see your GDPR programme mapped in minutes: https://regentcomply.ai/request-demo
This guide is general information, not legal advice. Regulatory detail is current as of July 2026; verify specifics against the official GDPR text (Regulation (EU) 2016/679) and your supervisory authority before relying on it.