Seven GDPR questions to ask any SaaS vendor
"GDPR compliant" is a marketing sentence, not a fact you can rely on. These seven questions turn it into something you can check — and the answers tell you as much about the vendor as about the law.
By SoftSelect Editorial4 min read
Every vendor website says "GDPR compliant". It is a marketing sentence. There is no certificate behind it, no auditor who issues it, and no consequence to the vendor for printing it. The useful version of the question is narrower and much easier to answer: what exactly am I signing up to when I put my customers' data into this product?
The seven questions below are the ones worth asking before a contract, in roughly the order that makes vendors comfortable enough to answer honestly. None of them requires a lawyer to ask. Most of them are answered badly by vendors who have never been asked.
You are the controller. That is the whole point.
When you upload your customer list into a CRM, you remain the controller — you decided why the data is being processed. The vendor is your processor, acting on your instructions. Article 28 of the GDPR says that relationship has to be governed by a contract with specific contents, and the regulator asks you for it, not the vendor. That asymmetry is why these are buying questions rather than legal-department questions: the risk lands on your side of the table regardless of what the vendor's marketing page claims.
Seven questions, in the order worth asking them
- Which legal entity will be my processor, and where is it established? The brand on the website is often not the entity on the contract. Ask for the company name and country that will appear on the data processing agreement.
- Who are the sub-processors, and how am I told when the list changes? Every SaaS product has them — hosting, email delivery, support tooling, analytics. You want a published list, a notification mechanism, and a right to object that is written down rather than implied.
- Where is the data stored, and from where is it accessed? These are two different questions and the second one is the one that gets skipped. Data at rest in Frankfurt is still transferred if a support engineer in a third country opens a ticket and reads it.
- Is there a data processing agreement I can sign without negotiating it? A DPA that exists as a standard annex, linked from the website, is a good sign. A DPA "available on request for enterprise customers" means the vendor treats compliance as an upsell.
- If data leaves the EEA, on what basis? Adequacy decision, standard contractual clauses, or something the vendor cannot name. If it is SCCs, ask whether a transfer impact assessment exists — you are the one who has to be able to show it.
- How do I answer a data subject request with this product? A customer asking for a copy or deletion of their data is routine. Ask whether export and erasure are self-service in the interface or a support ticket with a turnaround time, and get that time in writing.
- What happens at the end of the contract? Which formats can you export, how long does the data stay retrievable, when is it actually deleted from backups, and will you receive confirmation. "Deleted within a reasonable period" is not an answer.
What a good answer sounds like
Good answers are specific, dated and written down. A vendor with its house in order will point you at a page rather than write you a paragraph:
- A sub-processor list with names, purposes and countries — and an email list you can subscribe to for changes.
- A standard DPA as a PDF or a click-through annex, with the Article 28 contents visible, not summarised.
- A stated breach notification commitment measured in hours. You have 72 hours from becoming aware to notify the supervisory authority under Article 33; a processor that promises to tell you "promptly" has pushed its problem onto your clock.
- A security page that names the certification body and the audit date for any ISO 27001 or SOC 2 claim, rather than showing the logo.
Red flags
- "Our servers are in the EU" offered as the complete answer, with nothing about support access, backups or subcontractors.
- A DPA that appears only in the enterprise plan. Compliance obligations do not scale with your subscription tier.
- A sub-processor list that is a screenshot, or that has no date on it.
- Any resistance to putting deletion timelines in writing.
- An account manager who answers a data protection question with a reassurance instead of a document.
Keep the answers
Whatever you get back, save it next to the contract. Article 30 requires most organisations to maintain records of processing activities, and the fastest way to build one is to file the answers as they arrive rather than reconstructing them the week an audit lands. It also makes the renewal conversation shorter: you already know what changed.
For the underlying rules rather than the buying view, the European Data Protection Board publishes the guidelines that supervisory authorities actually apply. And on this site, GDPR posture is one of the structured dimensions we record per product — so you can start from the shortlist that already answers question three.