Software providers carry particular responsibility
If your product processes your customers' personal data, you are generally a data processor under Art. 28 GDPR. That means your customers (the controllers) enter into a Data Processing Agreement (DPA) with you — and you must ensure that your infrastructure and processes meet GDPR requirements.
At the same time, you are the controller for your own users' data (registration, usage behavior, support requests).
Privacy by Design and Privacy by Default
Art. 25 GDPR requires software providers to consider data protection during development itself — not as an afterthought. This means:
- Data minimization: only collect data that is genuinely needed
- Pseudonymization where possible
- Privacy-friendly default settings (Privacy by Default)
- Deletion concepts built directly into the software
We advise your development teams and help implement these principles in practice.
For software products with AI features, these principles apply with particular rigor: training data must be limited to what's necessary, users must know when their input improves AI models, and AI-driven default settings must not be based on maximum data collection.
AI features in your own product: what software providers need to know now
More and more SaaS products integrate AI features — chatbots, text summarization, anomaly detection, automatic categorization. What is technically an API integration has far-reaching data protection consequences.
AI third-party providers as sub-processors
If you integrate OpenAI, Azure OpenAI, Google Vertex AI, Anthropic, or similar services into your product and thereby process your customers' data, the AI provider becomes a sub-processor under Art. 28(4) GDPR. This means:
- You need a sub-processor agreement with the AI provider — and must be able to demonstrate this to your customers
- Your own DPA must explicitly govern sub-processors (including your customers' approval requirements)
- US third-country transfers must be safeguarded (Standard Contractual Clauses, and where necessary a Transfer Impact Assessment) — many AI APIs process data on US servers
- You must check whether the AI provider uses data for model training, and disable this or disclose it in your privacy notice if applicable
We review the data protection terms of common AI APIs and help you set up your contractual structure in a GDPR-compliant way.
Automated decisions and Art. 22 GDPR
If your product makes automated decisions with a significant effect on individuals — for example AI-driven credit scoring, automatic rejections, or risk classifications — Art. 22 GDPR applies. Affected individuals then have the right to human review, an explanation of the decision logic, and the right to object to automated processing. These rights must be technically implementable. We advise on how to build the necessary transparency and enforceability of data subject rights into your software.
Data Protection Impact Assessment (DPIA) for AI
AI-driven processing frequently requires a DPIA under Art. 35 GDPR — particularly for profiling with a significant effect on individuals, processing of special categories of data (health, biometrics), or systematic behavioral analysis. We support the DPIA process from risk identification through to audit-proof documentation.
EU AI Act: obligations for SaaS and software providers
The EU AI Act has been in force since August 2024 and applies in stages from 2025/2026. For SaaS providers, it is relevant in two respects.
As a provider of AI systems, you count as a "provider" under the AI Act if you develop an AI system and place it on the market — regardless of whether the model was trained by you or sourced from a third party. Obligations depend on the risk classification:
- Minimal risk (e.g., AI-powered search, spam filters): almost no additional obligations
- Limited risk (e.g., chatbots): transparency obligation — users must know they are interacting with AI
- High risk (e.g., AI in HR, lending, critical infrastructure): technical documentation, conformity assessment, registration in the EU database, risk management system, human oversight
- Unacceptable practices: prohibited, e.g., social scoring or manipulative AI
As a deployer of a third party's AI system, you have your own obligations: risk monitoring, logging, and informing your users.
We analyze which category your AI features fall into and support implementation — from technical documentation through to registration.
Typical engagements
DPA drafting as a data processor
When your customers enter into a DPA with you, it must meet the requirements of Art. 28 GDPR. We draft a legally sound standard DPA for your product.
Privacy notices and terms of use
Complete, understandable, and up-to-date privacy notices for your platform — separated by your own data processing and processing on behalf of customers.
Technical data protection advice
How do you technically implement data deletion, data export (data subject rights), audit logs, and pseudonymization? We translate data protection requirements into concrete technical implementation options.
GDPR-compliant AI API integration
We review the contractual basis (sub-processor agreements, SCCs) for AI APIs such as OpenAI, Azure, Google, or Anthropic, identify third-country transfer risks, and help you communicate your sub-processor list transparently to customers.
EU AI Act compliance check
We assess your AI features under the AI Act (risk class, provider vs. deployer obligations) and produce a prioritized action plan for meeting the statutory requirements.
DPIA for AI-driven processing
For AI features with elevated data protection risk, we support the Data Protection Impact Assessment from risk identification through to documentation.