GDPR for SaaS & Technology Platforms
GDPR-ready SaaS platforms must prove sub-processor accountability, demonstrate deletion workflows, show how PII is minimised across logs and AI tools, and answer DSARs within 30 days. Consentica and Privault turn those requirements into deployable controls — not documentation exercises.
Zero integration. Unlimited consents. Live within 48 hours.
Launch your DPDP-ready consent flow fast, validate it with real users, and scale when you're ready.
The General Data Protection Regulation governs the processing of personal data of individuals in the European Union and European Economic Area. It applies to organisations established in the EU, and to organisations outside the EU that offer goods or services to, or monitor the behaviour of, individuals in the EU.
GDPR distinguishes Controllers, who determine the purpose and means of processing, from Processors, who process data on a Controller's behalf under a Data Processing Agreement (DPA).
Both Controllers and Processors can be directly fined under GDPR — unlike DPDPA, where liability concentrates on the Data Fiduciary. A non-compliant sub-processor is a direct enforcement risk, not just a contractual one.
GDPR imposes a two-tier penalty structure: up to €10 million or 2% of global annual turnover (whichever is higher) for administrative failures, and up to €20 million or 4% of global annual turnover (whichever is higher) for core violations of data subject rights, consent, or cross-border transfer rules.
Maximum administrative fines under GDPR for key categories of non-compliance.
| Violation Category | Maximum Penalty |
|---|---|
Failure to maintain records of processing, conduct DPIAs, or appoint a DPO where required | Up to €10M or 2% global turnover |
Failure to implement appropriate security measures | Up to €10M or 2% global turnover |
Violation of lawful basis, consent, or core processing principles | Up to €20M or 4% global turnover |
Violation of data subject rights (access, erasure, portability) | Up to €20M or 4% global turnover |
Unlawful cross-border data transfer (Chapter V) | Up to €20M or 4% global turnover |
Non-compliance with a DPA order or investigation | Up to €20M or 4% global turnover |
Important: The 'whichever is higher' rule means fines for large multinational organisations are frequently calculated as a percentage of global — not just EU — annual turnover, making GDPR exposure scale directly with company size.
The most critical areas where organisations face DPA enforcement exposure.
Processing personal data without a valid lawful basis under Article 6.
Consent that is bundled, pre-ticked, or not freely given and specific.
Failing to maintain an accurate, contractually-bound sub-processor registry.
Failing to respond to access, erasure, or portability requests within 30 days.
Transferring data outside the EEA without SCCs, adequacy decisions, or valid safeguards.
Failing to notify the supervisory authority within 72 hours of becoming aware of a breach.
Collecting or retaining more personal data than necessary for the stated purpose.
Obstructing or failing to respond to a supervisory authority investigation.
The DPBI is a fully digital quasi-judicial body established under Chapter V of the DPDP Act. It is not a policy regulator — its sole function is investigation, adjudication, and enforcement.
An investigation can be initiated by:
For cross-border processing, a 'lead supervisory authority' coordinates enforcement across all affected EU member states under the one-stop-shop mechanism.
A DPA receives a complaint, breach notification, or opens its own investigation.
The DPA requests documentation, may conduct audits, and can compel testimony or access to systems.
For cross-border cases, the lead DPA circulates a draft decision to other concerned supervisory authorities.
The DPA issues a binding decision, which may include corrective measures and/or an administrative fine.
The organisation may appeal the decision to national courts, with further referral possible to the Court of Justice of the EU on points of EU law.
Key point: Under the one-stop-shop mechanism, cross-border GDPR cases can take significantly longer than single-jurisdiction cases due to the consensus process among concerned DPAs.
Article 83 GDPR gives supervisory authorities broad discretion based on the following factors.
Nature, gravity, and duration of the infringement, and the number of data subjects affected.
Whether the infringement was intentional or the result of negligence.
Actions taken to mitigate damage suffered by data subjects.
The degree of responsibility given prior security and privacy-by-design measures.
Whether the organisation has previously been found in violation.
The degree of cooperation with the supervisory authority to remedy the infringement.
GDPR's Article 83 factors give DPAs broad discretion. Documented privacy-by-design measures and prompt, transparent cooperation with an investigation are consistently associated with lower fines in published DPA decisions.
GDPR itself does not create a criminal offence — enforcement is administrative and civil at the EU level.
Some EU member states impose their own criminal sanctions for certain data protection violations under national law.
GDPR is primarily an administrative fine regime enforced by national DPAs. It does not itself establish criminal offences.
However, GDPR expressly permits member states to legislate additional penalties, including criminal sanctions, for infringements not subject to administrative fines — so national law should be checked for each jurisdiction of operation.
Important milestones in EU data protection regulation.
The European Parliament and Council formally adopt the Regulation.
GDPR applies directly across all EU member states; national DPAs begin enforcement.
Cross-border enforcement coordination and major fines establish enforcement precedent.
GDPR's turnover-based penalty structure means exposure scales directly with company size — making documented accountability, not just policy, the practical defence.
For SaaS and technology platforms specifically, an accurate sub-processor registry and a working DSAR workflow are the two most commonly tested compliance artefacts during enterprise procurement and DPA review alike.
A 4% global turnover exposure is not theoretical for scaled SaaS businesses — it is the single largest line-item privacy risk on the balance sheet.
A DPO is mandatory under GDPR if the core activities involve large-scale processing of special categories of data, large-scale systematic monitoring of individuals, or if the organisation is a public body. Many B2B SaaS platforms do not meet these thresholds, but appointing a privacy lead is strongly advised for accountability.