Enterprise buyers are no longer satisfied by a privacy policy URL in your DPA.

GDPR for SaaS & Technology Platforms

GDPR-ready SaaS platforms must prove sub-processor accountability, demonstrate deletion workflows, show how PII is minimised across logs and AI tools, and answer DSARs within 30 days. Consentica and Privault turn those requirements into deployable controls — not documentation exercises.

€20M / 4%
Max Penalty (higher of)
72 Hrs
Breach Reporting
30 Days
DSAR Response
2018
Enforcement Began

Get 3 Months Free Consentica Access

Zero integration. Unlimited consents. Live within 48 hours.

Launch your DPDP-ready consent flow fast, validate it with real users, and scale when you're ready.

What Is GDPR and Who Does It Apply To?

The General Data Protection Regulation governs the processing of personal data of individuals in the European Union and European Economic Area. It applies to organisations established in the EU, and to organisations outside the EU that offer goods or services to, or monitor the behaviour of, individuals in the EU.

GDPR distinguishes Controllers, who determine the purpose and means of processing, from Processors, who process data on a Controller's behalf under a Data Processing Agreement (DPA).

Who Must Comply?

  • Organisations established in the EU/EEA that process personal data
  • Non-EU organisations offering goods/services to, or monitoring, individuals in the EU

Important Compliance Point

Both Controllers and Processors can be directly fined under GDPR — unlike DPDPA, where liability concentrates on the Data Fiduciary. A non-compliant sub-processor is a direct enforcement risk, not just a contractual one.

Quick Answer

GDPR imposes a two-tier penalty structure: up to €10 million or 2% of global annual turnover (whichever is higher) for administrative failures, and up to €20 million or 4% of global annual turnover (whichever is higher) for core violations of data subject rights, consent, or cross-border transfer rules.

GDPR Penalty Schedule

Maximum administrative fines under GDPR for key categories of non-compliance.

Violation CategoryMaximum Penalty
Failure to maintain records of processing, conduct DPIAs, or appoint a DPO where required
Up to €10M or 2% global turnover
Failure to implement appropriate security measures
Up to €10M or 2% global turnover
Violation of lawful basis, consent, or core processing principles
Up to €20M or 4% global turnover
Violation of data subject rights (access, erasure, portability)
Up to €20M or 4% global turnover
Unlawful cross-border data transfer (Chapter V)
Up to €20M or 4% global turnover
Non-compliance with a DPA order or investigation
Up to €20M or 4% global turnover

Important: The 'whichever is higher' rule means fines for large multinational organisations are frequently calculated as a percentage of global — not just EU — annual turnover, making GDPR exposure scale directly with company size.

Major GDPR Violations

The most critical areas where organisations face DPA enforcement exposure.

Unlawful Processing

Processing personal data without a valid lawful basis under Article 6.

Invalid Consent Mechanisms

Consent that is bundled, pre-ticked, or not freely given and specific.

Sub-Processor Accountability Gaps

Failing to maintain an accurate, contractually-bound sub-processor registry.

DSAR Response Failures

Failing to respond to access, erasure, or portability requests within 30 days.

Cross-Border Transfer Violations

Transferring data outside the EEA without SCCs, adequacy decisions, or valid safeguards.

Breach Notification Failures

Failing to notify the supervisory authority within 72 hours of becoming aware of a breach.

Data Minimisation Violations

Collecting or retaining more personal data than necessary for the stated purpose.

Non-Cooperation with a DPA

Obstructing or failing to respond to a supervisory authority investigation.

How the Data Protection Board Enforces Penalties

The DPBI is a fully digital quasi-judicial body established under Chapter V of the DPDP Act. It is not a policy regulator — its sole function is investigation, adjudication, and enforcement.

Who Can Trigger a GDPR Enforcement Action?

An investigation can be initiated by:

  • A data subject filing a complaint with their national Data Protection Authority
  • A DPA-initiated investigation or sector-wide audit sweep
  • A breach notification submitted by the organisation itself
  • Referral from another EU supervisory authority under the one-stop-shop mechanism

For cross-border processing, a 'lead supervisory authority' coordinates enforcement across all affected EU member states under the one-stop-shop mechanism.

The 5-Stage Enforcement Process

Stage 1 — Complaint or Trigger

A DPA receives a complaint, breach notification, or opens its own investigation.

Stage 2 — Investigation

The DPA requests documentation, may conduct audits, and can compel testimony or access to systems.

Stage 3 — Draft Decision

For cross-border cases, the lead DPA circulates a draft decision to other concerned supervisory authorities.

Stage 4 — Final Decision and Fine

The DPA issues a binding decision, which may include corrective measures and/or an administrative fine.

Stage 5 — Judicial Appeal

The organisation may appeal the decision to national courts, with further referral possible to the Court of Justice of the EU on points of EU law.

Key point: Under the one-stop-shop mechanism, cross-border GDPR cases can take significantly longer than single-jurisdiction cases due to the consensus process among concerned DPAs.

6 Factors DPAs Consider Before Imposing a Fine

Article 83 GDPR gives supervisory authorities broad discretion based on the following factors.

Nature, Gravity, and Duration

Nature, gravity, and duration of the infringement, and the number of data subjects affected.

Intentional or Negligent Character

Whether the infringement was intentional or the result of negligence.

Mitigating Action Taken

Actions taken to mitigate damage suffered by data subjects.

Technical and Organisational Measures

The degree of responsibility given prior security and privacy-by-design measures.

History of Prior Infringements

Whether the organisation has previously been found in violation.

Cooperation with the DPA

The degree of cooperation with the supervisory authority to remedy the infringement.

GDPR's Article 83 factors give DPAs broad discretion. Documented privacy-by-design measures and prompt, transparent cooperation with an investigation are consistently associated with lower fines in published DPA decisions.

Does GDPR Have Criminal Penalties?

No EU-Wide Criminal Penalty

GDPR itself does not create a criminal offence — enforcement is administrative and civil at the EU level.

Member States May Add Criminal Law

Some EU member states impose their own criminal sanctions for certain data protection violations under national law.

GDPR is primarily an administrative fine regime enforced by national DPAs. It does not itself establish criminal offences.

However, GDPR expressly permits member states to legislate additional penalties, including criminal sanctions, for infringements not subject to administrative fines — so national law should be checked for each jurisdiction of operation.

Key GDPR Enforcement Dates

Important milestones in EU data protection regulation.

April 2016

GDPR adopted

The European Parliament and Council formally adopt the Regulation.

May 25, 2018

GDPR becomes enforceable

GDPR applies directly across all EU member states; national DPAs begin enforcement.

Ongoing

One-stop-shop mechanism matures

Cross-border enforcement coordination and major fines establish enforcement precedent.

Conclusion

GDPR's turnover-based penalty structure means exposure scales directly with company size — making documented accountability, not just policy, the practical defence.

For SaaS and technology platforms specifically, an accurate sub-processor registry and a working DSAR workflow are the two most commonly tested compliance artefacts during enterprise procurement and DPA review alike.

A 4% global turnover exposure is not theoretical for scaled SaaS businesses — it is the single largest line-item privacy risk on the balance sheet.

Frequently Asked Questions

A DPO is mandatory under GDPR if the core activities involve large-scale processing of special categories of data, large-scale systematic monitoring of individuals, or if the organisation is a public body. Many B2B SaaS platforms do not meet these thresholds, but appointing a privacy lead is strongly advised for accountability.