GDPR compliance for SaaS: which obligations actually apply to you?

The GDPR applies to any organisation established in the EU, and to organisations elsewhere that offer goods or services to, or monitor the behaviour of, people in the EU. There is no revenue or headcount threshold: if you process personal data within that scope, the regulation applies to you.

Applies to: Organisations established in the EU or EEA, and organisations elsewhere that offer goods or services to, or monitor the behaviour of, people in the EU.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Most SaaS founders meet the GDPR the moment they have a single user in the EU, and the usual question is not whether it applies but which parts create real work. The regulation is broad, but the day-to-day obligations for a growing software company come down to a short list. This hub explains who is in scope and points to a focused page for each of the duties you are most likely to act on.

Who the GDPR reaches

The GDPR applies in two situations. The first is where your organisation is established in the EU or EEA and processes personal data in the context of that establishment. The second, which catches most non-EU SaaS companies, is the extraterritorial rule in Article 3(2): even with no EU establishment, you are in scope if you offer goods or services to people in the EU or monitor their behaviour, for example through analytics or advertising technology. There is no revenue or headcount floor. Being small does not put you outside the regulation, though it can affect a few specific obligations. If you are a non-EU company, when the GDPR applies to a US SaaS works through the targeting and monitoring tests, and many companies caught this way must also appoint an EU representative under Article 27.

The obligations you meet most often

Once you are in scope, a handful of duties do most of the work. You need a lawful basis for every processing activity under Article 6, and a stronger basis for special category data under Article 9; where you rely on consent, the Article 7 conditions for valid consent decide whether it holds up. You must give clear privacy information when you collect data, the Article 13 and 14 duty that sets what a privacy notice includes. Beyond that, three operational duties come up again and again for SaaS teams, and each has its own page here: keeping a record of processing activities under Article 30, putting a data processing agreement in place with every vendor under Article 28, and running a data protection impact assessment for high-risk processing under Article 35, and checking whether you need a data protection officer under Article 37. You also have to honour individual rights on request, including the right of access, or DSAR, under Article 15, the right to erasure under Article 17, and the right to data portability under Article 20, and the right to object under Article 21, and the rules on automated decision-making and profiling under Article 22. When something goes wrong, you must be ready to meet the 72-hour breach notification duty under Articles 33 and 34. If you send EU personal data to the US or another third country, GDPR international data transfers explains the Chapter V mechanisms you need, and how GDPR fines are calculated shows what getting any of this wrong can cost.

Where the website itself is in scope

Your own site is part of compliance too. If you set analytics or advertising cookies on EU visitors, the cookie consent rules require valid consent before those cookies load, which is a separate obligation from the core processing duties above. Getting the banner right is often the most visible GDPR task a SaaS company faces, because it is the part every visitor sees.

Next step

The fastest way to see which of these obligations currently applies to your setup is to run the free 2-minute Obligation Scan. It maps how you process personal data to the specific GDPR duties that follow, so you can act on the ones that matter to you rather than working through the whole regulation.

Compliance checklist

  • Confirm whether you are established in the EU, or offer goods or services to or monitor people in the EU (Article 3).
  • Identify a lawful basis for each processing activity, and the higher basis for special category data (Articles 6 and 9).
  • Give clear privacy information at the point of collection (Articles 13 and 14).
  • Keep records of processing, sign processor contracts, and run impact assessments where the risk is high (Articles 30, 28, and 35).
  • Have a breach process that can meet the 72-hour notification deadline (Articles 33 and 34).

Sources

Last verified: 2026-08-11

Informational, not legal advice.