Art.28
Processor obligations
When a SaaS shares user data with third-party processors (analytics, email, payments), a written Data Processing Agreement is required.
Why it matters for SaaS exits
Buyers check if the seller has DPAs with every processor (Stripe, GA, Intercom, etc.). Missing DPAs mean the seller is personally liable for processor breaches — a hidden liability buyers price into the deal.
What we scan for
We detect third-party trackers and services (Google Analytics, Facebook Pixel, Stripe, Intercom) from network requests, then check if the privacy policy lists them as processors. Unlisted processors are a finding.
Automated checks (0)
No automated checks map to this article yet.
Buyer due-diligence checklist
- ▸Request the list of all sub-processors (third parties with data access).
- ▸Verify DPAs exist for each sub-processor — ask to see at least the Stripe and analytics ones.
- ▸Check if the privacy policy names the key processors, not just 'we use third-party services'.
Run this scan on your site
See exactly where your site stands on Art.28 before a buyer asks.
Scan free →