When might SaaS be affected?

SaaS providers should pay attention where their service stores, processes, analyses or makes available business data, customer data, operational data or connected-product data.

Even where a SaaS product is not itself a connected product, the Data Act may still be relevant through cloud switching, data-processing service obligations, customer exit rights or contractual terms.

Key SaaS risk areas

  • Customer data export and portability.
  • APIs and technical access to data.
  • Contract terms on data use and data sharing.
  • Exit, termination and migration support.
  • Use of customer data for analytics, AI or product improvement.
  • Restrictions that make switching provider difficult.

SaaS checklist

What SaaS providers should review

Data export

Can customers export their data in a structured, commonly usable format?

Contract clarity

Do your terms clearly explain data access, data use, sharing, retention and deletion?

Switching support

Can customers move to another provider without unnecessary friction or lock-in?

Connected data

Does your SaaS platform receive or process data from connected products or IoT devices?

SaaS self-check

Get your free compliance report

The checker gives SaaS providers a quick starting point before a more detailed compliance review.

Start free assessment