GDPR Compliance: DPA, DPIA, Legal Basis, and the Rights

The General Data Protection Regulation governs how any company processes personal data of people in the EU/UK.

GDPR Compliance: The Regulation That Ended Casual Data Collection

The General Data Protection Regulation (GDPR) is the EU privacy law that took effect in 2018, replacing a patchwork of national laws with unified rules for how companies process personal data of EU/UK residents. GDPR applies regardless of your company's location — if you have EU users, you must comply. Penalties reach 4% of global revenue for serious violations, and enforcement has become more aggressive over time. Compliance is a mix of paperwork (DPAs, privacy notices, records of processing), engineering (data subject rights, retention, security controls), and operations (breach notification, DPO if required).

The concepts that actually matter

Personal data — any information relating to an identifiable person, defined broadly (email, IP, device ID, behavioral patterns). Controller vs. processor — the controller decides why and how data is processed (your company); processors act on the controller's instructions (your vendors). Legal basis — every processing purpose needs one of six bases (consent, contract, legal obligation, vital interests, public interest, legitimate interest); the default 'consent' is often the wrong choice for B2B SaaS where 'contract' or 'legitimate interest' fits better. Special category data (health, biometric, ethnicity) has stricter rules and mostly requires explicit consent.

Paperwork you actually need

(1) Privacy notice — public-facing, explains what data you collect, why, legal basis, retention, rights. Update when you change processing. (2) Data Processing Agreement (DPA) — signed with every processor (vendor). Standard templates exist; most vendors have their own. (3) Records of Processing Activities (Article 30) — internal register of every processing purpose with categories of data, recipients, and retention. Required if you have 250+ employees or high-risk processing. (4) DPIA (Data Protection Impact Assessment) — required for high-risk processing (large-scale profiling, biometric, systematic monitoring). Skip only if none of your processing is high-risk.

Data subject rights

EU users have the right to: access their data, correct it, delete it (right to be forgotten), export it (data portability), object to processing, restrict processing, and not be subject to solely automated decisions. Requests must be handled within one month. Build an internal process — a form or email address (privacy@) monitored, an SLA'd handoff to engineering, and reproducible steps for each right. Manual scramble on the first request doesn't scale and blows the deadline. Deletion needs to cascade through backups, warehouses, and third-party processors; document the actual coverage rather than claiming full deletion.

International transfers

Transferring EU personal data outside the EU requires safeguards. Since Schrems II (2020), transfers to the US require Standard Contractual Clauses (SCCs) plus transfer impact assessments. The EU-US Data Privacy Framework (2023) simplifies this for participating US companies. Most cloud vendors (AWS, GCP, Azure, Cloudflare) support EU-region hosting; using EU regions for EU customer data is often the simplest path. Sub-processor lists must be public and customers must be able to object to new sub-processors.

Breach notification

Personal data breaches must be reported to your lead supervisory authority within 72 hours if the breach is likely to result in risk to individuals. If the risk is high, affected individuals must also be notified. 'Breach' includes loss of confidentiality (leaked data) and loss of availability (lost/unrecoverable data). Have an incident response playbook that includes the privacy team, legal counsel, and pre-drafted notification templates. Missing the 72-hour deadline is one of the more penalized GDPR violations.

Frequently asked questions

Do we need a Data Protection Officer (DPO)?
Required if your core activities involve large-scale systematic monitoring or large-scale processing of special category data. Most B2B SaaS don't need one. Consumer products, adtech, and health apps usually do. Even when not required, having a designated privacy lead is good practice.
Does GDPR apply to B2B SaaS?
Yes — B2B doesn't mean no personal data. Employee names, emails, and behavior data at your customers' companies are personal data. B2B just means the legal basis is often 'contract' or 'legitimate interest' rather than 'consent.'
What about the UK, California, and other jurisdictions?
UK GDPR is nearly identical to EU GDPR post-Brexit. California's CCPA/CPRA has similar concepts with different mechanics; Brazil's LGPD, Canada's PIPEDA, and others are converging on similar principles. Design your privacy program to satisfy GDPR + CCPA and you'll cover most of the world without per-jurisdiction reworks.

Related fundraising guides (40)

Investor directory · Fundraising library · Articles A–Z · Company funding database