Get Demo
↑

GDPR for SaaS Companies: Processor Obligations and Sub-Processor Lists

SaaS vendors are often processors under Article 28 — DPAs, sub-processor transparency, assistance with rights, and security under Article 32.

Published: September 2026 Compliance · GDPR 8–12 min read

Most B2B SaaS companies act as processors (and sometimes dual controllers for their own marketing/HR data). Article 28 obligations, sub-processor lists, and Article 32 security dominate enterprise security questionnaires.

Related: GDPR hub · DPA template · CyberSilo DPA.

Processor basics: process only on documented instructions; flow down obligations to sub-processors; assist with DSARs, DPIAs, and breaches; delete/return data at end of service.

Controller vs Processor in SaaS

Sub-Processor Lists

Publish a current list (hosting, email, support tools, AI subprocessors). Article 28 requires prior authorisation patterns and equivalent contractual obligations. Give customers a change-notice mechanism.

How CyberSilo Helps

Make Enterprise DPAs Easy to Win

Ship a solid Art 28 pack, sub-processor transparency, and continuous security evidence.

Frequently Asked Questions

Is every SaaS a processor?

For customer-uploaded personal data, usually yes. Marketing analytics on your own site is typically controller processing.

Do I need SCCs if I host in the EU only?

Maybe not for storage — but support tools, subprocessors, or admin access from third countries can still create transfers.

What do enterprise buyers ask first?

DPA, sub-processor list, transfer mechanism, breach SLA, and SOC 2/ISO evidence alongside GDPR answers.

GDPR hub · DPA · Transfers · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!