Summary
Sometimes two organizations jointly determine the purposes of processing. This requires a specific legal arrangement between both parties. 6. Legitimate interests — Your business interest outweighs the individual’s privacy rights (requires a balancing test) For most software companies, the primary bases are contract (for delivering your service), consent (for marketing emails or non-essential cookies), and legitimate interests (for fraud prevention or analytics).
GDPR Step by Step for Software Companies: A Practical Compliance Guide
If you run a software company that serves customers in the European Union, GDPR compliance isn’t optional — it’s a legal requirement. The General Data Protection Regulation affects every SaaS platform, app developer, and software vendor that processes personal data belonging to EU residents, regardless of where your company is headquartered.
This guide walks you through GDPR compliance step by step, in plain language, so you can build a solid foundation without getting lost in legal jargon.
Step 1: Understand Whether GDPR Applies to Your Software Company
Before doing anything else, confirm your obligations. GDPR applies to your company if:
- You have customers or users located in the EU or EEA
- You process personal data on behalf of EU-based clients (acting as a data processor)
- You collect behavioral data, analytics, or cookies from EU website visitors
- You offer goods or services to EU residents, even if your company is based in the US, UK, or elsewhere
Personal data includes names, email addresses, IP addresses, device identifiers, location data, and any information that can identify a living individual. For software companies, this almost always applies.
Step 2: Determine Your Role — Controller or Processor
This distinction shapes your entire compliance strategy.
Data Controller
You decide why and how personal data is processed. If you collect user data directly through your platform, you’re a controller. Controllers carry the heaviest compliance burden.
Data Processor
You process data on behalf of another organization (the controller). Many B2B SaaS companies act as processors for their clients. Processors must sign Data Processing Agreements (DPAs) with each controller they work with.
Joint Controllers
Sometimes two organizations jointly determine the purposes of processing. This requires a specific legal arrangement between both parties.
Identifying your role correctly determines which GDPR obligations apply to you — so get this right early.
Step 3: Conduct a Data Mapping Exercise
You cannot protect data you don’t know exists. A data mapping (or data inventory) exercise documents:
- What personal data you collect (names, emails, payment info, usage logs)
- Where it comes from (sign-up forms, third-party integrations, cookies)
- Where it’s stored (your servers, cloud providers like AWS or Azure, third-party tools)
- Who has access (internal teams, contractors, sub-processors)
- How long you keep it (retention periods)
- Where it flows (especially cross-border transfers outside the EU)
Create a Record of Processing Activities (RoPA) — this is a formal requirement under Article 30 of GDPR for most organizations. Keep it updated as your product evolves.
Step 4: Establish a Lawful Basis for Each Processing Activity
Every time you process personal data, you need a legal justification. GDPR provides six lawful bases:
- Consent — The user has freely given, specific, informed, and unambiguous agreement
- Contract — Processing is necessary to fulfill a contract with the user
- Legal obligation — You’re required to process data by law
- Vital interests — Necessary to protect someone’s life
- Public task — Processing carried out in the public interest
- Legitimate interests — Your business interest outweighs the individual’s privacy rights (requires a balancing test)
For most software companies, the primary bases are contract (for delivering your service), consent (for marketing emails or non-essential cookies), and legitimate interests (for fraud prevention or analytics).
Document your chosen lawful basis for every processing activity in your RoPA.
Step 5: Update Your Privacy Policy and Legal Documents
Your privacy policy must be clear, concise, and comprehensive. Under GDPR, it needs to include:
- Who you are and how to contact you
- What data you collect and why
- The lawful basis for each processing activity
- How long you retain data
- Who you share data with (third parties, sub-processors)
- Users’ rights and how to exercise them
- Details of any international data transfers
- Cookie policy information
Beyond the privacy policy, software companies typically need:
- Terms of Service aligned with GDPR obligations
- Cookie consent banners that meet the “freely given” standard
- Data Processing Agreements (DPAs) for B2B relationships
- Data Retention Policy
- Data Breach Response Plan
Step 6: Implement Data Subject Rights Processes
GDPR grants individuals eight key rights. Your software must support them:
- Right to access — Users can request a copy of their data
- Right to rectification — Users can correct inaccurate data
- Right to erasure (“right to be forgotten”) — Users can request deletion
- Right to restriction — Users can limit how you process their data Right to data portability — Users can receive their data in a machine-readable format
- Right to object — Users can object to certain types of processing
- Rights related to automated decision-making — Protections against purely automated decisions with significant effects
You must respond to most requests within 30 days. Build internal workflows and, where possible, self-service tools within your product to handle these efficiently.
Step 7: Review Your Third-Party Sub-Processors
Software companies typically rely on dozens of third-party tools — cloud hosting, analytics platforms, email providers, payment processors, customer support tools. Each one that touches personal data is a sub-processor.
Your responsibilities:
- Maintain an up-to-date list of sub-processors
- Ensure each sub-processor has adequate GDPR protections in place
- Include sub-processor clauses in your DPAs with clients
- Notify clients when you add or change sub-processors
Review the privacy documentation and DPAs of every tool in your tech stack, including AWS, Google Workspace, Stripe, Intercom, HubSpot, and others.
Step 8: Address International Data Transfers
If you transfer personal data outside the EU/EEA — for example, to US-based servers or service providers — you need a legal transfer mechanism:
- Standard Contractual Clauses (SCCs) — The most common mechanism; updated versions were released in 2021
- Adequacy decisions — Transfers to countries the EU has deemed adequate (e.g., UK, Switzerland, Japan)
- Binding Corporate Rules (BCRs) — For multinational companies transferring data within their own group
The US-EU Data Privacy Framework (DPF) also provides a transfer mechanism for certified US companies. Check whether your key vendors are DPF-certified.
Step 9: Implement Security Measures
GDPR requires “appropriate technical and organizational measures” to protect personal data. For software companies, this includes:
- Encryption at rest and in transit
- Access controls and role-based permissions
- Regular security testing and vulnerability assessments
- Employee training on data protection
- Incident response procedures for data breaches
- Data minimization — only collect what you genuinely need
If you experience a data breach, you must notify your supervisory authority within 72 hours and affected individuals without undue delay if the breach poses a high risk to them.
Step 10: Appoint a Data Protection Officer (If Required)
You must appoint a DPO if:
- You’re a public authority
- You carry out large-scale, systematic monitoring of individuals
- You process special category data (health, biometric, religious beliefs, etc.) on a large scale
Many SaaS companies don’t require a formal DPO, but appointing one voluntarily — or designating a privacy lead internally — is considered best practice.
Ongoing Compliance: GDPR Is Not a One-Time Project
GDPR compliance requires continuous maintenance. Build these habits into your operations:
- Review and update your RoPA quarterly
- Conduct Data Protection Impact Assessments (DPIAs) before launching high-risk features
- Train new employees on data protection principles
- Audit your sub-processors annually
- Monitor regulatory guidance from your local supervisory authority
Frequently Asked Questions
Does GDPR apply to my US-based software company?
Yes, if you have EU users or customers. GDPR has extraterritorial reach. If you collect data from EU residents, you must comply — regardless of where your servers or offices are located.
What’s the difference between a DPA and a privacy policy?
A privacy policy is a public-facing document explaining how you handle personal data. A Data Processing Agreement is a contract between a data controller and a data processor, outlining each party’s responsibilities. B2B SaaS companies typically need both.
How much can we be fined for GDPR violations?
Fines can reach up to €20 million or 4% of global annual turnover, whichever is higher. Smaller violations carry fines up to €10 million or 2% of turnover. Regulators also issue warnings, reprimands, and processing bans.
Do we need consent for every type of data processing?
No. Consent is just one of six lawful bases. Many software companies rely on contract performance or legitimate interests for core processing activities. However, consent is generally required for marketing communications and non-essential cookies.
What is a DPIA and when do we need one?
A Data Protection Impact Assessment is a structured risk assessment for high-risk processing activities — such as large-scale profiling, processing sensitive data, or using new technologies. It’s mandatory in certain scenarios and strongly recommended before launching major new features.
Start Your GDPR Compliance Journey with Ready-to-Use Templates
Working through GDPR compliance from scratch is time-consuming and easy to get wrong. Our professionally drafted GDPR compliance template bundle gives software companies everything they need to get compliant faster:
- ✅ Privacy Policy Template (SaaS-ready)
- ✅ Data Processing Agreement (DPA) Template
- ✅ Record of Processing Activities (RoPA) Template
- ✅ Data Breach Response Plan
- ✅ Data Retention Policy
- ✅ DPIA Template
- ✅ Cookie Consent Policy
Stop starting from a blank page. Our templates are written by compliance professionals, ready to customize, and trusted by software companies at every stage of growth.
Best for teams organizing privacy documentation and operating guidance.