Home Blog At What Headcount Does GDPR Get Serious for a SaaS?

GDPR

At What Headcount Does GDPR Get Serious for a SaaS?

Posted by Kevin Yun|September 8, 2026

Almost none of it turns on headcount, which is an unsatisfying answer to a reasonable question. There is no employee threshold anywhere in the scope provisions. A three-person company with EU users carries the same core obligations as a three-hundred-person one. Numbers appear in exactly two places in the regulation, and both are about what you do rather than how many people you employ.

This article covers why scope has no size test, what Article 30(5) actually says, why Article 37 is about scale and nature rather than staff count, what genuinely changes as a SaaS grows, and the one place a staff number moves a real figure.

Scope Has No Size Test

Article 3 sets territorial scope by establishment and by targeting. If you are established in the Union, or you offer goods or services to people in the Union, or you monitor their behaviour there, the regulation applies. There is no clause about employees, revenue or funding stage.

The same is true of the substantive obligations. Lawful basis, transparency, security, data subject rights, breach notification and the accountability principle all attach from the first record you hold. A two-person company that suffers a breach has the same 72-hour assessment obligation as a large one.

This is worth stating clearly because a great deal of advice aimed at small companies implies otherwise, and much of it is generic enough to leave the impression that the rules loosen below some line. They do not. What genuinely varies is proportionality: Article 24 asks for measures appropriate to the nature, scope, context and purposes of processing and the risks involved, which means a small company with low-risk processing can do less and defend it. That is a different claim from being exempt, and a general affordable implementation approach for a new company is about how to sequence the work rather than about which parts you can skip.

Article 30(5) Is The Only Real Number, And It Is A Ceiling

The one headcount figure in the regulation is in Article 30(5), which disapplies the record-keeping obligations for an enterprise employing fewer than 250 persons — unless the processing is likely to result in a risk to the rights and freedoms of data subjects, or the processing is not occasional, or it includes special category data under Article 9(1) or criminal conviction data under Article 10.

Read the carve-outs and the exemption evaporates for essentially every SaaS company. Running customer accounts is not occasional. Payroll is not occasional. A CRM is not occasional. The exemption was written for genuinely sporadic processing — the kind of one-off activity a small organisation does a few times a year — and it does not describe a business whose product holds user records continuously.

Two details are worth knowing. The 250 figure counts the enterprise's total employees, not the number involved in the processing. And "fewer than 250" is a ceiling above which the exemption is unavailable at all, rather than a safe harbour below it. Ireland's Data Protection Commission ran a sweep of thirty organisations' records in early 2022 and asked those without one to explain why; the exemption was available to some, and the fact that it had to be justified rather than assumed is the useful part.

The practical conclusion is the same one most regulators reach: treat the record of processing activities as mandatory regardless of size. That page covers the obligation itself, its mandatory fields and this exemption in its own right; what follows here is only the question of what genuinely changes as you grow.

Article 37 Is About What You Do, Not How Many You Are

The second place numbers appear is the data protection officer obligation, and it is not a headcount test either. Article 37(1) requires a designation where the controller is a public authority, where core activities require regular and systematic monitoring of data subjects on a large scale, or where core activities involve large-scale processing of special category or criminal offence data.

Both operative triggers turn on the nature and scale of the processing. A ten-person analytics company whose entire product is behavioural monitoring is far closer to the threshold than a two-hundred-person company selling invoicing software. Growing the team changes neither.

"Core activities" is doing real work in that sentence: it means the processing that is inseparable from what you sell, not administrative processing every company does. Payroll and HR are not core activities for a software company even though they involve special category data.

Whether a particular business crosses the line, and what the role requires once it does, is a bigger question than this article. The point here is that you will not answer it by counting employees.

What Actually Changes As You Grow

The triggers that genuinely change your obligations are events, not numbers, and they are mostly commercial.

Your first EU or UK user. Territorial scope engages. If you have no establishment there, this is also where an Article 27 representative comes into view — and that obligation applies regardless of company size, which surprises founders more than anything else on this list.

Your first enterprise buyer. Nothing legal changes, but the evidence burden does. Vendor reviews ask for documents that already had to exist, and this is where most companies discover which ones do not.

Your first special category data. Health, biometrics, or anything under Article 9(1). Constraints tighten sharply and several previously comfortable positions stop working.

Your first EU establishment. A subsidiary or staff on the ground moves you into Article 3(1), changes your lead supervisory authority analysis, and removes the Article 27 obligation by replacing it with something larger.

Your first serious incident. The 72-hour clock does not care how many people you employ, and it is the moment your documentation is tested rather than described.

The One Place Staff Count Genuinely Moves A Number

There is a real headcount threshold, and it is not in the GDPR at all — it is the UK data protection fee, which is a separate registration obligation administered by the ICO.

Its tiers use turnover or staff count, and the criteria are alternatives rather than cumulative, which several secondary sources get wrong. Staff count includes overseas staff, averaged monthly across the financial year. It is genuinely a number, it genuinely changes what you pay, and it is completely separate from anything in the GDPR itself — whether you have to register with the ICO and what it costs is its own question with its own answer, and conflating the fee with compliance is a frequent error.

Everything else that feels like it scales with headcount is really scaling with something else: more staff means more systems, more vendors, more access to manage and more data. The obligations did not change. Your surface did.

Common Mistakes With Size And GDPR

Believing the fewer-than-250 exemption applies to you. It requires the processing to be occasional, low-risk and free of special category data as well as under the headcount. Continuous customer accounts fail the first test on their own.

Deferring documentation until "we are big enough." The record of processing activities is cheapest to build when there are eight systems rather than eighty. Waiting means reconstructing history from memory and expense reports.

Assuming a DPO obligation arrives at a certain team size. It arrives with regular systematic monitoring at scale or large-scale special category processing as core activities. Some very small companies are caught; many large ones are not.

Confusing the ICO fee with GDPR compliance. Paying the fee is a UK registration obligation. It does not demonstrate compliance with anything else, and being exempt from it does not exempt you from UK GDPR.

Treating proportionality as permission to skip. Article 24 lets a small company implement lighter measures where the risk is genuinely lower. It does not let you omit a lawful basis, a retention position or a breach process, and "we are small" is not a documented risk assessment.

FAQ

Is there a minimum company size below which GDPR does not apply?

No. There is no lower threshold for scope in Article 3 or for the substantive obligations. A sole trader processing EU personal data is within scope. What varies is what proportionate measures look like, not whether the regulation applies.

We are a US company with a handful of EU users. Does the regulation really apply?

If you are targeting them rather than merely being reachable, yes. Mere accessibility of a website from the EU is not enough on its own; indicators like EU currencies, languages, EU-targeted advertising or region-specific support point to intentional offering. A handful of users you deliberately signed up is different from one who found you by accident.

Does the fewer-than-250 exemption mean we do not need a data map?

Practically, no. Even where the Article 30 obligation were disapplied, you still need to know what you hold to answer data subject requests, name a lawful basis, set retention and assess a breach. The record is the artefact that makes all of those possible, which is why it is worth having regardless.

When should we start taking this seriously?

Before the first EU user, if you can, because retrofitting is more expensive than sequencing. The realistic answer for most founders is at the first enterprise sales conversation, when someone asks for evidence and the cost of not having it becomes a deal timeline rather than an abstraction.

Closing Thought

The question contains an assumption worth examining, which is that compliance obligations scale with company size the way most business obligations do. Employment law, financial reporting and tax all have thresholds, so it is reasonable to expect data protection to have them too. It largely does not, because the regulation is built around risk to individuals rather than capacity of organisations, and a small company can create a great deal of risk. Ten people with a database of two million users is not a small data protection problem.

Which means the useful question is not "are we big enough yet" but "what do we actually hold, and can we show it." Checked 8 August 2026, that remains the thing every buyer, regulator and data subject asks for first. ComplyDog hosts a compliance portal on your own domain covering your DPA, subprocessor list, data subject request handling and security page, which is the answering layer once you have the underlying record. It does not build the record, set your retention periods or tell you whether your processing is large-scale — those are the judgements that come first, and they do not get easier by waiting.