GDPR for a software company: what customers will ask for
The GDPR — Regulation (EU) 2016/679 — applies to every company processing the personal data of people in the EU, from a two-person SaaS to a bank. For a software vendor the practical obligations are a legal basis and a privacy notice for your own processing (Art. 6, 13–14), a record of processing activities (Art. 30), security measures (Art. 32), breach handling (Art. 33–34) and — where you process on behalf of customers — an Art. 28 data processing agreement.
Applies to
Controllers and processors established in the EU, and companies outside the EU offering goods or services to people in the EU or monitoring them (Art. 3). No size threshold.
Controller and processor
For your own users and staff you are a controller. For the data your customers put into your product you are usually a processor — with the obligations in Art. 28.
Accountability, not box-ticking
Art. 5(2): you have to be able to demonstrate compliance. The documents are that demonstration.
Enforced in Poland by the UODO
The President of the Personal Data Protection Office can inspect, order and fine — up to €20m or 4% of turnover (Art. 83).
The documents a software company actually needs
| Document | Article | Who asks for it |
|---|---|---|
| Privacy policy / notice for users and visitors | Art. 13–14 | Every user; the supervisory authority |
| Record of processing activities (RoPA) | Art. 30 | The authority during an inspection; enterprise customers |
| Data processing agreement template | Art. 28(3) | Every customer whose data you process |
| Sub-processor list and notification process | Art. 28(2) and (4) | Customers, before signing |
| Description of technical and organisational measures (TOMs) | Art. 32 | Customers; an annex to the DPA |
| Breach procedure and breach register | Art. 33–34 | The authority within 72 h of becoming aware; customers under the DPA |
| Procedure for handling data subject requests | Art. 12–22 | Users; customers relying on your assistance |
| Transfer assessment, if data leaves the EEA | Art. 44–49 | Customers; the authority |
| Data protection impact assessment, where required | Art. 35 | The authority; large customers |
| Employee privacy notice and internal policy | Art. 13, 88 | Employees; the labour inspectorate |
What the customer questionnaire is testing
A GDPR questionnaire from a bank or an insurer is, at heart, an Art. 28 check: does this processor provide sufficient guarantees? They will ask where you store data, who your sub-processors are, how you secure the data, how fast you report a breach, how you help with data subject requests and what happens to the data when the contract ends. Each question maps to a document in the table above. Audomate audits your existing documents against those articles, drafts the missing ones and answers the questionnaire with citations — see pass vendor due diligence.
Saying “GDPR compliant” in public
You can say it if it is true and verifiable; you cannot imply an Art. 42 certification you do not hold, or approval by a supervisory authority. The verified mark gives you a dated statement with a scope and a public evidence page.
Book an audit demoThe GDPR framework is in preparation; today we can show the audit on DORA or on a questionnaire from your customer.
Questions we get most often
Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.
Find out where you stand in four weeks
Pick this regulation for a 4-week pilot. Your documents, a cited gap list, remediation drafts — and a verified mark if you pass.