Legal

GDPR Compliance Requirements for US-Based SaaS Companies

A practical GDPR checklist for U.S. SaaS companies covering scope, controller/processor roles, contracts, security, transfers, rights requests and breach response.

✓ Practical checklist✓ Primary sources where available✓ No signup✓ Clear limitations
Decision framework

What this guide helps you evaluate

U.S.-based SaaS companies that offer services to people or organizations in the EEA or otherwise fall within GDPR scope.

This page is designed to help you compare the moving parts, organize due diligence and ask better questions before you commit money, sign a contract or change an operating process.

What to compare first

  • Controller, processor and sub-processor roles
  • Lawful basis, transparency and data minimization
  • Article 28 processing agreements
  • International transfer mechanism and vendor chain
  • Data-subject rights, security, retention and breach response

Step-by-step process

  1. 01

    Map personal data, purposes, systems, vendors and geographic transfers.

  2. 02

    Determine role and lawful basis for each material processing activity.

  3. 03

    Put processor contracts and sub-processor controls in place.

  4. 04

    Create workflows for access, deletion and other rights requests.

  5. 05

    Test incident response, including the information needed for breach assessment and notification.

Common mistakes and risk checks

  • Assuming a U.S. company is outside GDPR automatically.
  • Copying a privacy notice without matching actual processing.
  • Ignoring sub-processors and international transfers.

Primary and official references

Rules, pricing and requirements can change. Use these sources to verify the latest details that apply to your situation.