A blog that helps software companies navigate GDPR compliance
Only vendors that process personal data on your behalf. That is fewer than every supplier and more than most SaaS companies assume.
Posted by Kevin Yun | 2026-09-06T15:52:33.064Z
For most B2B SaaS companies one accountable owner is enough. The regulation asks for accountability and evidence, not for headcount.
Posted by Kevin Yun | 2026-09-05T05:41:33.370Z
It depends on whether they work under your direct authority or as an independent processor. Employment status decides it, not the invoice.
Posted by Kevin Yun | 2026-09-05T05:39:51.789Z
Yes. Fixtures, env files, screenshots and build artefacts hold personal data, and git history makes deletion genuinely harder than elsewhere.
Posted by Kevin Yun | 2026-09-04T18:24:43.673Z
Yes. Internal dashboards hold the same personal data as your product, and they are the systems most often missing from a data map entirely.
Posted by Kevin Yun | 2026-09-04T18:23:20.759Z
Yes. Public availability does not make personal data non-personal, and scraping triggers an Article 14 duty to inform people within one month.
Posted by Kevin Yun | 2026-09-03T18:56:33.669Z
Yes, and the regulation says so in terms: Article 3(2)(a) applies irrespective of whether payment is required. Free users are data subjects too.
Posted by Kevin Yun | 2026-09-03T18:54:42.180Z
SCCs are a contract you sign today. BCRs are an internal rulebook a regulator must approve. For almost every SaaS, only one of those is realistic.
Posted by Kevin Yun | 2026-09-02T08:12:35.177Z
If GDPR reaches you through Article 3(2) and you have no EU establishment, you probably need one. The exemption is narrower than most companies hope.
Posted by Kevin Yun | 2026-09-02T08:10:16.674Z
Popular Posts
The 7 Basic Principles of GDPR Compliance
GDPR Cookie Consent (Banner): An Essential Guide, Checklist, and Examples
OpenAI's GDPR Compliance: Understanding the €15 Million Fine and What It Means for AI Companies
GDPR Software ROI: Is It Worth the Investment?
GDPR and the Consequences of Non-Compliance: What B2B SaaS Companies Need to Know
New to ComplyDog? Your Guide to Getting Started
What is a DPA? Data Processing Agreement for GDPR Explained
GDPR Compliance Checklist For B2B SaaS Companies
GDPR Implementation Examples: Success Stories for B2B SaaS Companies
With ComplyDog, our team was able to create a fully compliant GDPR page in just 30 minutes. We were impressed with how user-friendly the interface was, and how it guided us step-by-step through the process. The tool even helped us to identify potential privacy issues on our site that we hadn"t considered before, which was incredibly helpful.
Sagar Soni
Co-Founder at Requestify