GDPR for US SaaS Companies: What European Buyers Ask Before They Sign
Does GDPR apply to a US company?
Yes, if you offer goods or services to people in the EU or monitor their behaviour, even without an office there. The UK has its own, very similar version.
For most B2B SaaS companies the customer is the "controller" of the data and you are the "processor". That matters, because the customer is legally responsible for choosing a processor that protects the data. This is why their lawyers ask so many questions.
This article covers the commercial side. It is not legal advice.
The questions you will be asked
Where is our data stored and processed? Many European buyers prefer data to stay in the EU. Some, especially in the public sector, finance and health, require it. Offering an EU hosting region removes a common objection.
How is data transferred to the US? If data leaves the EU, you need a legal basis for the transfer. US companies commonly rely on certification under the EU-US Data Privacy Framework or on standard contractual clauses. The framework has been challenged in court and its long-term status is not settled, so many buyers ask for standard contractual clauses as well.
Can we see your data processing agreement? European customers expect a DPA as a standard part of the contract. Have one ready that a European lawyer has reviewed.
Who are your sub-processors? Keep a public, current list of the third parties that handle customer data, such as your cloud host and support tools, and a process for notifying customers of changes.
What security measures do you have? Certifications such as ISO 27001 or SOC 2 help. So do clear answers on encryption, access controls and incident response.
How do you handle requests from individuals? People have rights to access, correct and delete their data. Your customer will want to know how your product helps them respond.
What happens if there is a breach? Customers will expect to be notified quickly so they can meet their own reporting deadlines.
Do you have a representative in the EU? Companies without an EU establishment often need to appoint one. Buyers sometimes ask who it is.
Build the answers into the product
At compensIT we processed payroll and income data for millions of people in Europe. Privacy could not be handled in a policy document afterwards. It had to be designed into the product: what data we collected, how consent was given and what each party could see.
The same applies to a US SaaS product entering Europe. If your product collects more data than it needs, or cannot delete a customer's data on request, the sale gets harder no matter what the contract says.
A short preparation list
- Map what personal data your product processes and why.
- Decide on EU hosting, and be clear about what stays in the EU and what does not.
- Prepare a DPA and a sub-processor list.
- Set up your transfer mechanism and document it.
- Write a two-page security and privacy summary for sales to hand over.
- Train the sales team to answer the basic questions without calling legal.
Common questions
Does GDPR apply to a US company with no office in Europe?
Yes, if it offers goods or services to people in the EU or monitors their behaviour. Location of the company does not matter.
Do I need to host data in the EU to sell to European customers?
It is not always a legal requirement, but many buyers expect it and some sectors require it. Offering an EU region makes selling easier.
What is a data processing agreement?
A contract between a customer and a service provider that sets out how the provider handles personal data on the customer's behalf. European customers expect one from every vendor that processes personal data for them.