Art.6
Lawfulness of processing
Requires a valid lawful basis (consent, contract, legitimate interest, etc.) before any personal data is processed.
Why it matters for SaaS exits
If a SaaS processes user data without identifying a lawful basis, the entire data pipeline is unlawful. Buyers treat 'we haven't determined our Art.6 basis' as a deal-killer because it means retroactive consent may be required — which is technically impossible for already-collected data.
What we scan for
We scan the privacy policy for explicit statements of legal basis (the words 'consent', 'contract', 'legitimate interest', 'legal obligation'). Policies that omit this are flagged — it's the #1 GDPR gap we find in SaaS for sale.
Automated checks (0)
No automated checks map to this article yet.
Buyer due-diligence checklist
- ▸Ask: 'What is your Art.6 lawful basis for each processing activity?'
- ▸Check if the privacy policy mentions 'legitimate interest' — and if so, is there an LIA (legitimate interest assessment)?
- ▸Verify consent is used for non-essential cookies, not silently assumed.
Run this scan on your site
See exactly where your site stands on Art.6 before a buyer asks.
Scan free →