Data protection advice for SaaS companies in Germany: duties, templates, officers
SaaS providers are processors in almost every customer contract in accordance with Art. 28 GDPR. This guide shows which obligations apply, how the data protection officer is anchored and which templates you need.
Since May 25, 2018, the General Data Protection Regulation 2016/679 has been directly applicable in every Member State. SaaS companies based in Germany bear a double burden: They process their own customer data as the controller and at the same time act as a processor in almost every productive customer contract in accordance with Art. 28 GDPR. Anyone who constantly employs more than 20 people in the automated processing of personal data or processes data on a larger scale must also appoint a data protection officer (Section 38 BDSG, Art. 37 GDPR). According to Art. 83 GDPR, violations of these obligations are punishable by fines of up to 20 million euros or 4% of global group sales.
This guide is aimed at management, legal and CTOs of German and EU-related SaaS providers. It shows which obligations you actually have, how an order processing agreement (AVV) must be structured, which technical-organisational measures (TOMs) an enterprise buyer expects in the security questionnaire and how the 72-hour reporting requirement according to Art. 33 GDPR works operationally. We then classify the data protection officer as a role, describe the DPIA obligation according to Art. 35 GDPR for AI functions, look at the TTDSG situation for cookies and tracking, and conclude with the two reference models that SaaS companies typically choose today: internal DPO with workspace licence or external DPO as officer-as-a-service.
Key Takeaways
- SaaS providers are processors in almost every B2B contract and require an AVV in accordance with Art. 28 GDPR, TOMs in accordance with Art. 32 GDPR and a documented subcontractor chain.
- In Germany, the obligation to appoint a data protection officer usually applies via Section 38 BDSG (20 or more people) or via Art. 37 GDPR (core activity, regular systematic monitoring).
- Data breaches must be reported to the responsible supervisory authority within 72 hours of becoming aware of them (Article 33 GDPR). Deadline begins as soon as we become aware of it.
Why SaaS companies need to approach data protection structurally differently
A classic medium-sized company processes employee, applicant and customer data in a manageable number of systems. A SaaS company does the same and also takes on the role of processor in every productive customer contract in accordance with Art. 28 GDPR. This fundamentally changes the data protection architecture: the software itself, the tenant structure, the logging, the backups, the subcontractor chain and the ability to restore become part of the data protection concept. Anyone who refers to a GDPR audit report from 2018 will fail the first security questionnaire in the 2026 audit at the latest.
Anyone who sends a white paper to an enterprise buyer will be confronted with a security questionnaire in weeks 4 to 8. There are usually 80 to 240 questions about hosting, encryption, access control, subprocessors, data deletion, third country transfers, ISO/IEC 27001:2022, SOC 2 Type II, BSI C5 and the role of a designated data protection officer. Without reliable documents, the contract remains in place, often for several quarters, sometimes permanently.
The second point is scaling. A SaaS product that onboards 50 customers will have 50 separate AVV ratios, 50 lists of processed data categories, and potentially 50 deletion logics. Data protection advice that only provides templates does not cover this. A platform logic is needed: central TOMs, versioned AVV, a directory of processing activities in accordance with Art. 30 GDPR, a maintainable subprocessor list, an escalation matrix and a documented reporting chain for Art. 33 GDPR. This is exactly where the external data protection officer comes in and translates these requirements into a repeatable process that grows with each new customer instead of being reinvented with each new customer. The third and often underestimated point is audit documentation. Anyone who goes through due diligence in a Series A or Series B round will be asked for exactly this documentation, with a notice period of 10 to 14 days. Anyone who presents an Excel list loses negotiating power; Whoever presents a versioned directory with an audit trail wins it.
Obligation to name the data protection officer in SaaS contexts
The legal basis is twofold. Art. 37 Para. 1 GDPR requires the identification if the core activity consists of extensive, regular and systematic monitoring of data subjects or if special categories of data according to Art. 9 GDPR (health, biometric data, sexual orientation, political opinion) are processed extensively. § 38 Para. 1 BDSG adds: If there are 20 people who constantly process personal data automatically, a data protection officer must be appointed, regardless of the business model and regardless of the industry.
For SaaS providers, this means in practice: A team of 18 developers and two ops people who process tickets, logs and telemetry reaches the threshold. An HR tech, health tech or legal tech SaaS typically exceeds Art. 37 GDPR earlier because profiling, tracking or health data are part of the core of the product. AdTech, customer analytics and sales engagement platforms are also regularly classified as monitoring-intensive.
The designation is formal. What is required is a written appointment certificate, publication of the contact details in the data protection declaration and notification to the responsible state supervisory authority (e.g. LfDI Baden-Württemberg, BlnBDI Berlin, LDI NRW, BayLDA for Bavaria). Violations of the naming obligation are punishable by fines of up to 10 million euros or 2% of global group sales in accordance with Article 83 (4) GDPR. According to Article 38 Paragraph 3 of the GDPR, the data protection officer is to be exempt from instructions, reports directly to the highest management level and may not be removed or disadvantaged because of the performance of his duties. CIVAC provides the appointment certificate, the reporting line to management and the reporting procedure in a standardised manner. Reporting to the supervisory authority typically occurs within 2 working days of the mandate being accepted. The appointment certificate, signed, filed, verifiable.
Order processing, AVV and subprocessors in the SaaS architecture
The order processing contract according to Art. 28 Para. 3 GDPR forms the backbone of every B2B SaaS relationship. It contains the subject matter, duration, type and purpose of the processing, the categories of data subjects and data, the TOMs according to Art. 32 GDPR, the regulation on sub-processors, control rights of the controller, notification obligations in the event of data protection violations and the return or deletion of the data at the end of the contract. If one of these components is missing, the AVV is incomplete and the buyer is on shaky ground legally.
Operationally, three layers come together for a German SaaS company: your own AVV template that you offer to your customers, the AVV with hyperscalers (AWS Frankfurt, Microsoft Azure West Europe, Google Cloud europe-west3), and the AVV with subprocessors such as Stripe, Twilio, HubSpot, Intercom, OpenAI or Anthropic. Each shift needs a maintainable subprocessor list, a notification rule in the event of a change with the person responsible having the right to object, an assessment of the third country transfer according to Art. 44 ff. GDPR and a transfer impact assessment according to Schrems II.
A central directory in the workspace helps in practice: there are AVV versions with version number and status date, subprocessor lists with scope, standard contractual clauses 2021/914 with the appropriate modules, the Transfer Impact Assessment and the signed side letters. Anyone who wants to win a large DAX customer as a SaaS provider is asked for exactly this directory, often with a deadline of 5 working days for complete delivery. The parallel running ISO/IEC 27001:2022 logic provides the control level with 93 controls, the AVV provides the contractual level. Both belong together in a system that serves audits and buyer questionnaires from a single source. Others run compliance like a filing cabinet. We run it like software. The workspace provides version statuses, a diff view between AVV versions and an overview of open buyer questionnaires with deadline and status.
TOMs according to Art. 32 GDPR: What enterprise buyers check
Technical-organisational measures according to Art. 32 GDPR are not an appendix, but rather the implemented security situation. A robust TOM list for SaaS providers covers eight fields: confidentiality (access, entry, access control), integrity (input, propagation control), availability (backup, recovery, RPO and RTO), resilience (capacity, scaling, DDoS protection), recoverability after physical or technical incidents, procedures for periodic effectiveness verification, encryption in transit and at rest, and pseudonymization. Each of these eight categories must be specifically described, not listed abstractly.
Enterprise buyers check specifically: TLS 1.2 or 1.3 for transport, AES-256 or comparable for storage, multi-factor authentication for all admin access, role-based permissions with least privilege principle, audit logs with at least 12 months retention, annual penetration tests by independent providers, separate test and Productive environments without real personal data in testing, defined patch cycles with service levels for critical CVEs, EU data residency and a documented incident response procedure with exercises. Anyone who is ISO/IEC 27001:2022 certified has mapped 93 controls and can answer the majority of these questions with reference to the Statement of Applicability and the Risk Treatment Plan.
CIVAC operates this control level as a compliance platform and officer-as-a-service: 93 controls structured, 490 ready-to-use audit templates, reporting line to management documented, EU data residence in the workspace itself. This means you can deliver in one go Buyer questionnaire not 80 free answers, but 80 references to a versioned directory with receipts. The auditor calls, the evidence is ready. This shortens typical vendor risk assessments from 6 to 8 weeks to 2 to 3 weeks and speeds up contract closing because Procurement and InfoSec can work in parallel. For the management, a bottleneck in the sales cycle that was previously difficult to plan becomes a calculable quantity.
Data breach notification in 72 hours: The emergency path
Art. 33 GDPR obliges the person responsible to report a violation of the protection of personal data to the responsible supervisory authority immediately and, if possible, within 72 hours of becoming aware of it. Art. 33 Para. 2 GDPR obliges the processor, i.e. the SaaS provider, to inform the person responsible immediately after becoming aware of it so that he can fulfil his reporting obligation. The clock starts on awareness. If there is a high risk to the rights and freedoms of data subjects, Article 34 of the GDPR also imposes the obligation to notify the data subjects.
In SaaS reality, a data breach rarely occurs on the weekend at 9 a.m. It arises from misdirected email exports, compromised API tokens, misconfigurations in an S3 bucket, a lost employee laptop, a subprocessor incident reported to Stripe or Mailchimp, or a phishing success in the support team. Without a clear reporting path, 24 to 48 hours of clarification emails pass and the 72-hour clock expires. A late report is regularly prosecuted by the supervisory authorities as a separate breach of duty, with fines in the six-figure range.
An operational reporting path contains three components: a clear entry point (security mail, hotline, ticket queue with severity tag), 24-hour triage by the data protection officer and a prepared reporting mask for the respective supervisory authority including a sample text and an attachment list. CIVAC provides this path in the workspace, including an escalation matrix, sample report, draft communication to affected customers and a logbook for preserving evidence. For SaaS providers affected by NIS 2, there is also the 24-hour early warning path to the BSI, which runs parallel to the GDPR path, with a 72-hour follow-up report and final report. Both paths are intertwined, but must be clearly documented separately so that each authority receives the relevant document in the correct form.
Third country transfer and EU data residency: What counts according to Schrems II
The ECJ's Schrems II ruling of July 16, 2020 overturned the EU-US Privacy Shield. Since then, every transfer of personal data to a third country must be examined individually in accordance with Art. 44 ff. GDPR. For the USA, the EU-US Data Privacy Framework has been the EU Commission's adequacy decision since July 10, 2023, but it is politically fragile, is being contested in ongoing proceedings and is secured in practice by supplementary standard contractual clauses 2021/914. Anyone who relies solely on the DPF and does not prepare the directory for a possible loss risks an inadmissible transfer situation within days.
For SaaS providers this means: Every subprocessor based or processing outside the EEA needs a documented legal basis. These include SCC modules 2 (controller to processor) or 3 (processor to processor), a transfer impact assessment with an assessment of the legal environment and the access powers of authorities, and, if necessary, additional measures such as encryption with key sovereignty in the EEA or bring-your-own-key architectures. Anyone who uses hyperscaler regions Frankfurt, Amsterdam or Dublin reduces the complexity, but does not eliminate it, because the US Cloud Act continues to affect US parent companies, regardless of the physical storage location.
The practical way out is EU data residency with a clear architectural decision: storage in the EU region, backups in the EU region, logs in the EU region and, for AI functions, ideally models with EU hosting or European providers such as Mistral, Aleph Alpha or OVHcloud. CIVAC itself operates the workspace with EU data residency and explicitly states this in the AVV. For SaaS companies with a DACH focus, EU data residency is no longer a premium feature, but rather a minimum requirement for banks, insurance companies, energy suppliers, authorities and healthcare providers. Anyone who does not deliver this remains excluded from these segments.
Data Protection Impact Assessment (DPIA) for SaaS features
Art. 35 GDPR requires a data protection impact assessment if processing is likely to pose a high risk to the rights and freedoms of natural persons. The supervisory authorities have published lists (Art. 35 Para. 4 GDPR), in Germany the DSK list and the respective state list. Typical constellations that are subject to DPIA in the SaaS context are profiling functions, scoring models, biometric recognition, extensive location tracking, processing of health or financial data, automated personnel selection and the use of artificial intelligence to support decision-making with a personal connection.
A DPIA is not a one-time act, but an assessment that is reassessed for each feature, each roll-out and each larger product decision. It contains a systematic description of the processing with a data flow diagram, an assessment of necessity and proportionality, a risk assessment for the data subjects (likelihood and severity of harm) and the planned remedial measures with the responsible person and deadline. The data protection officer must be involved in accordance with Art. 35 Para. 2 GDPR, the recommendation must be documented and, if management deviates, justified in writing.
For SaaS products with AI components, the DPIA becomes the connection between the GDPR and the EU AI Act: Art. 27 EU AI Act requires a fundamental rights impact assessment for high-risk systems, which partially overlaps with the DPIA in terms of content. CIVAC has templates available in the workspace for both assessments, so that product teams do not conduct two assessment strands in parallel, but rather create an integrated assessment with two views. This typically saves 8 to 16 person-hours in legal and engineering per feature. Audit-proof, documented, Art. 35-firm. Once a product team has practiced this rhythm, the DPIA becomes part of the definition of done and no longer a special task before a release.
Cookies, tracking and marketing stack: TTDSG and ePrivacy
In addition to the GDPR, the Telecommunications Telemedia Data Protection Act (TTDSG), now called TDDDG, has been in effect since December 1, 2021. Section 25 TDDDG requires the end user's prior consent for any access to end devices that is not strictly necessary. This applies to virtually all marketing tracking, heatmaps, session replay tools, A/B testing platforms, advertising-related cookies and server-side tracking, as long as it addresses the device. Strictly necessary cookies (login session, shopping cart, load balancing) are still permitted without consent, but must be clearly differentiated.
For SaaS companies this means: The marketing website (typically www.firma.com) must be viewed separately from the product (app.firma.com). The marketing website needs to have a consent management banner with true freedom of choice, provider-level granularity, equal acceptance and rejection, and documented consent logic. The order processing standards apply in the product itself: Here the customer is the responsible party, the SaaS provider is the order processor, and tracking cookies are usually not additionally integrated by the SaaS provider, but only technical cookies that are necessary for the product are set.
The supervisory authorities have been checking more closely since 2024. The DSK has made it clear in several decisions that cookie banners with only an accept button, with a hidden reject option, with misleading colour contrasts or with nudging texts do not generate effective consent. Fines in the six-figure range against DAX companies and large SaaS providers have been documented. CIVAC accompanies the selection of the consent tool (Usercentrics, Cookiebot, OneTrust, Cookiehub), the configuration of the categories according to purpose, the integration into the tag manager and the documentation of the consent logs in a form that can withstand the supervisory authority. Including a monthly sample and screenshot archive so that the status can be verified at any time. The auditor calls, the evidence is ready. For SaaS providers with international reach, regional configuration is also an additional requirement because the requirements in France (CNIL) or Italy (Garante) are interpreted more strictly than in some other EU countries.
Data protection consulting with CIVAC: Two models, one workspace
SaaS companies typically choose their data protection architecture between two poles. On the one hand, the internal model: A person from Legal, Operations or Engineering takes on the DPO role, but has neither the tools nor the time for 80 buyer questionnaires per year and no specialised training in accordance with Article 37 (5) GDPR. On the other hand, the classic law firm: legally sound, but rarely present in the day-to-day operational work of a product team. Hourly rates of 280 to 450 euros do not scale with 50 customer AVVs per quarter.
As a compliance platform and officer-as-a-service, CIVAC is built precisely for the gap. If you licence the workspace for your internal representatives, then your internal DPO works with 490 audit templates, the 72-hour reporting path, the AVV generator, the subprocessor list and the directory of processing activities in a versioned system with EU data residency. Or have our representatives appointed, then CIVAC will take on the role of DPO in accordance with Section 38 BDSG, including an appointment certificate, reporting line to the management, reporting to the supervisory authority and representation in the event of a dispute. SLA: 2 working days instead of 2 to 6 weeks classic.
Both models run in the same workspace. You can switch from externally ordered to internally licensed at any time without rebuilding the directory, and vice versa. For most SaaS companies between 20 and 400 employees, the hybrid model has become established: externally appointed DPO for role and liability, internal product team with workspace access for daily work, monthly officer meeting for reporting lines. The appointment certificate, signed, filed, verifiable. Turn reading into a mandate.: info@civac.de or the contact form on civac.de. You will usually receive an initial assessment of your protection needs within 2 working days, together with a proposal for a workspace licence or an ordered DPO.
FAQ
When is a SaaS company in Germany obliged to appoint a data protection officer?
The obligation applies according to Section 38 BDSG if at least 20 people are constantly engaged in the automated processing of personal data, or according to Art. 37 GDPR in the case of extensive regular monitoring or processing of special data categories according to Art. 9 GDPR. For most B2B SaaS providers, the threshold is already reached from the first productive customer with personal data processing, but at the latest when the number of data processing employees exceeds 20.
Is a standard AVV template from the Internet sufficient?
No. An AVV according to Art. 28 Para. 3 GDPR must contain specific data categories, processing purposes, TOMs according to Art. 32 GDPR and the subprocessor list of your actual stack, supplemented by third country transfer regulations and standard contractual clauses 2021/914. Generic templates are rejected by enterprise buyers and regularly lead to complaints in audits with a deadline for improvement. A product-specific template is the basis of every reliable sales pipeline.
How quickly must a data breach in a SaaS product be reported?
The person responsible reports this to the responsible supervisory authority within 72 hours of becoming aware of it (Art. 33 GDPR). As a processor, the SaaS provider informs the person responsible immediately after becoming aware of it (Art. 33 Para. 2 GDPR). The 72 hours do not begin with the completion of the internal investigation, but with the first substantiated knowledge of the incident. If the risk is high, Art. 34 GDPR is also relevant.
What is the difference between an external DPO and a data protection law firm?
The external DPO assumes the formal role in accordance with Art. 37 GDPR with an appointment certificate, reporting line to the management and reporting to the responsible supervisory authority. A law firm provides selective advice on legal issues, but does not necessarily take on the formal role and is rarely involved in day-to-day product work. CIVAC provides the DPO as Officer-as-a-Service plus the workspace with 37 audit templates, EU data residency and SLA of 2 working days.
How are subprocessors like OpenAI or Anthropic handled?
Both are considered third-country processors if the processing takes place in the USA. What is required are AVV, standard contractual clauses 2021/914 with the appropriate modules, a transfer impact assessment with an assessment of the legal environment and inclusion in the subprocessor list with the obligation to notify in the event of a change. EU hosting options or European providers such as Mistral or Aleph Alpha significantly reduce complexity and are often the only viable option for regulated industries.
How does GDPR relate to ISO/IEC 27001:2022?
The GDPR regulates data protection obligations in the EU, ISO/IEC 27001:2022 regulates the information security management system with 93 controls in four categories (organisational, personnel, physical, technological). Both systematically complement each other. Anyone who is ISO/IEC 27001:2022 certified can demonstrate TOMs in accordance with Art. 32 GDPR with reference to the Statement of Applicability and the Risk Treatment Plan and significantly reduces the effort for security questionnaires.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.