← All resources
For software and technology companies · GDPR

What a buyer's security review actually checks.

Seven specific things, tested in roughly this order — most SaaS companies fail at least one without knowing it.

Xprofesso · Resources~6 min readCurrent as of 21 July 2026Cited to source

General information for software and technology companies, not legal advice for your specific facts or jurisdiction — no lawyer-client relationship. See full terms.

TL;DR

Enterprise security reviews test seven specific things before they'll sign: a Records of Processing Activities register, a DPA with a named sub-processor list, documented Article 32 security measures, a written breach-notification runbook, an international-transfer mechanism, a retention and deletion schedule, and — where processing is high-risk — a DPIA. Missing any one is a common, fixable reason deals stall at review.

The seven checks

What a security review actually tests.

Enterprise procurement and security teams run these seven checks before they'll sign — in roughly this order.

CHECK 1 · ART. 30

Records of Processing Activities (RoPA)

A current register of what personal data you process, why, who you share it with, where it goes, and how long you keep it. Reviewers ask to see it — not just hear that it exists.

CHECK 2 · ART. 28

DPA and sub-processor list

A GDPR-compliant Data Processing Agreement with your customers, plus a list of your own sub-processors — hosting, email, analytics, support tooling — and a way to notify customers when that list changes.

CHECK 3 · ART. 32

Technical and organisational security measures

Encryption at rest and in transit, access controls, MFA, logging, and a defined penetration-testing cadence — documented as a policy, not just practised informally.

CHECK 4 · ART. 33/34

Breach notification runbook

A written procedure to detect, assess and notify the supervisory authority within 72 hours, and affected data subjects without undue delay. Reviewers ask for the actual document.

CHECK 5 · CH. V

International transfer mechanism

If any processing happens outside the EEA or UK — common with US-based infrastructure or support tooling — Standard Contractual Clauses (and the UK Addendum, where relevant) need to be executed, with a transfer impact assessment behind them.

CHECK 6 · ART. 5(1)(E)

Retention and deletion schedule

Defined retention periods per data category, plus a working deletion and export mechanism — this also covers customer offboarding requests.

CHECK 7 · ART. 35

Data Protection Impact Assessment

Required when processing is likely high-risk — large-scale profiling or systematic monitoring, for instance. Buyers in regulated industries (health, fintech) will ask whether one exists for your core product.

Already fielding one of these reviews? The free DDQ Evidence Mapper shows which of your kit documents already answers each question a buyer asks.

Specialist note

The check that fails most often isn’t the exotic one. Companies can usually produce security documentation under pressure, but naming every sub-processor correctly, on the spot, is where most reviews actually stall. Keep that list current before a deal is on the table — not during it.

In practice

A worked example.

LOST
THE DEAL

A 40-person SaaS company lost a six-figure annual enterprise contract at security review — not because of a breach, but because they couldn't produce a RoPA or name their own sub-processors on request. The underlying gap took two weeks to close properly. The deal had already moved to a competitor by the time they could answer.

Sources & dating

Cited, not guessed.

Regulation (EU) 2016/679 (GDPR), Articles 3, 5, 28, 30, 32, 33, 34, 35 and 37 — full consolidated text on EUR-Lex. UK-specific readers: the UK GDPR and the ICO's International Data Transfer Agreement follow the same underlying logic with UK-specific mechanics. Current as of 21 July 2026.

Want the full set procurement asks for, ready to hand over?

Questions

Before you act on this.

We're a small company — does GDPR even apply to us?

Size doesn't exempt you. GDPR applies to any organisation processing personal data of people in the EU/UK, regardless of size or location (Article 3). What changes with size is which obligations bite hardest — the Article 30(5) RoPA exemption for under-250-employee companies is narrower than most assume, covering only occasional, low-risk processing, and most SaaS customer-data processing doesn't qualify.

What's the actual difference between a DPA and the Terms of Service?

The ToS governs the commercial relationship; the DPA specifically governs personal-data processing under Article 28 and is a separate, legally required document once you process personal data on a customer's behalf. Enterprise buyers' legal and security teams will ask for it by name.

How long does preparing for a review like this take?

If the documents already exist and are current, most reviews close in days. Starting from zero, budget three to six weeks for a RoPA, DPA, sub-processor list and breach runbook — a DPIA, if needed, can take longer since it requires an actual risk assessment, not a template fill.

Do we need a Data Protection Officer?

Only mandatory under Article 37 if you're a public authority, or your core activities involve large-scale systematic monitoring or large-scale processing of special-category data. Most SaaS companies don't meet that bar, but many appoint a DPO contact voluntarily because enterprise buyers ask for one.

Want a founder-level read on your own setup?

30 minutes, fixed fee, with the person who does the work — not a sales call.