
GDPR Compliance for B2B SaaS: Articles 28–34 Explained
A B2B SaaS reference to GDPR Articles 28, 32, 33 & 34 — DPAs, security of processing, and breach notification — with a compliance checklist and links to each deep-dive.
GDPR Compliance for B2B SaaS: Articles 28–34 Explained
Regulation (EU) 2016/679 has been enforceable since May 25, 2018. Total fines now exceed €7.1 billion — with €1.2 billion issued in 2025 alone. For B2B companies operating in the EU, GDPR compliance is not optional: it governs how you collect, process, store, and protect personal data of every EU and EEA resident your business touches.
This hub covers the four articles B2B teams meet most often — Article 28 (data processing agreements), Article 32 (security of processing), and Articles 33 & 34 (breach notification) — with a compliance checklist, recent fines, and a link to each article's dedicated deep-dive.
Looking for the big picture first? Start with our complete guide to GDPR compliance — the seven principles, six lawful bases, and data subject rights. Then use this page as the map to the article-by-article detail.
The GDPR Article Cluster
Each of the four articles below has its own full deep-dive. Use this hub for the overview and the checklist; follow the links for the mechanics, enforcement examples, and how to prove compliance:
| Article | What it governs | Deep-dive |
|---|---|---|
| Article 28 | Processor obligations & DPA requirements | GDPR Article 28: Processor Obligations & DPA Requirements |
| Article 32 | Security of processing (TOMs) | GDPR Article 32: Security of Processing Requirements |
| Article 33 | Breach notification to the authority (72 hours) | GDPR Article 33: The 72-Hour Breach Notification Rule |
| Article 34 | Breach communication to data subjects | GDPR Article 34: Communicating a Breach to Data Subjects |
For the operational, controller-facing side of Article 28 — running a public subprocessor list and change-notice workflow — see subprocessor management under GDPR Article 28.
Jump to:
- Who Must Comply with GDPR
- GDPR Compliance Checklist for 2026
- Article 32: Security of Processing
- Articles 33 and 34: Breach Notification
- Article 28: Data Processing Agreements
- GDPR Fines and Enforcement in 2025–2026
- GDPR Compliance Software
- ISMS and Trust Center: Two Sides of the Same Coin
What Is GDPR Compliance?
GDPR compliance means that your organization processes personal data of EU/EEA residents in accordance with Regulation (EU) 2016/679 — the General Data Protection Regulation. The regulation applies whenever personal data (any information relating to an identified or identifiable natural person) is collected, stored, used, or transferred.
Compliance has four pillars:
- Lawfulness: Every processing activity requires a legal basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests under Article 6)
- Transparency: Data subjects must know what data is collected, why, and for how long (Articles 12–14)
- Security: Appropriate technical and organizational measures protect personal data (Article 32)
- Accountability: Organizations must be able to demonstrate compliance at any time (Article 5(2))
For B2B SaaS and technology companies, compliance is particularly complex because most companies occupy two roles simultaneously: data controller (responsible for your own customer data) and data processor (handling data your customers entrust to your platform). Each role carries distinct obligations.
Who Must Comply with GDPR?
GDPR applies to any organization that:
- Is established in the EU or EEA, regardless of where the data is processed
- Is established outside the EU but offers goods or services to EU/EEA residents, or monitors the behavior of individuals in the EU (the "targeting criterion" under Article 3(2))
There is no minimum size threshold. A five-person SaaS startup with EU customers must comply. A US enterprise serving a single EU client must comply.
Specific obligations depend on your role:
| Role | Definition | Key obligations |
|---|---|---|
| Controller | Determines the purposes and means of processing | Legal basis, privacy notices, data subject rights, DPA with processors, DPIAs |
| Processor | Processes data on behalf of a controller | DPA with controller, security measures, breach notification to controller, sub-processor rules |
| Both | Most B2B SaaS companies | All of the above in each direction |
GDPR Compliance Checklist for 2026
Regulators in 2026 expect demonstrable, operational compliance — not just policies. Here is what needs to be in place:
1. Data Mapping and Records of Processing Activities (Article 30)
Maintain a complete inventory of every processing activity: what data is collected, from whom, for what purpose, on what legal basis, how long it is retained, and which processors receive it. Article 30 makes these records of processing activities (RoPAs) mandatory for most organizations — our free GDPR RoPA template ships the controller and processor registers ready to complete.
2. Legal Basis for Every Processing Activity (Article 6)
Document the lawful basis for each processing activity before it begins. Consent must be freely given, specific, informed, and unambiguous — and withdrawable at any time. Legitimate interests require a balancing test. Processing without a documented lawful basis triggers the upper fine tier.
3. Privacy Notices (Articles 12–14)
Provide clear, plain-language privacy information to data subjects at the time of collection. The EDPB's 2026 coordinated enforcement action focuses specifically on Articles 12–14 transparency obligations, making this a priority for supervisory authorities across all EU member states this year.
4. Data Subject Rights Mechanisms (Articles 15–22)
Implement processes to respond to access requests (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), and objection (Article 21) within one month. The EDPB's 2025 coordinated action focused on the right to erasure — organizations without working deletion workflows were penalized.
5. Data Processing Agreements with All Processors (Article 28)
Every third-party vendor that processes personal data on your behalf requires a signed DPA. This includes cloud providers, analytics tools, CRM platforms, payment processors, and any subcontractors. See Article 28 requirements in detail below.
6. Technical and Organizational Security Measures (Article 32)
Implement encryption, pseudonymization, access control, multi-factor authentication, and regular security testing. Document these measures as Technical and Organizational Measures (TOMs). See Article 32 requirements below.
7. Data Protection Impact Assessments for High-Risk Processing (Article 35)
Conduct a DPIA before starting any processing "likely to result in a high risk" to individuals. High-risk categories include large-scale processing of sensitive data, systematic profiling, and new technologies. DPIAs must identify risks and document the mitigating measures adopted — our free DPIA template provides the full Article 35(7) structure with screening questions and a risk matrix.
8. Data Protection Officer Appointment (Article 37)
Appoint a DPO if your core activities involve large-scale systematic monitoring of individuals or large-scale processing of special categories of data. Public authorities must always appoint a DPO.
9. Breach Detection and Notification Readiness (Articles 33–34)
Have a tested incident response process that can detect breaches quickly, assess their risk level, and notify the supervisory authority within 72 hours. See Articles 33–34 in detail below.
10. International Data Transfer Safeguards (Articles 44–49)
Personal data may only be transferred outside the EU/EEA to countries with an adequacy decision, or under appropriate safeguards (Standard Contractual Clauses, Binding Corporate Rules). Following the TikTok €530M fine in May 2025 for unlawful transfers to China, supervisory authorities are actively scrutinizing cross-border data flows.
Where an ISMS Contributes — and Where the GDPR Goes Further
A good ISMS (Information Security Management System) provides the structure for technical and organizational measures required by the GDPR. But the GDPR imposes two additional requirement layers that an ISMS as an internal governance system cannot address on its own:
- Operational breach notification obligations under Articles 33 and 34 — within tight external deadlines
- Binding obligations in the processor relationship under Article 28 — contractual, ongoing, and auditable
Article 32: Security of Processing
Article 32 requires controllers and processors to implement "appropriate technical and organizational measures" (TOMs) to ensure a level of security appropriate to the risk — judged against the state of the art, cost, and the nature, scope, context, and purposes of processing. It names four illustrative measures: pseudonymization and encryption; ongoing confidentiality, integrity, availability, and resilience; the ability to restore availability after an incident; and a process for regularly testing the effectiveness of measures. "Insufficient technical and organisational measures" is one of the most frequently fined GDPR categories, and the accountability principle (Article 5(2)) means every measure must be demonstrable, not just implemented.
→ Full requirements, the risk-based test, encryption, the ISO 27001 ↔ Article 32 mapping, fines, and how to prove it: GDPR Article 32: Security of Processing Requirements.
Articles 33 and 34: Personal Data Breach Notification
The GDPR introduces a two-tier notification regime for personal data breaches.
Want the full guides? Read our deep-dives on GDPR Article 33: the 72-hour breach notification rule and GDPR Article 34: communicating a breach to data subjects.
Notification to the Supervisory Authority (Article 33)
In case of a personal data breach, the controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it — unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The notification covers the nature of the breach, a contact point, the likely consequences, and the measures taken; where the facts are not all known in time, Article 33(4) permits phased notification. Processors must alert controllers without undue delay (Article 33(2)), and every breach must be documented internally (Article 33(5)) — even those that are not notifiable.
→ Full mechanics, when the clock starts, enforcement examples, and the UK/Norway position: GDPR Article 33: the 72-hour breach notification rule.
Communication to Data Subjects (Article 34)
When the breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must also communicate it to the affected data subjects without undue delay, in clear and plain language. This is a deliberately higher threshold than the Article 33 duty owed to the authority — and Article 34(3) provides three exceptions (most importantly, effective encryption). The supervisory authority can compel communication under Article 34(4).
→ Full detail, the three exceptions, and the UK/Norway position: GDPR Article 34: communicating a breach to data subjects.
Article 28: Data Processing Agreements
Article 28 governs the controller–processor relationship. A controller may only use processors that provide "sufficient guarantees" of appropriate security (Article 28(1)) — a continuous due-diligence duty, not a one-off check — and the relationship must be governed by a Data Processing Agreement (DPA) containing the eight mandatory clauses of Article 28(3): documented instructions, confidentiality, Article 32 security, sub-processor conditions, assistance with data-subject rights, assistance with Articles 32–36, deletion/return of data, and audit-and-information rights. Sub-processors need the controller's specific or general authorisation (Article 28(2)), and the initial processor remains fully liable for them (Article 28(4)). EDPB Opinion 22/2024 (October 2024) further requires controllers to be able to identify every processor and sub-processor in the chain at all times.
→ The eight DPA clauses in full, sub-processor authorisation, EDPB Opinion 22/2024, fines, and how to prove it: GDPR Article 28: Processor Obligations & DPA Requirements. For the operational subprocessor-list and change-notice side, see subprocessor management under Article 28.
Penalties (Article 83)
The GDPR provides for a two-tier penalty system:
| Violation | Fine | Legal basis |
|---|---|---|
| Obligations of controllers and processors (Art. 8, 11, 25–39, 42, 43) | Up to EUR 10 million or 2% annual turnover | Art. 83(4) |
| Processing principles, data subject rights, transfers to third countries (Art. 5–7, 9, 12–22, 44–49) | Up to EUR 20 million or 4% annual turnover | Art. 83(5) |
| Non-compliance with an order by the supervisory authority | Up to EUR 20 million or 4% annual turnover | Art. 83(6) |
The higher amount applies in each case.
Relevance for data processing and breach notification:
- Violations of Article 28 (processing) and Article 32 (security) fall under the lower tier (up to EUR 10 million / 2%)
- Violations of Article 33 (notification to authority) and Article 34 (communication to data subjects) also fall under the lower tier
- However, failure to notify may additionally be considered a violation of Article 5 (accountability) — which can trigger the upper tier
When setting fines, Article 83(2) requires consideration of, among other factors: the nature, gravity, and duration of the infringement; intentional or negligent character; measures taken to mitigate damage; previous infringements; and cooperation with the supervisory authority.
GDPR Fines and Enforcement in 2025–2026
GDPR enforcement has accelerated sharply. Total fines since May 2018 reached €7.1 billion by January 2026, with approximately €1.2 billion in penalties issued in 2025. The same survey reports an average of 443 personal-data breach notifications each day.
Major Enforcement Actions in 2025
TikTok — €530 million (May 2025) Ireland's Data Protection Commission fined TikTok €530 million for illegally transferring European Economic Area user data to servers in China, in violation of Chapter V transfer rules. Engineers in China were routinely able to access sensitive information belonging to EU residents, and TikTok failed to carry out adequate risk assessments regarding Chinese state surveillance laws.
Meta — €479 million (2025) A Madrid court found Meta had unlawfully processed user data, giving it an unfair advantage in the online advertising market and benefiting 87 Spanish media companies' legal claims.
Vodafone Germany — €45 million (2025) Germany's Federal Commissioner for Data Protection (BfDI) issued two fines: €15 million for poor internal data protection controls and €30 million for security flaws in handling customer data through customer portals and hotlines.
Capita plc (UK) — £14 million The UK Information Commissioner's Office fined Capita £14 million following a cyber-attack that exposed the personal data of 6.6 million people.
2026 Enforcement Priority: Transparency (Articles 12–14)
Following the EDPB's 2025 coordinated enforcement action on the right to erasure (Article 17), the EDPB announced on 14 October 2025 that the 2026 coordinated enforcement action will focus on transparency and information obligations under Articles 12 to 14 GDPR. Organizations without clear, complete, and accessible privacy notices face heightened supervisory scrutiny in 2026.
Enforcement is no longer reactive. Regulators are proactively auditing organizations, particularly for dark patterns in consent UIs, unlawful cross-border transfers, and inadequate breach notification procedures.
GDPR Compliance Software: What to Look For
The complexity of GDPR compliance — spanning data mapping, consent management, DPA tracking, breach notification, and continuous evidence collection — has created a mature market for compliance software. For organisations navigating multiple EU frameworks simultaneously (GDPR, NIS2, DORA), see our EU Compliance Software Buyer's Guide for a structured evaluation framework. Key capabilities to evaluate:
| Capability | Why it matters |
|---|---|
| Data mapping / RoPA automation | Maintaining Article 30 records manually is error-prone at scale |
| DPA and subprocessor management | Article 28 requires monitoring processors continuously, not once |
| Consent management | Consent logs must be auditable; cookie flows must not use dark patterns |
| Breach response workflows | 72-hour deadline requires pre-built notification templates and escalation paths |
| Continuous evidence collection | Article 5(2) accountability requires always-available proof, not point-in-time snapshots |
| Data subject rights management | DSAR workflows must respond within one month |
| Cross-border transfer tracking | Post-TikTok enforcement, transfer impact assessments need regular review |
The leading platforms serve different segments: OneTrust and TrustArc for large enterprise privacy operations; Sprinto and Drata for continuous compliance automation; specialist tools for consent management (Cookiebot, Usercentrics). Orbiq's Trust Center addresses the specific challenge of demonstrating GDPR compliance externally — to customers, prospects, and auditors — through a centralized, always-current documentation hub.
ISMS and Trust Center: Two Sides of the Same Coin
GDPR requirements cannot be met with a single system. Governance requires structure — an ISMS is indispensable for this. However, Articles 28, 33, and 34 additionally require operational capabilities:
- Breach notification within 72 hours — to supervisory authorities and, where applicable, data subjects
- Documentation of all breaches — including those not subject to notification
- Structured assessment and monitoring of processors
- Demonstrable due diligence in selecting and continuously monitoring service providers
The Two Directions of a Trust Center
A Trust Center not only supports inbound assessment of your own service providers — it also solves a practical problem on the outbound side: Organizations acting as processors must provide their customers with the information required under Article 28(3)(h).
In practice, this means: Every potential or existing customer can — and will — request evidence. A Trust Center consolidates this documentation in one professional location:
| Document | Purpose | GDPR Reference |
|---|---|---|
| Data Processing Agreement (DPA) | Standard contract for signature | Art. 28(3) |
| Technical and Organizational Measures (TOMs) | Evidence of security measures | Art. 32 |
| List of Sub-processors | Transparency about sub-processors | Art. 28(2) |
| Certifications (ISO 27001, SOC 2) | Evidence of sufficient guarantees | Art. 28(5), Art. 42 |
| Audit reports and penetration test summaries | Independent assessment of measures | Art. 28(3)(h) |
| Security policies | Documentation of internal processes | Art. 32 |
| Records of processing activities | Overview of data processing | Art. 30 |
| Data Protection Impact Assessments (where applicable) | Risk assessment for critical processing | Art. 35 |
Without a Trust Center, this communication runs through email, individual requests, and manual processes — time-consuming, error-prone, and difficult to scale. With a Trust Center, reactive document searches become proactive demonstration of compliance.
The Dual Perspective
Many organizations are simultaneously controllers (vis-a-vis data subjects) and processors (vis-a-vis their customers). A Trust Center addresses both roles:
As a Controller (Inbound):
- Assessment and monitoring of your own processors
- Collection and maintenance of DPAs, TOMs, and certificates from service providers
- Documentation of due diligence in selection
As a Processor (Outbound):
- Provision of all evidence to customers in one place
- Scalable response to security questionnaires and audits
- Proactive transparency instead of reactive document searches
Organizations that connect both worlds are well-positioned: An ISMS for internal governance, a Trust Center for external communication — in both directions. This transforms compliance effort into a functioning system and documentation into true resilience. See also our guide on continuous monitoring for how to maintain always-current compliance evidence.
Sources & References
- Regulation (EU) 2016/679 (GDPR) – Full Text — Official Journal of the European Union. The complete text of the General Data Protection Regulation.
- DLA Piper — GDPR Fines and Data Breach Survey (January 2026) — €7.1 billion in cumulative fines, approximately €1.2 billion in 2025, and 443 daily breach notifications.
- DLA Piper GDPR Fines and Data Breach Survey: January 2026 — Annual survey of GDPR enforcement trends and fine volumes.
- EDPB 2026 Coordinated Enforcement Action Announcement — EDPB announcement (14 October 2025) of focus on Articles 12–14 transparency obligations for 2026.
- gdpr-info.eu – Article 28 (Processor) — Requirements for data processing agreements.
- gdpr-info.eu – Article 32 (Security of Processing) — Technical and organizational measures.
- gdpr-info.eu – Article 33 (Notification to Supervisory Authority) — 72-hour deadline for data breaches.
- gdpr-info.eu – Article 34 (Communication to Data Subject) — Communication in high-risk cases.
- gdpr-info.eu – Article 83 (General conditions for imposing administrative fines) — Penalty framework.
- EDPB – Guidelines 9/2022 on personal data breach notification — Guidelines on personal data breach notification (Version 2.0, March 2023).
- TikTok €530M fine — The Guardian (May 2025) — Ireland DPC enforcement action for unlawful data transfers to China.
- Surfshark Research: GDPR fines exceeded €1B in 2025 — Annual analysis of GDPR enforcement volume.
Related Reading
- GDPR Article 28: Processor Obligations & DPA Requirements
- GDPR Article 32: Security of Processing Requirements
- GDPR Article 33: The 72-Hour Breach Notification Rule
- GDPR Article 34: Communicating a Breach to Data Subjects
- EU Data Sovereignty vs. Residency
- NIS2: Internal Proof vs External Proof
- Subprocessor Management under GDPR Article 28
- GDPR Subprocessor Change Notices: The Article 28 Notification Workflow
- Trust Center for Legal Teams
- Continuous Monitoring
Frequently Asked Questions
What is GDPR compliance?
GDPR compliance means an organization processes personal data of EU/EEA residents in accordance with Regulation (EU) 2016/679. This includes having a lawful basis for each processing activity, implementing appropriate technical and organizational security measures, honoring data subject rights, maintaining records of processing activities, and notifying supervisory authorities within 72 hours of a data breach.
Who needs to comply with GDPR?
Any organization that processes personal data of individuals in the EU or EEA must comply with GDPR — regardless of where the organization itself is located. This includes companies based outside the EU that offer goods or services to EU residents or monitor their behavior. B2B SaaS companies are typically both data controllers (for their own customer data) and data processors (for data their customers store via the platform).
What must a Data Processing Agreement (DPA) include under GDPR Article 28?
Article 28 requires DPAs to include at minimum: subject matter and duration of processing, nature and purpose, types of personal data, categories of data subjects, processor obligations (process only on documented instructions, ensure confidentiality, implement security measures, assist with breach notification, delete data after engagement, and allow audits).
What are the penalties for GDPR non-compliance?
GDPR violations can result in fines up to EUR 20 million or 4% of annual global turnover, whichever is higher. In 2025, approximately €1.2 billion in GDPR fines were issued, including TikTok (€530M) and Meta (€479M). Data subjects also have the right to claim compensation for material and non-material damage.
How does a Trust Center help with GDPR compliance?
A Trust Center serves a dual role: as a controller, it provides a structured framework for assessing and monitoring your own data processors with documented due diligence evidence. As a processor, it demonstrates your compliance posture to your customers with publicly accessible subprocessor lists, DPA hosting, and transparent technical and organizational measures.