← Back to blog

The 7 Things Your SaaS Privacy Policy Must Say (GDPR Art. 13)

·4 min read·ComplyScan Team

The 7 Things Your SaaS Privacy Policy Must Say (GDPR Art. 13)

"We respect your privacy" is not a privacy policy. Under GDPR Article 13, a privacy policy is a list of specific disclosures — and if any of the seven below are missing, you have a compliance gap that a buyer's lawyer will document in week two of due diligence.

What Article 13 actually requires

When you collect personal data, you must give the data subject — your user — the following information, in a clear and plain way:

  1. Who you are. The identity and contact details of the controller (you, the SaaS). An email like privacy@yoursaas.com is the minimum.
  2. What you collect and why. The categories of personal data and the purpose of processing for each. "Marketing" is a purpose; "analytics" is a purpose. Vague purposes fail.
  3. The legal basis. For each purpose, the GDPR legal basis — consent, legitimate interest, contract, or legal obligation. If you rely on legitimate interest, name it.
  4. Who you share it with. Third-party processors and recipients — your hosting provider, payment processor, analytics tool, email service. Generic "trusted partners" language fails.
  5. Cross-border transfers. If data leaves the EU/EEA, you must say where it goes and what safeguards apply — Standard Contractual Clauses, an adequacy decision, or BCRs. Silence on this is the most common finding.
  6. How long you keep it. Retention periods, or the criteria used to determine them. "As long as necessary" is not a period.
  7. Their rights. The right to access, rectify, erase, restrict, port, and object — plus how to exercise them and how to complain to a supervisory authority.

The ones buyers actually flag

In our scan data, three of the seven show up as findings more than the others:

Cross-border transfers (Art. 13(1)(f)). If your SaaS is hosted on AWS us-east-1, uses Stripe (US), and sends email through Postmark (US), you're transferring EU user data to the US — and you need to say so, naming SCCs as the mechanism. Many policies either omit this entirely or say "we may transfer data internationally" without naming the safeguard. Both fail.

Retention (Art. 13(2)(a)). "We keep data for as long as your account is active" is not a retention period. Buyers want to see per-category retention — e.g., "account data: until 30 days after deletion request; server logs: 90 days; billing records: 7 years (tax law)."

The legal basis (Art. 13(1)(c)). Most policies list purposes but not legal bases. If you process analytics on the basis of legitimate interest, say so. If you process marketing email on the basis of consent, say so — and make sure that consent is actually captured.

A template you can adapt

Here's the minimum structure that passes an Article 13 audit:

## Who we are
[Company name], [address], [email]. DPO/contact: [email].

## What we collect and why
- Account data (name, email) — to provide the service. Basis: contract.
- Usage analytics (pseudonymous) — to improve the product. Basis: legitimate interest.
- Marketing email — to send updates. Basis: consent (you can withdraw anytime).

## Who we share it with
- [Hosting provider] — server hosting.
- [Payment processor] — billing.
- [Analytics tool] — product analytics.
We do not sell your data.

## International transfers
Some processors are located outside the EU/EEA ([list countries]).
We transfer data on the basis of Standard Contractual Clauses.

## How long we keep it
- Account data: until account deletion + 30 days.
- Server logs: 90 days.
- Billing records: 7 years (tax retention).

## Your rights
You have the right to access, correct, delete, restrict, port, and object.
To exercise these, email [email]. You can also complain to your local
data protection authority.

That's it. It's not glamorous. It's not 4,000 words of legalese. But it covers all seven Article 13 disclosures, and a buyer's lawyer reading it has nothing to flag.

The meta-requirement: plain language

Article 13 also requires the policy be "concise, transparent, intelligible, and easily accessible." This is why 4,000-word policies written by a lawyer for other lawyers fail the smell test. A real user has to be able to understand it. If your privacy policy is longer than your terms of service, you've lost the plot.

Check yours in 60 seconds

Run a free scan and we'll check your privacy policy page against all seven Article 13 disclosures — and tell you exactly which sentence to add to close each gap. Most policies are one afternoon's work to fix. The problem is knowing what's missing.

Now you do.

Run a free GDPR scan on your SaaS — 60 seconds to a graded report.

Scan free →