Regulation · GDPR

GDPR for a software company: what customers will ask for

The GDPR — Regulation (EU) 2016/679 — applies to every company processing the personal data of people in the EU, from a two-person SaaS to a bank. For a software vendor the practical obligations are a legal basis and a privacy notice for your own processing (Art. 6, 13–14), a record of processing activities (Art. 30), security measures (Art. 32), breach handling (Art. 33–34) and — where you process on behalf of customers — an Art. 28 data processing agreement.

01

Applies to

Controllers and processors established in the EU, and companies outside the EU offering goods or services to people in the EU or monitoring them (Art. 3). No size threshold.

02

Controller and processor

For your own users and staff you are a controller. For the data your customers put into your product you are usually a processor — with the obligations in Art. 28.

03

Accountability, not box-ticking

Art. 5(2): you have to be able to demonstrate compliance. The documents are that demonstration.

04

Enforced in Poland by the UODO

The President of the Personal Data Protection Office can inspect, order and fine — up to €20m or 4% of turnover (Art. 83).

The documents a software company actually needs

DocumentArticleWho asks for it
Privacy policy / notice for users and visitorsArt. 13–14Every user; the supervisory authority
Record of processing activities (RoPA)Art. 30The authority during an inspection; enterprise customers
Data processing agreement templateArt. 28(3)Every customer whose data you process
Sub-processor list and notification processArt. 28(2) and (4)Customers, before signing
Description of technical and organisational measures (TOMs)Art. 32Customers; an annex to the DPA
Breach procedure and breach registerArt. 33–34The authority within 72 h of becoming aware; customers under the DPA
Procedure for handling data subject requestsArt. 12–22Users; customers relying on your assistance
Transfer assessment, if data leaves the EEAArt. 44–49Customers; the authority
Data protection impact assessment, where requiredArt. 35The authority; large customers
Employee privacy notice and internal policyArt. 13, 88Employees; the labour inspectorate

What the customer questionnaire is testing

A GDPR questionnaire from a bank or an insurer is, at heart, an Art. 28 check: does this processor provide sufficient guarantees? They will ask where you store data, who your sub-processors are, how you secure the data, how fast you report a breach, how you help with data subject requests and what happens to the data when the contract ends. Each question maps to a document in the table above. Audomate audits your existing documents against those articles, drafts the missing ones and answers the questionnaire with citations — see pass vendor due diligence.

Saying “GDPR compliant” in public

You can say it if it is true and verifiable; you cannot imply an Art. 42 certification you do not hold, or approval by a supervisory authority. The verified mark gives you a dated statement with a scope and a public evidence page.

Book an audit demoThe GDPR framework is in preparation; today we can show the audit on DORA or on a questionnaire from your customer.

Questions we get most often

Art. 30(5) exempts organisations under 250 employees only where the processing is occasional, involves no special categories and poses no risk to rights and freedoms. A software company processing user data continuously does not meet that exemption in practice.
Only where Art. 37 applies: a public authority, core activities consisting of large-scale regular and systematic monitoring, or large-scale processing of special categories. Most small SaaS companies do not have to appoint one, but should name a privacy contact.
If personal data is accessible from outside the EEA — including through a support or analytics tool — it is a transfer under Chapter V and needs a basis (an adequacy decision, standard contractual clauses with a transfer assessment, and so on). It is one of the most common gaps an audit finds.

Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.

Find out where you stand in four weeks

Pick this regulation for a 4-week pilot. Your documents, a cited gap list, remediation drafts — and a verified mark if you pass.