Many SaaS suppliers are concerned about the changes the GDPR will impose upon their current data protection obligations, particularly in light of the uncertainties surrounding “Brexit”. SaaS suppliers should be aware that they will be obliged to comply with the new rules imposed by the GDPR from May next year and post Brexit.
Will the GDPR apply in the UK after Brexit
Regardless of the timing of Brexit and any agreement reached between the UK and the EU on the terms under which the UK will leave the EU, the GDPR will automatically apply in the UK, until UK data protection laws are amended.
GDPR applies to UK SaaS Suppliers despite Brexit
Regardless of when and how Brexit takes place or any subsequent changes made to UK data protection laws, the GDPR will still apply directly to SaaS suppliers located within the UK if:
- They offer goods or services to SaaS customers located within the EU (i.e. in any of the remaining 27 Member States); or
- They monitor the behaviour of EU data subjects;
Even though UK SaaS suppliers will no longer be located within the EU themselves after a Brexit.
GDPR will apply to non-EU SaaS Suppliers
From the 25th of May 2018 the GDPR will automatically also apply to all SaaS suppliers located outside of the EU i.e. in the USA, if:
- They offer goods or services to SaaS customers located within the EU; or
- They monitor the behaviour of EU data subjects, even though the SaaS supplier is not located within the EU.
Complying with the GDPR
The following are the main obligations that all SaaS suppliers, who are subject to data processor obligations under the GDPR, will need to comply with:
- Having specific minimum terms in a written data processing agreement with all customers;
- Keeping records of all categories of processing activities that they carry out;
- Obtaining prior written consent to the subcontracting of any data processing activities;
- Notifying customers of any breach of their obligations, without undue delay, after becoming aware of the breach;
- Appointing a data protection officer (DPO) in specific circumstances; and
- Allowing customers to choose between deletion or return of all personal data.
Fines for Breach
Data subjects will be able to claim damages directly from SaaS suppliers who breach:
- Any obligations under the GDPR; or
- Any lawful instructions of the customer.
In addition data protection authorities will be able to fine SaaS suppliers up to 4% of annual global turnover or 20m Euros (whichever is higher) for breaches of the GDPR.
Preparing for Change
The current position with regard to Brexit is unclear and subject to change. However, all SaaS suppliers supplying SaaS services to customers located in the EU need to be aware that current data protection laws will change throughout the EU on the 25th of May 2018, and/or in the UK following Brexit.
SaaS suppliers who plan to provide SaaS services to individuals located in the EU after the 25th of May 2018, need to take the following action:
- Review their existing privacy policies;
- Review the terms of existing SaaS agreements;
- Create a written data processing agreement;
- Review all internal procedures relating to data protection and security; and
- Review insurance cover limits and exclusions.
Irene Bodle is an IT lawyer specialising in SaaS, with over 14 years experience dealing with SaaS, cloud computing matters and IT law issues. If you require assistance with any SaaS agreements, cloud computing matters or any other IT legal issues please contact me at:
To register for my newsletter click here
Other related articles:
- SaaS Agreements – Brexit – EU Data Transfers to UK after Brexit
- SaaS Agreements – GDPR – The General Data Protection Regulation
- SaaS Agreements – GDPR – Local Derogations
- SaaS Agreements – GDPR – UK Data Protection Act 2018
- SaaS Agreements – GDPR – Age of Consent
- SaaS Agreements – Brexit – EU Data Transfers
- SaaS Agreements – Brexit – Legal Implications
- SaaS Agreements – Data Protection – SaaS, Brexit and the GDPR
- SaaS Agreements – Data Protection – Transfer of Data Outside the EEA
- SaaS Agreements – Data Protection – Privacy Shield Approved
- SaaS Agreements – Data Protection – Binding Corporate Rules
- SaaS Agreements – Data Protection – EU Model Clauses
- SaaS Agreements – FAQs – What is SaaS and Essential Terms to include in a SaaS Agreement
- SaaS Agreements – FAQs – What is a SLA and Essential Terms to Include in a SLA
- SaaS Agreements – Essential Element
- SaaS Agreements – Essential Elements – SLAs Explained