European GDPR-compliant SaaS development partner: 8 checks
Publicly documented GDPR fines hit 6.11 billion euro by March 2026. Eight checks on a development partner: DPA annexes, sub-processors, region, breach clock.
In this piece
A GDPR-compliant SaaS development partner is a processor that can show you, in writing and before it touches your database, how it meets Article 28 of the GDPR. Four artefacts carry that proof: a data processing agreement with real annexes, a current list of the partner's own sub-processors, a named region where the data sits, and a breach notification window short enough to leave you room inside your own 72 hours.
The check matters because liability does not travel with the work. You are the controller. The partner is the processor. When a processor loses a database, the supervisory authority opens the file on you. The CMS Enforcement Tracker counted 6.11 billion euro in publicly documented GDPR fines across 2,685 cases to 1 March 2026, up 487.6 million euro on its previous edition. The eight checks below take about thirty minutes to run, and they filter most of the field before anyone writes a proposal.
Why “GDPR compliant” on a vendor page proves nothing
The phrase costs nothing to publish, and it is not what Article 28 asks for. EDPB Guidelines 07/2020 on the concepts of controller and processor say a processing contract cannot simply restate the provisions of the article: it has to give concrete information on how each obligation will be met. A vendor page cannot do that. Only the agreement and its annexes can.
Three documents get confused in this conversation. A privacy policy tells your users what you do with their data. An ISO 27001 certificate says the partner runs an information security management system, audited against a standard. A data processing agreement binds the partner to your instructions under Article 28. The first two are useful. Neither one substitutes for the third.
The eight checks
1. A data processing agreement with annexes that say something
Ask for the DPA before the statement of work, not after. Then read the annexes rather than the body: categories of personal data, categories of data subjects, purposes, the retention rule, the technical and organisational measures. An annex that reads “as instructed by the controller” and stops there is not an annex. If the partner has to draft the document from zero when you ask, you have learned something about how many regulated builds it has run. On how the DPA sits next to the commercial paperwork, see our note on SOW and MSA structure.
2. The sub-processor list, and your window to object
Article 28(2) is explicit: a processor may not engage another processor without your prior specific or general written authorisation, and under a general authorisation it must tell you about additions or replacements and give you the chance to object. Ask for today's list with four columns: name, what it does, where it runs, and the transfer basis if it runs outside the EEA.
On a normal SaaS build that list runs long: hosting, managed database, object storage, transactional mail, error tracking, product analytics, a CI runner, and in 2026 almost always a model provider. The EDPB recommends the contract fix the timeframe for approval or objection. A DPA that reserves the right to change sub-processors at any time, with notice posted to a page you are expected to check yourself, fails this one.
3. Where the data sits, and where the people sit
Region selection is a dropdown. Access is the harder question. Ask three things: which region the primary database is pinned to, which regions the backups replicate to, and whether an engineer outside the EEA can open a production console. Remote access from a third country is a transfer under Chapter V, whatever the storage region says. Backup replication is where this usually breaks, because it gets configured once and nobody reads it again.
4. The answer on US transfers, given where the law now stands
This is the check that separates a partner tracking the file from a partner who copied a clause in 2023. The EU-US Data Privacy Framework has been in force since 10 July 2023. The General Court dismissed Philippe Latombe's challenge on 3 September 2025, and the appeal is pending before the Court of Justice. Then on 29 June 2026 the US Supreme Court held in Trump v. Slaughter that removal protections for FTC commissioners are unconstitutional, a ruling that weakens the independence the framework's oversight and redress story rests on.
Nobody knows how the appeal lands, which is the reason to ask. Ask which US sub-processors are DPF-certified, what the documented fallback is if adequacy goes (standard contractual clauses plus a transfer impact assessment), and how long a swap would take in code. A partner with no answer has not read the file.
5. The breach clock, with a number in it
Article 33 gives you 72 hours from becoming aware to notify the supervisory authority. Article 33(2) tells the processor to notify the controller without undue delay, which is not a number, so put the number in the contract. Twenty-four hours from detection is workable and gets agreed often.
Then specify the payload. A call saying there was an incident leaves you drafting a notification from nothing. Ask for time of detection, systems affected, categories and approximate number of records and data subjects, containment steps already taken, and a named contact who stays reachable. Ask who writes the first draft of the notification too. Usually it should be them, for you to sign.
6. What fills development and staging
Copying the production database into a staging environment is the quiet violation in most builds. It happens for good engineering reasons, and it puts real personal data in an environment with broader access, thinner logging, and no retention rule.
Ask what non-production environments are seeded with. Synthetic data passes. A masked dump passes if the masking rule is written down and the masking runs before the data leaves production. Restoring a production backup into staging “just for a week” does not pass, and “it is only for testing” is not a legal basis. While you are there, ask how tenant isolation is enforced in the real database, because row-level security is where it either exists or does not.
7. Deletion, export, and the exit
Article 28(3)(g) requires the processor to delete or return the data at the end of the service, at your choice. Get the method, the deadline, and what happens to backups, which outlive deletions by the length of their retention window.
The EU Data Act (Regulation 2023/2854) added a second layer, applicable since 12 September 2025. With an in-scope cloud service, a customer can switch provider on two months' notice or less, exportable data and digital assets move inside a 30-day transition window, and the provider offers open documented interfaces for it. Switching and egress charges have to be gone by 12 January 2027. Those obligations sit on the cloud providers rather than on your development partner, but the partner picked them for you. Ask which of its picks makes a 30-day port realistic and which one would need a rewrite. Our comparison of R2, S3, and Supabase Storage covers the egress side of that.
8. Access logs and audit rights you can use
Article 28(3)(h) requires the processor to make information available to demonstrate compliance and to allow audits and inspections. Ask what an audit means here in practice: a filled questionnaire, a third-party report, or a real look at the configuration. All three are legitimate answers. Usually only one is on offer, and you want to know which one before you need it.
Then the operational questions. Who holds production access, how it is granted, whether it is logged, and how fast it is revoked when somebody leaves the project. And ask for the input you need for your own Article 30 records of processing, which stay your obligation. A partner that has done this before hands it over the same week.
What “European” buys you, and what it does not
An EU-established partner sits inside the GDPR's jurisdiction and within reach of your supervisory authority. That shortens arguments and removes a layer of paperwork. It does not make the stack European. An EU studio can host on a US hyperscaler, send mail through a US provider, and call a US model API, and then Chapter V applies exactly as before.
The reverse holds too. A partner outside the EU is not disqualified. Article 3(2) may pull it into scope anyway, and standard contractual clauses with a transfer impact assessment can cover the transfer. What changes is who does the paperwork, how long the negotiation takes, and how quickly you reach somebody when a regulator asks a question. Weigh it as friction, not as a yes or no.
What we put in a build
We send the DPA before the statement of work, with the sub-processor annex filled in by name and region rather than by category. The primary database is pinned to an EU region and the backup replication targets are checked against it, not assumed. Non-production environments get synthetic data. The processor breach window is 24 hours from detection, with the payload listed in the contract. Deletion and export run as a routine a support request triggers, not as a small project.
Where a US sub-processor is hard to avoid, which in 2026 usually means a model provider, we name it in the annex, record the transfer basis, and keep the swap cost low: one provider behind one interface, so a change in the law becomes a change in configuration. A limit worth stating plainly: we are not a law firm. A data protection officer or privacy counsel signs the assessment. We build to it, and we write the parts an engineer has to implement. For the regulated-sector version of the same conversation, our brief on KYC, PSD3 and DORA adds the checks a fintech buyer runs on top.
One thing to watch this year. The Commission's Digital Omnibus, published 19 November 2025, would amend the GDPR itself, and on 11 February 2026 the EDPB and the EDPS said in Joint Opinion 2/2026 that the proposal goes well beyond a technical amendment and would narrow the concept of personal data. The data half of that package is still in negotiation. A partner writing five-year compliance promises into a proposal is writing fiction.
Sources
- GDPR Article 28: Processor
- GDPR Article 33: Notification of a personal data breach to the supervisory authority
- GDPR Article 82: Right to compensation and liability
- EDPB Guidelines 07/2020 on the concepts of controller and processor in the GDPR
- CMS GDPR Enforcement Tracker Report 2025/2026: numbers and figures
- Epstein Becker Green: Adequacy of the EU-U.S. Data Privacy Framework Survives Challenge
- activeMind.legal: EU-U.S. Data Privacy Framework at risk following U.S. Supreme Court ruling
- Cooley: New EU Data Act switching rules for IaaS, PaaS and SaaS
- EDPB-EDPS Joint Opinion 2/2026 on the Digital Omnibus proposal (PDF)
Frequently asked questions
Does a GDPR-compliant development partner have to be based in the EU?+
No. Article 3(2) of the GDPR can reach a processor outside the EU when the processing relates to offering goods or services to people in the EU, and a transfer to a third country can be carried by standard contractual clauses plus a transfer impact assessment. What an EU-established partner gives you is less paperwork and a shorter route to somebody accountable in your own jurisdiction. What it does not give you is a European stack, so read the sub-processor list either way.
Who pays the fine if the development partner causes the breach?+
Both can be exposed, on different grounds. Under Article 83 a supervisory authority can fine a processor directly for breaching its own obligations, Article 28 included. Under Article 82 a data subject can claim compensation from the controller, and from the processor where it failed its processor duties or acted outside the controller's instructions, with joint and several liability so the claimant can pursue either one for the full amount. In practice the authority contacts the controller first, which is you. The contract decides who carries the cost afterwards, so read the liability cap next to the DPA rather than on its own.
Can we use a copy of the production database in staging, just for a week?+
Treat it as processing that needs its own legal basis and its own safeguards, because that is what it is. The copy usually lands in an environment with broader access, thinner logging, and no retention rule, which is the combination that turns a test into a breach. Use synthetic data, or a masked dump where the masking runs before the data leaves production and the rule is written down. If a real dataset is genuinely needed to reproduce a bug, scope it to the records involved, time-box it, log who touched it, and put the deletion date in the ticket.
What happens to our build if the EU-US Data Privacy Framework is struck down?+
Transfers to certified US sub-processors would need a new basis, in practice standard contractual clauses with a transfer impact assessment, and some of those assessments would not pass. The engineering question is swap cost. If every US service is called through one interface with its own configuration, replacing one is days of work. If provider-specific calls are spread through the codebase, it is a quarter. The appeal against the adequacy decision is pending at the Court of Justice, so this is worth costing now rather than after a ruling.
Related services
Studio
Start a project.
We write about what we build. Tell us what you want to build.