Scrutineer.ai

Scrutineer · By framework

GDPR compliance for SaaS companies with EU customers

An EU customer's privacy review asks three things of a US SaaS vendor: your DPA, your sub-processor list and how the data legally gets to the US. Missing any one stalls the deal.

Scrutineer maps your GDPR processor and controller duties to the controls you already run for SOC 2, tracks each sub-processor and its transfer route, and keeps the evidence current. Compliance software, not legal advice.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with GDPR for SaaS

A SaaS company is two things under GDPR at once

For the data your customers load into the product, you are almost always a processor acting on their instructions. For your own account, billing, marketing and product analytics data, you are a controller. Most GDPR for SaaS guides describe only one of these roles. The processor side is what EU customers audit through your DPA, your sub-processor list and your security questionnaire. The controller side is what brings you directly under Article 3(2) the moment you offer the product to people in the EU, which usually means a privacy notice, a lawful basis for each purpose, a way to handle access and deletion requests and, unless your processing is occasional, an EU representative under Article 27. Map both roles to controls, because a single mistake in one does not show up in the other.

GDPR follows the person in the EU, not the passport

GDPR protects people who are in the Union, whatever their nationality. An EU citizen using your product from Texas is generally outside Article 3(2); a US citizen signing up from Paris is inside it. For a processor, the EDPB is explicit in Guidelines 3/2018: a processor not established in the EU is not made subject to GDPR just because it serves an EU controller. GDPR reaches it through the Article 28 contract and the transfer terms instead. That is why, for most US B2B SaaS companies, the DPA is not paperwork around GDPR compliance. It is the GDPR compliance, and every clause in it is an obligation you have to evidence.

Your transfer mechanism covers you, not your sub-processors

Self-certifying to the EU-US Data Privacy Framework lets an EU customer transfer personal data to you without Standard Contractual Clauses. It says nothing about where you send the data next. Each sub-processor that receives that data needs its own lawful route, whether its own DPF certification, SCCs or an adequacy decision, and your DPA usually promises the customer you have checked. The DPF also has to be recertified every year, and a lapsed certification quietly breaks the promise in every contract that relies on it. The General Court upheld the DPF in Latombe v Commission on 3 September 2025, and that judgment can be appealed, so most SaaS DPAs keep SCCs as a fallback.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps your GDPR processor obligations under Article 28 (instructions, confidentiality, security, sub-processors, assistance, deletion, audits) to the controls you already run for SOC 2 and ISO 27001
  • Keeps the sub-processor register behind your public list: what each one receives, where it processes, and which transfer mechanism covers it
  • Tracks your own EU-US Data Privacy Framework recertification date and each sub-processor's DPF status, so a lapse is flagged before a customer finds it
  • Evidences Article 32 security measures from live systems (access reviews, encryption settings, logging, backups) instead of a policy PDF
  • Runs a processor incident workflow that notifies the affected customer without undue delay, so they can meet their own 72-hour clock under Article 33
  • Drafts answers to EU customers' GDPR and security questionnaires from the same mapped controls and evidence
  • Holds your records of processing activities as a processor under Article 30(2), per customer category and per sub-processor
  • Adds SOC 2, ISO 27001, HIPAA and PCI DSS on the same control library when the next customer segment asks
GDPR for SaaS readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Scoping GDPR for a SaaS company

How GDPR reaches a US SaaS company, by situation

Most GDPR for SaaS guides say the law applies to anyone handling EU citizens' data. That is wrong twice: it follows people in the EU, not citizens, and it reaches a non-EU processor through its contracts rather than directly. Your situation decides your role, your transfer mechanism and what a customer will ask for.

Your situation Your GDPR role How GDPR reaches you Transfer mechanism you need What EU customers ask for
US SaaS selling to EU businesses, no EU office Processor for customer data, controller for your own account data Through the Article 28 DPA and transfer terms for customer data (EDPB Guidelines 3/2018), and directly under Article 3(2) for account and marketing data DPF self-certification or SCCs Module 2 from each customer to you DPA, sub-processor list, security measures annex, breach notice terms, SOC 2 or ISO 27001 report
US SaaS with self-serve signups from individuals in the EU Controller Directly, under Article 3(2)(a), because you offer the service to people in the Union None for data you collect directly; SCCs or DPF for onward transfers to your vendors Privacy notice, lawful basis per purpose, access and deletion handling, Article 27 EU representative unless processing is occasional
US SaaS serving US customers who upload data about people in the EU Processor for a controller that may itself be under Article 3(2) Through your customer's DPA, which passes GDPR terms down to you Whatever your customer's contract requires, often SCCs Module 3 onward A DPA drafted by the customer, and proof you can support their data subject requests
SaaS with an EU subsidiary, office or employees handling the product Controller or processor, depending on the data Directly, under Article 3(1), for processing in the context of that establishment Intra-group transfer mechanism, usually SCCs Everything above, plus local supervisory authority engagement
Every case above, for your sub-processors You are the controller or processor passing data on Your DPA makes you liable for them under Article 28(4) Each sub-processor needs its own DPF certification, SCCs or adequacy route Advance notice of new sub-processors and a right to object, per Article 28(2)

Good questions

Questions about GDPR for SaaS

Yes, in two ways. If you offer your product to people in the EU, GDPR applies to you directly under Article 3(2) for the data you control. If you process personal data for EU business customers, GDPR reaches you through the Article 28 data processing agreement and the transfer terms, even with no EU office. Most US B2B SaaS companies are in both positions.
Usually both. You are a processor for the personal data your customers put into the product, because you act on their instructions. You are a controller for your own account, billing, support and marketing data. The processor role drives your DPA and sub-processor duties; the controller role drives your privacy notice, lawful basis and data subject request handling.
Yes, if you process personal data for EU customers. Article 28 requires a contract between the customer and you as processor that sets out processing instructions, confidentiality, security, sub-processor rules, assistance with data subject requests and breaches, deletion or return at the end, and audit rights. Most SaaS companies publish a standard DPA and let customers sign it online.
Often, yes. Article 27 requires a controller or processor not established in the EU that falls under Article 3(2) to appoint a representative in the EU in writing. The exemption covers only occasional processing that does not include special categories of data at large scale and is unlikely to result in a risk. A SaaS product that serves EU users continuously rarely qualifies.
For transfers to you, yes, if you are self-certified and your certification covers the relevant data. It is not enough for your onward transfers: each sub-processor needs its own lawful route. The DPF must be recertified every year. The EU General Court upheld it on 3 September 2025, but an appeal is possible, so many SaaS DPAs keep Standard Contractual Clauses as a fallback.
Article 33(2) requires a processor to notify the controller without undue delay after becoming aware of a personal data breach. It sets no hour count for processors. The controller then has 72 hours to notify the supervisory authority, so enterprise DPAs often commit processors to 24 or 48 hours to leave customers time to meet their own deadline.
Processor obligations under Articles 28 to 39, including security and breach duties, carry fines of up to 10 million euros or 2 percent of worldwide annual turnover, whichever is higher. Breaches of the core principles, data subject rights or transfer rules carry up to 20 million euros or 4 percent. For most SaaS companies the faster cost is lost EU deals when a DPA review fails.
No. SOC 2 evidences security controls, which covers much of Article 32, but GDPR also requires lawful bases, data subject rights, records of processing, sub-processor authorization and a transfer mechanism. A SOC 2 report is still useful in an EU deal, because it answers the security half of the review. Scrutineer maps the overlap so the shared controls are built once.
No software does that on its own, and no certificate proves it. Scrutineer is compliance software: it maps GDPR processor and controller obligations to your controls, collects evidence from your systems, tracks sub-processors and transfer mechanisms, and answers customer questionnaires from that evidence. Your counsel still owns your DPA wording and lawful basis decisions.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification