AGIDAT – Datenschutz | Informationssicherheit

Data Protection for SaaS & Software

As a software provider, you are yourself a data processor — know and fulfill your legal obligations.

Software providers carry particular responsibility

If your product processes your customers' personal data, you are generally a data processor under Art. 28 GDPR. That means your customers (the controllers) enter into a Data Processing Agreement (DPA) with you — and you must ensure that your infrastructure and processes meet GDPR requirements.

At the same time, you are the controller for your own users' data (registration, usage behavior, support requests).

Privacy by Design and Privacy by Default

Art. 25 GDPR requires software providers to consider data protection during development itself — not as an afterthought. This means:

  • Data minimization: only collect data that is genuinely needed
  • Pseudonymization where possible
  • Privacy-friendly default settings (Privacy by Default)
  • Deletion concepts built directly into the software

We advise your development teams and help implement these principles in practice.

For software products with AI features, these principles apply with particular rigor: training data must be limited to what's necessary, users must know when their input improves AI models, and AI-driven default settings must not be based on maximum data collection.

AI features in your own product: what software providers need to know now

More and more SaaS products integrate AI features — chatbots, text summarization, anomaly detection, automatic categorization. What is technically an API integration has far-reaching data protection consequences.

AI third-party providers as sub-processors

If you integrate OpenAI, Azure OpenAI, Google Vertex AI, Anthropic, or similar services into your product and thereby process your customers' data, the AI provider becomes a sub-processor under Art. 28(4) GDPR. This means:

  • You need a sub-processor agreement with the AI provider — and must be able to demonstrate this to your customers
  • Your own DPA must explicitly govern sub-processors (including your customers' approval requirements)
  • US third-country transfers must be safeguarded (Standard Contractual Clauses, and where necessary a Transfer Impact Assessment) — many AI APIs process data on US servers
  • You must check whether the AI provider uses data for model training, and disable this or disclose it in your privacy notice if applicable

We review the data protection terms of common AI APIs and help you set up your contractual structure in a GDPR-compliant way.

Automated decisions and Art. 22 GDPR

If your product makes automated decisions with a significant effect on individuals — for example AI-driven credit scoring, automatic rejections, or risk classifications — Art. 22 GDPR applies. Affected individuals then have the right to human review, an explanation of the decision logic, and the right to object to automated processing. These rights must be technically implementable. We advise on how to build the necessary transparency and enforceability of data subject rights into your software.

Data Protection Impact Assessment (DPIA) for AI

AI-driven processing frequently requires a DPIA under Art. 35 GDPR — particularly for profiling with a significant effect on individuals, processing of special categories of data (health, biometrics), or systematic behavioral analysis. We support the DPIA process from risk identification through to audit-proof documentation.

EU AI Act: obligations for SaaS and software providers

The EU AI Act has been in force since August 2024 and applies in stages from 2025/2026. For SaaS providers, it is relevant in two respects.

As a provider of AI systems, you count as a "provider" under the AI Act if you develop an AI system and place it on the market — regardless of whether the model was trained by you or sourced from a third party. Obligations depend on the risk classification:

  • Minimal risk (e.g., AI-powered search, spam filters): almost no additional obligations
  • Limited risk (e.g., chatbots): transparency obligation — users must know they are interacting with AI
  • High risk (e.g., AI in HR, lending, critical infrastructure): technical documentation, conformity assessment, registration in the EU database, risk management system, human oversight
  • Unacceptable practices: prohibited, e.g., social scoring or manipulative AI

As a deployer of a third party's AI system, you have your own obligations: risk monitoring, logging, and informing your users.

We analyze which category your AI features fall into and support implementation — from technical documentation through to registration.

Typical engagements

DPA drafting as a data processor

When your customers enter into a DPA with you, it must meet the requirements of Art. 28 GDPR. We draft a legally sound standard DPA for your product.

Privacy notices and terms of use

Complete, understandable, and up-to-date privacy notices for your platform — separated by your own data processing and processing on behalf of customers.

Technical data protection advice

How do you technically implement data deletion, data export (data subject rights), audit logs, and pseudonymization? We translate data protection requirements into concrete technical implementation options.

GDPR-compliant AI API integration

We review the contractual basis (sub-processor agreements, SCCs) for AI APIs such as OpenAI, Azure, Google, or Anthropic, identify third-country transfer risks, and help you communicate your sub-processor list transparently to customers.

EU AI Act compliance check

We assess your AI features under the AI Act (risk class, provider vs. deployer obligations) and produce a prioritized action plan for meeting the statutory requirements.

DPIA for AI-driven processing

For AI features with elevated data protection risk, we support the Data Protection Impact Assessment from risk identification through to documentation.