A blog that helps software companies navigate GDPR compliance
Almost none of it turns on headcount. There is no employee threshold for scope, and the two places numbers appear are narrower than they look.
Posted by Kevin Yun | 2026-09-08T14:58:52.805Z
Usually yes for the part that touches the device, and that is a separate question from your lawful basis for the processing that follows.
Posted by Kevin Yun | 2026-09-08T14:55:48.944Z
The controller and the processor both do. In a B2B SaaS deal your customer signs yours, and you sign your vendors' — often on the same day.
Posted by Kevin Yun | 2026-09-06T15:58:42.261Z
Only vendors that process personal data on your behalf. That is fewer than every supplier and more than most SaaS companies assume.
Posted by Kevin Yun | 2026-09-06T15:52:33.064Z
For most B2B SaaS companies one accountable owner is enough. The regulation asks for accountability and evidence, not for headcount.
Posted by Kevin Yun | 2026-09-05T05:41:33.370Z
It depends on whether they work under your direct authority or as an independent processor. Employment status decides it, not the invoice.
Posted by Kevin Yun | 2026-09-05T05:39:51.789Z
Yes. Fixtures, env files, screenshots and build artefacts hold personal data, and git history makes deletion genuinely harder than elsewhere.
Posted by Kevin Yun | 2026-09-04T18:24:43.673Z
Yes. Internal dashboards hold the same personal data as your product, and they are the systems most often missing from a data map entirely.
Posted by Kevin Yun | 2026-09-04T18:23:20.759Z
Yes. Public availability does not make personal data non-personal, and scraping triggers an Article 14 duty to inform people within one month.
Posted by Kevin Yun | 2026-09-03T18:56:33.669Z
Popular Posts
The 7 Basic Principles of GDPR Compliance
GDPR Cookie Consent (Banner): An Essential Guide, Checklist, and Examples
OpenAI's GDPR Compliance: Understanding the €15 Million Fine and What It Means for AI Companies
GDPR Software ROI: Is It Worth the Investment?
GDPR and the Consequences of Non-Compliance: What B2B SaaS Companies Need to Know
New to ComplyDog? Your Guide to Getting Started
What is a DPA? Data Processing Agreement for GDPR Explained
GDPR Compliance Checklist For B2B SaaS Companies
GDPR Implementation Examples: Success Stories for B2B SaaS Companies
With ComplyDog, our team was able to create a fully compliant GDPR page in just 30 minutes. We were impressed with how user-friendly the interface was, and how it guided us step-by-step through the process. The tool even helped us to identify potential privacy issues on our site that we hadn"t considered before, which was incredibly helpful.
Sagar Soni
Co-Founder at Requestify