[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-gdpr::en":3,"gloss-cluster-gdpr::en":20,"gloss-next-gdpr::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"gdpr","saas","GDPR (General Data Protection Regulation)","The General Data Protection Regulation (GDPR) is the European Union's comprehensive data-privacy and data-protection law, in force since May 2018, that governs how any organization — regardless of where that organization itself is based — collects, processes, stores, and protects the personal data of individuals located in the EU\u002FEEA. GDPR is extraterritorial by design: a SaaS company headquartered in the US or elsewhere is still bound by GDPR the moment it has EU users or customers, and non-compliance carries real teeth — fines up to €20 million or 4% of global annual revenue, whichever is higher, for the most serious violations. For SaaS builders, GDPR compliance touches product and engineering decisions directly, not just legal paperwork: it requires a documented lawful basis for every category of personal data processed (consent, contractual necessity, legitimate interest, etc.), explicit and granular consent for non-essential tracking\u002Fcookies (driving the ubiquitous cookie-consent banners), a \"right to erasure\" (users can request their personal data be deleted, requiring engineering to actually support hard-deleting or anonymizing user records on request, not just soft-deleting), a \"right to data portability\" (users can request an export of their data in a machine-readable format), breach notification obligations (a reportable breach must typically be disclosed to regulators within 72 hours), and a formal Data Processing Agreement (DPA) with every sub-processor (e.g., your hosting provider, your email-sending service, your analytics tool) that touches EU personal data on your behalf. Many SaaS companies designate an EU data-residency option (hosting EU customer data specifically in EU-region infrastructure) as a paid enterprise feature to simplify compliance for privacy-sensitive customers. Concrete worked example: a SaaS company receives a GDPR erasure request from an EU user who canceled their subscription 8 months ago. Engineering must locate every system holding that user's personal data — the primary database, the CRM, the analytics platform (Mixpanel\u002FAmplitude), backups, and the email-marketing tool — and either hard-delete or fully anonymize each record within the required response window (typically one month under GDPR), while retaining any data legally required for tax\u002Faccounting purposes under a documented separate lawful basis. This is exactly why GDPR-conscious SaaS architectures build \"delete this user's data everywhere\" as a first-class, testable engineering capability from day one, rather than a manual scramble triggered by the first real request. GDPR was also the template many other jurisdictions have since followed — California's CCPA\u002FCPRA, Brazil's LGPD, and similar laws in dozens of other countries share the same core rights (access, deletion, portability) with regional variations, meaning a SaaS company that builds genuinely GDPR-compliant data infrastructure once is usually 80% of the way to compliant with most other major privacy regimes it will eventually need to satisfy as it expands internationally.","GDPR is the EU's comprehensive data-privacy law, governing how any company handling EU residents' personal data must collect, process, and protect it.",null,[11,14,17],{"slug":12,"name":13},"multi-tenant","Multi-Tenant",{"slug":15,"name":16},"sla","Service-Level Agreement (SLA)",{"slug":18,"name":19},"soc-2","SOC 2",[21,25,29,32,35,38,41,45,48,51,54,57],{"slug":22,"category":5,"name":23,"updated_at":24},"activation","Activation","2026-08-24T02:46:36+00:00",{"slug":26,"category":5,"name":27,"updated_at":28},"aha-moment","Aha Moment","2026-08-24T02:46:37+00:00",{"slug":30,"category":5,"name":31,"updated_at":28},"annual-contract-value","Annual Contract Value (ACV)",{"slug":33,"category":5,"name":34,"updated_at":24},"api-first","API-First",{"slug":36,"category":5,"name":37,"updated_at":24},"arpa","Average Revenue Per Account (ARPA)",{"slug":39,"category":5,"name":40,"updated_at":24},"arr","Annual Recurring Revenue (ARR)",{"slug":42,"category":5,"name":43,"updated_at":44},"auto-renewal-clause","Auto-Renewal Clause","2026-08-24T02:46:38+00:00",{"slug":46,"category":5,"name":47,"updated_at":44},"build-vs-buy","Build vs. Buy",{"slug":49,"category":5,"name":50,"updated_at":28},"burn-multiple","Burn Multiple",{"slug":52,"category":5,"name":53,"updated_at":44},"burn-rate","Burn Rate",{"slug":55,"category":5,"name":56,"updated_at":24},"cac","Customer Acquisition Cost (CAC)",{"slug":58,"category":5,"name":59,"updated_at":24},"cdn","Content Delivery Network (CDN)"]