Seven specific things, tested in roughly this order — most SaaS companies fail at least one without knowing it.
General information for software and technology companies, not legal advice for your specific facts or jurisdiction — no lawyer-client relationship. See full terms.
Enterprise security reviews test seven specific things before they'll sign: a Records of Processing Activities register, a DPA with a named sub-processor list, documented Article 32 security measures, a written breach-notification runbook, an international-transfer mechanism, a retention and deletion schedule, and — where processing is high-risk — a DPIA. Missing any one is a common, fixable reason deals stall at review.
Enterprise procurement and security teams run these seven checks before they'll sign — in roughly this order.
A current register of what personal data you process, why, who you share it with, where it goes, and how long you keep it. Reviewers ask to see it — not just hear that it exists.
A GDPR-compliant Data Processing Agreement with your customers, plus a list of your own sub-processors — hosting, email, analytics, support tooling — and a way to notify customers when that list changes.
Encryption at rest and in transit, access controls, MFA, logging, and a defined penetration-testing cadence — documented as a policy, not just practised informally.
A written procedure to detect, assess and notify the supervisory authority within 72 hours, and affected data subjects without undue delay. Reviewers ask for the actual document.
If any processing happens outside the EEA or UK — common with US-based infrastructure or support tooling — Standard Contractual Clauses (and the UK Addendum, where relevant) need to be executed, with a transfer impact assessment behind them.
Defined retention periods per data category, plus a working deletion and export mechanism — this also covers customer offboarding requests.
Required when processing is likely high-risk — large-scale profiling or systematic monitoring, for instance. Buyers in regulated industries (health, fintech) will ask whether one exists for your core product.
Already fielding one of these reviews? The free DDQ Evidence Mapper shows which of your kit documents already answers each question a buyer asks.
The check that fails most often isn’t the exotic one. Companies can usually produce security documentation under pressure, but naming every sub-processor correctly, on the spot, is where most reviews actually stall. Keep that list current before a deal is on the table — not during it.
A 40-person SaaS company lost a six-figure annual enterprise contract at security review — not because of a breach, but because they couldn't produce a RoPA or name their own sub-processors on request. The underlying gap took two weeks to close properly. The deal had already moved to a competitor by the time they could answer.
Regulation (EU) 2016/679 (GDPR), Articles 3, 5, 28, 30, 32, 33, 34, 35 and 37 — full consolidated text on EUR-Lex. UK-specific readers: the UK GDPR and the ICO's International Data Transfer Agreement follow the same underlying logic with UK-specific mechanics. Current as of 21 July 2026.
Want the full set procurement asks for, ready to hand over?
Size doesn't exempt you. GDPR applies to any organisation processing personal data of people in the EU/UK, regardless of size or location (Article 3). What changes with size is which obligations bite hardest — the Article 30(5) RoPA exemption for under-250-employee companies is narrower than most assume, covering only occasional, low-risk processing, and most SaaS customer-data processing doesn't qualify.
The ToS governs the commercial relationship; the DPA specifically governs personal-data processing under Article 28 and is a separate, legally required document once you process personal data on a customer's behalf. Enterprise buyers' legal and security teams will ask for it by name.
If the documents already exist and are current, most reviews close in days. Starting from zero, budget three to six weeks for a RoPA, DPA, sub-processor list and breach runbook — a DPIA, if needed, can take longer since it requires an actual risk assessment, not a template fill.
Only mandatory under Article 37 if you're a public authority, or your core activities involve large-scale systematic monitoring or large-scale processing of special-category data. Most SaaS companies don't meet that bar, but many appoint a DPO contact voluntarily because enterprise buyers ask for one.
30 minutes, fixed fee, with the person who does the work — not a sales call.