Skip to content
UK GDPR

UK GDPR for SaaS Companies Selling into the UK

4 min readUpdated 9 September 2026

SaaS companies selling into the UK market face the same two-role challenge as in the EU: you are a data controller for your own processing (marketing, HR, analytics) and a data processor when you handle your customers' personal data on their behalf. UK GDPR governs both roles. This article covers what UK GDPR requires from SaaS companies specifically.


Your Two Roles Under UK GDPR

As a controller: For personal data you collect and use for your own purposes:

  • Your own marketing database
  • Website analytics and tracking
  • Employee and contractor data
  • Billing and customer account data

As a processor: For personal data your customers store in your product:

  • End user data entered into your platform by your customers
  • Customer employee data processed through your HR SaaS
  • Transaction data processed through your fintech SaaS

You have different obligations in each role. As a controller, you have the full UK GDPR framework to manage. As a processor, your primary obligations are to process only on customer instructions, maintain security, support customers' compliance, and execute Data Processing Agreements.


Controller Obligations for UK SaaS Companies

Privacy Notice

Your website and product must have a UK GDPR-compliant privacy notice covering:

  • What data you collect from visitors and customers
  • Lawful bases for each processing activity
  • Third parties you share data with
  • International transfers (including your US-based tools)
  • Data retention periods
  • User rights and how to exercise them
  • ICO as the supervisory authority

Cookie Consent

If your website or product uses non-essential cookies (analytics, advertising, A/B testing):

  • Implement a consent management platform
  • No non-essential cookies before consent
  • Reject option equal to accept
  • Record consent

Marketing Consent

For email marketing to UK individuals:

  • Consent required for new contacts
  • Legitimate interest may apply for existing customers (with easy opt-out)
  • TPS/CTPS checks for telemarketing
  • Double opt-in best practice

Processor Obligations for UK SaaS Companies

Data Processing Agreement (DPA)

For every UK-established customer that stores personal data in your product, you need a UK GDPR-compliant DPA. Article 28 requirements apply under UK GDPR as under EU GDPR:

  • Processing only on customer instructions
  • Confidentiality obligations on staff with access
  • Security measures appropriate to the risk
  • Sub-processor management (notification, contractual requirements)
  • Assistance with data subject rights
  • Deletion or return of data at contract end
  • Assistance with compliance obligations (DPIAs, breach response)

Publish your DPA. UK enterprise customers will request it before signing. Maintaining a standard DPA as a downloadable document (or online page) accelerates enterprise sales.

Sub-Processor Management

Your DPA with UK customers must address sub-processors — the other SaaS tools that process customer data on your behalf (AWS, Intercom, analytics tools).

Include in the DPA:

  • General or specific authorisation model for sub-processors
  • Notification obligation when sub-processors change
  • Requirement that sub-processors are bound to equivalent obligations

International Transfer Mechanisms

If customer data flows to the US or other non-adequate countries, the DPA must address the transfer mechanism:

  • UK Addendum to EU SCCs, or
  • IDTA, or
  • UK adequacy regulations

For US-based sub-processors: confirm they hold UK Bridge certification under the Data Privacy Framework, or execute an IDTA.


UK-Specific Considerations for Non-UK SaaS

If you are based outside the UK (EU, US, or elsewhere) and sell to UK customers:

UK GDPR applies via the targeting criterion if you offer services to UK individuals.

UK Representative: Required if you are not established in the UK.

ICO notification: For significant breaches affecting UK customers: 72 hours to ICO.

UK DPA addendum: UK enterprise customers will request UK GDPR-specific DPA terms. If your standard DPA references EU GDPR only (not UK GDPR), add a UK addendum.


Checklist for UK SaaS Compliance

As a controller:

  • UK GDPR privacy notice published and current
  • Cookie consent implemented correctly
  • Marketing database built on valid UK consent
  • DSAR procedure in place
  • Records of Processing Activities maintained
  • International transfer mechanisms documented for US tools

As a processor:

  • Standard DPA available for customer execution
  • DPA references UK GDPR (not EU GDPR only)
  • Sub-processor list maintained and disclosed
  • UK transfer mechanisms in customer DPA
  • UK breach notification procedure (notify customers within hours of incidents affecting their data)
  • UK Representative appointed (if not UK-established)

ComplyOne covers UK GDPR and EU GDPR in one platform — identifying the specific gaps between the two frameworks.

Check your UK GDPR compliance →