Scrutineer · By framework
GDPR compliance for SaaS companies with EU customers
An EU customer's privacy review asks three things of a US SaaS vendor: your DPA, your sub-processor list and how the data legally gets to the US. Missing any one stalls the deal.
Scrutineer maps your GDPR processor and controller duties to the controls you already run for SOC 2, tracks each sub-processor and its transfer route, and keeps the evidence current. Compliance software, not legal advice.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with GDPR for SaaS
A SaaS company is two things under GDPR at once
For the data your customers load into the product, you are almost always a processor acting on their instructions. For your own account, billing, marketing and product analytics data, you are a controller. Most GDPR for SaaS guides describe only one of these roles. The processor side is what EU customers audit through your DPA, your sub-processor list and your security questionnaire. The controller side is what brings you directly under Article 3(2) the moment you offer the product to people in the EU, which usually means a privacy notice, a lawful basis for each purpose, a way to handle access and deletion requests and, unless your processing is occasional, an EU representative under Article 27. Map both roles to controls, because a single mistake in one does not show up in the other.
GDPR follows the person in the EU, not the passport
GDPR protects people who are in the Union, whatever their nationality. An EU citizen using your product from Texas is generally outside Article 3(2); a US citizen signing up from Paris is inside it. For a processor, the EDPB is explicit in Guidelines 3/2018: a processor not established in the EU is not made subject to GDPR just because it serves an EU controller. GDPR reaches it through the Article 28 contract and the transfer terms instead. That is why, for most US B2B SaaS companies, the DPA is not paperwork around GDPR compliance. It is the GDPR compliance, and every clause in it is an obligation you have to evidence.
Your transfer mechanism covers you, not your sub-processors
Self-certifying to the EU-US Data Privacy Framework lets an EU customer transfer personal data to you without Standard Contractual Clauses. It says nothing about where you send the data next. Each sub-processor that receives that data needs its own lawful route, whether its own DPF certification, SCCs or an adequacy decision, and your DPA usually promises the customer you have checked. The DPF also has to be recertified every year, and a lapsed certification quietly breaks the promise in every contract that relies on it. The General Court upheld the DPF in Latombe v Commission on 3 September 2025, and that judgment can be appealed, so most SaaS DPAs keep SCCs as a fallback.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps your GDPR processor obligations under Article 28 (instructions, confidentiality, security, sub-processors, assistance, deletion, audits) to the controls you already run for SOC 2 and ISO 27001
- Keeps the sub-processor register behind your public list: what each one receives, where it processes, and which transfer mechanism covers it
- Tracks your own EU-US Data Privacy Framework recertification date and each sub-processor's DPF status, so a lapse is flagged before a customer finds it
- Evidences Article 32 security measures from live systems (access reviews, encryption settings, logging, backups) instead of a policy PDF
- Runs a processor incident workflow that notifies the affected customer without undue delay, so they can meet their own 72-hour clock under Article 33
- Drafts answers to EU customers' GDPR and security questionnaires from the same mapped controls and evidence
- Holds your records of processing activities as a processor under Article 30(2), per customer category and per sub-processor
- Adds SOC 2, ISO 27001, HIPAA and PCI DSS on the same control library when the next customer segment asks
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Scoping GDPR for a SaaS company
How GDPR reaches a US SaaS company, by situation
Most GDPR for SaaS guides say the law applies to anyone handling EU citizens' data. That is wrong twice: it follows people in the EU, not citizens, and it reaches a non-EU processor through its contracts rather than directly. Your situation decides your role, your transfer mechanism and what a customer will ask for.
| Your situation | Your GDPR role | How GDPR reaches you | Transfer mechanism you need | What EU customers ask for |
|---|---|---|---|---|
| US SaaS selling to EU businesses, no EU office | Processor for customer data, controller for your own account data | Through the Article 28 DPA and transfer terms for customer data (EDPB Guidelines 3/2018), and directly under Article 3(2) for account and marketing data | DPF self-certification or SCCs Module 2 from each customer to you | DPA, sub-processor list, security measures annex, breach notice terms, SOC 2 or ISO 27001 report |
| US SaaS with self-serve signups from individuals in the EU | Controller | Directly, under Article 3(2)(a), because you offer the service to people in the Union | None for data you collect directly; SCCs or DPF for onward transfers to your vendors | Privacy notice, lawful basis per purpose, access and deletion handling, Article 27 EU representative unless processing is occasional |
| US SaaS serving US customers who upload data about people in the EU | Processor for a controller that may itself be under Article 3(2) | Through your customer's DPA, which passes GDPR terms down to you | Whatever your customer's contract requires, often SCCs Module 3 onward | A DPA drafted by the customer, and proof you can support their data subject requests |
| SaaS with an EU subsidiary, office or employees handling the product | Controller or processor, depending on the data | Directly, under Article 3(1), for processing in the context of that establishment | Intra-group transfer mechanism, usually SCCs | Everything above, plus local supervisory authority engagement |
| Every case above, for your sub-processors | You are the controller or processor passing data on | Your DPA makes you liable for them under Article 28(4) | Each sub-processor needs its own DPF certification, SCCs or adequacy route | Advance notice of new sub-processors and a right to object, per Article 28(2) |
Good questions
Questions about GDPR for SaaS
Keep reading
Guides that go deeper on this framework
GDPR compliance checklist for US companies
The obligations a US company carries, in the order an EU customer checks them.
Read the guideBest data privacy management software
How privacy platforms differ from compliance automation, and when you need both.
Read the guideISO 27001 vs SOC 2
Which security report EU buyers expect from a US SaaS vendor.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification