GDPR for SaaS: lawful basis and data mapping done properly
7 min read · Certifyi research team · Updated July 2026
GDPR compliance starts with knowing what personal data you hold and why you are allowed to hold it. Those two artefacts, a data map and a documented lawful basis per processing purpose, underpin every other obligation, and they are where most programmes are weakest.
Controller or processor?
For most B2B SaaS you are a processor for customer data and a controller for your own marketing, HR and account data. Obligations differ, and conflating the two produces a privacy notice that does not survive scrutiny.
The six lawful bases
You need one per processing purpose, recorded before processing begins.
| Basis | Typical SaaS use |
|---|---|
| Contract | Delivering the service a customer signed up for |
| Legitimate interests | Product analytics, security monitoring, some B2B marketing |
| Consent | Marketing cookies and optional communications |
| Legal obligation | Retaining financial records |
| Vital interests | Rare in SaaS |
| Public task | Rare outside public bodies |
The consent trap
- Consent must be freely given, specific, informed and withdrawable.
- If you cannot honour withdrawal without breaking the service, consent was the wrong basis.
- Legitimate interests requires a documented balancing test, not just an assertion.
Building a data map that is useful
A data map exists to answer regulator and customer questions quickly. Structure it around flows, not systems.
- What personal data is collected, and which categories are special
- Where it enters, where it is stored, and where it leaves
- Which third parties receive it and under what agreement
- Retention period and deletion mechanism
- Legal basis and purpose for each flow
- Whether it leaves the UK or EEA, and under what transfer mechanism
Record of Processing Activities
Article 30 requires a ROPA for most organisations. Its absence is one of the fastest ways to signal an immature programme during a regulator interaction or an enterprise privacy review. It is largely derivable from a good data map.
What buyers ask for
Enterprise privacy reviews rarely ask "are you GDPR compliant". They ask for your ROPA, your DPA, your subprocessor list, your retention schedule, and evidence you can service a data subject request within a month. Prepare those five artefacts and most reviews go smoothly.
Key takeaways
- Establish controller versus processor role per data set.
- Document a lawful basis per purpose before processing.
- Map flows, not just systems.
- A ROPA is expected and largely falls out of a good data map.
Frequently asked questions
Do we need a DPO?
Only if you are a public authority, or your core activities involve large-scale systematic monitoring or large-scale special-category processing. Many SaaS companies do not, but should still name a privacy owner.
Is legitimate interests risky?
It is legitimate and widely used, but it requires a documented balancing test weighing your interest against individual rights. Undocumented, it is indefensible.
How long do we have to answer a data subject request?
One month, extendable by two further months for complex requests, provided you inform the person within the first month.
Does GDPR apply if we are not in Europe?
Yes, if you offer goods or services to people in the EU or monitor their behaviour there.
Related reading
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.
Book a 20-min deal readiness call