GDPR & SaaS: A Compliance Checklist for 2026
Every SaaS tool you sign up for is a place your customers' and employees' personal data ends up living. Under the UK GDPR, you stay responsible for that data even when a supplier holds it — which makes GDPR SaaS due diligence one of the quiet essentials of buying software. This checklist walks through what to verify before you commit.
Why GDPR matters when you buy SaaS
When you adopt a SaaS product that touches personal data, you are almost always the data controller and the vendor is a data processor acting on your instructions. That relationship carries specific obligations under the UK GDPR and the Data Protection Act 2018, and — crucially — you cannot outsource accountability. If a supplier mishandles data you entrusted to them, the responsibility to your customers and to the Information Commissioner's Office (ICO) still rests with you.
This is why the moment a GDPR SaaS decision arises, the buying conversation should include more than features and price. A tool with brilliant functionality but a vague privacy posture can expose you to complaints, reputational harm and regulatory scrutiny. The good news is that the checks are largely repeatable: once you know what to look for, you can run the same review across every new subscription.
The principle underneath all of it is data protection by design and by default. In practice that means choosing suppliers who make the safe path the easy path — sensible defaults, clear documentation and a willingness to answer hard questions — rather than ones who treat compliance as an afterthought.
The GDPR SaaS compliance checklist
Work through each item below before signing. Treat any gap as a question to resolve, not necessarily a deal-breaker — but do document the answers.
- Data Processing Agreement (DPA). A written DPA (or equivalent contract terms) is generally required between a controller and a processor under Article 28 of the UK GDPR. Confirm the vendor offers one, that it is available to your business, and that it sets out the subject matter, duration, nature and purpose of processing.
- Lawful basis. You need a lawful basis for the processing the tool enables — commonly consent, contract or legitimate interests, depending on the use case. The vendor cannot choose this for you; make sure your own basis is clear and that the tool supports it (for example, honouring consent withdrawals).
- Data location & transfers. Ask where data is stored and processed. If personal data leaves the UK, you need to know so you can assess whether a valid transfer mechanism applies (see the UK GDPR section below).
- Sub-processors. Most SaaS vendors rely on other providers — hosting, analytics, support tooling. Ask for the list of sub-processors, how you are notified of changes, and whether you can object. A transparent, published sub-processor list is a good sign.
- Security measures. The UK GDPR requires appropriate technical and organisational measures. Look for encryption in transit and at rest, access controls, and recognised assurance such as ISO 27001 certification or a SOC 2 report. These are indicators, not guarantees — read what they actually cover.
- Data subject requests. Individuals have rights — access, rectification, erasure, portability and others. Check that the tool lets you locate, export and delete an individual's data so you can meet these requests within the statutory timeframe.
- Retention & deletion. Confirm how long data is kept, whether you can configure retention, and what happens when you close the account. You should be able to retrieve your data and have it deleted rather than left indefinitely on the vendor's systems.
- Breach notification. Processors must notify controllers of a personal data breach without undue delay. Check the contract commits the vendor to prompt notification and gives you enough information to meet your own reporting duties to the ICO and, where required, to affected individuals.
UK GDPR nuances after Brexit
Since the end of the Brexit transition period, the UK has its own version of the regime — the UK GDPR, sitting alongside the Data Protection Act 2018 and overseen by the ICO. For most day-to-day purposes it closely mirrors the EU GDPR, but the two are now separate legal frameworks, and a business serving customers on both sides may need to consider each.
The area that most often needs care with SaaS is international transfers. If your chosen tool stores or accesses personal data outside the UK, you generally need a lawful transfer mechanism. Where the destination country benefits from UK "adequacy", transfers can proceed on that basis. Where it does not, businesses commonly rely on contractual safeguards — historically the EU Standard Contractual Clauses (SCCs), and in the UK context the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs.
The Schrems II ruling reinforced that signing transfer clauses is not always enough on its own: organisations may need to assess whether the destination offers a genuinely equivalent level of protection and consider supplementary measures. This is one of the areas where the framing gets genuinely complex, and where the specifics of your data and destination matter a great deal — so treat vendor assurances as a starting point and seek professional input where transfers are significant. The ICO publishes practical guidance and tools to help with these assessments.
Questions to ask a SaaS vendor
You do not need to be a lawyer to run a solid first-pass review. A short, direct set of questions surfaces most of what matters:
- Will you sign a Data Processing Agreement, and can I see it before I commit?
- Where is my data stored and processed, and does any of it leave the UK?
- If data is transferred internationally, what mechanism do you rely on — adequacy, SCCs, the IDTA or the UK Addendum?
- Who are your sub-processors, and how will you tell me when that list changes?
- What security measures and certifications (for example ISO 27001 or SOC 2) do you hold?
- How do you help me respond to data subject access, deletion and portability requests?
- What are your retention periods, and what happens to my data when I leave?
- How and how quickly will you notify me of a personal data breach?
Vague or evasive answers are themselves informative. A vendor that handles these calmly and in writing is demonstrating the kind of maturity you want in a data processor. Security is rarely one product, either — the same discipline you apply to SaaS should extend across your stack, from your business antivirus to the business management software that sits at the centre of your operations.
Getting help
GDPR SaaS reviews are repeatable, but the contract terms and transfer questions can get thorny fast — particularly for regulated sectors or high-volume, cross-border processing. If you are weighing several tools and want a second pair of eyes on the data protection clauses before you sign, it is worth getting a structured review rather than trusting a marketing page.
Get help reviewing SaaS contracts
Share the tools you are considering and we will help you check the DPA, transfer terms and security posture — free, no obligation.
▸ Request a reviewIs a Data Processing Agreement always required for SaaS?
Where a SaaS vendor processes personal data on your behalf, the UK GDPR generally requires a written contract with specific terms — commonly provided as a DPA. If a supplier cannot offer one, that is a significant gap worth resolving before you proceed.
Does UK GDPR still apply if my vendor is based in the EU or US?
Yes. Your obligations as a controller follow the personal data, not the vendor's location. Using an overseas provider typically raises international transfer questions, which is exactly why data location and transfer mechanisms are on the checklist.
What is the difference between SCCs and the IDTA?
Both are contractual tools for safeguarding international transfers. The Standard Contractual Clauses originate in the EU framework, while the International Data Transfer Agreement (and the UK Addendum to the EU SCCs) are the UK's mechanisms. Which applies depends on your circumstances.
Who is responsible if my SaaS vendor has a data breach?
As controller you retain accountability to the individuals affected and to the ICO, even though the processor must notify you and assist. This is why breach-notification terms and prompt communication are so important to confirm up front.