If your SaaS imports personal data, list its sources. The 2026 GDPR transparency check asks your customers.

Kenneth Graupner photo Kenneth Graupner Published 7 Oct 2026 AI drafted 6 min read
If your SaaS imports personal data, list its sources. The 2026 GDPR transparency check asks your customers.

Say you sell a sourcing tool to recruitment agencies in Brandenburg. This year the state's data protection authority sent those agencies a questionnaire about how they inform people about their personal data, and for data an agency did not collect from the person, GDPR Article 14 makes it tell each candidate what kinds of data it holds and where they came from 2. Thousands of the agency's candidate profiles came in through your tool. If you cannot tell the agency what your tool pulled in, from where, and who else received it, the agency's answer to its regulator reads "imported through our sourcing vendor", and your product is now named in a regulator's file.

That questionnaire is part of a check that 25 European data protection authorities started in March 2026, coordinated by the European Data Protection Board (EDPB), the body where those authorities work together 1. The authorities are now comparing the answers, and the combined results are expected at the start of 2027, so customers who were asked may still be fixing their notices. Of the fourteen authorities that had said how they take part by 7 October 2026, none named software companies as a target. I read all fourteen statements, and my conclusion is that a software company meets this check through a customer's email, if its product brings in data about people that the customer did not collect from those people.

Why would a regulator's questions reach a software vendor?

Because the questions are about data the customer often cannot describe without you.

A recruitment agency that finds a candidate through a CV database, a referral or a public profile must tell that candidate which categories of data it holds and where they came from. It has one month at the latest, and less if it contacts the candidate or sends the CV to an employer first 2. The Slovenian authority picked employment agencies that pass candidate data to many employers, which is the case where that deadline is shortest. A marketing team that buys contact details, or uses a tool that adds job titles and phone numbers to its list, owes the same notice to every person on it.

To answer, the agency has to know what its sourcing tool pulls in, from where, and which other companies receive it. Often only the vendor that built the tool knows. That the questionnaire will travel to vendors this way is my reading; no authority has said so.

A vendor can also be asked directly in two cases. If it builds its own database of people, compiling profiles or contact data for its own purposes and selling access to them, it is a controller of that data and owes the Article 14 notice to every person in the database itself 2. And Slovakia, which picked healthcare providers, says it may also question their processors.

Does your legal documentation match what you ship?

Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, then proposes the edits for your team to approve and publish.

Get started

Which organisations are being checked?

Ten of the fourteen authorities that have published a statement say who they are checking:

Authority Who it is checking
Brandenburg (DE) Recruitment agencies
Lower Saxony (DE) 15 companies, 5 municipalities
Finland Parliamentary parties
Greece Large public bodies
Italy Several sectors (below)
Malta Private sector
Slovakia Healthcare providers
Slovenia Employment agencies
Spain Public and private sample
Luxembourg Organisations in Luxembourg

Italy's sectors "include" the public sector, insurance and financial services, health and research, utilities and marketing, so its list is open-ended. The other fifteen participants have not said whom they contact.

Software is not named as a sector anywhere. A software company could still be in one of the samples defined only by country or size (Lower Saxony, Malta, Spain and Luxembourg), or in Italy's marketing sector if it sells marketing data itself. Answers can lead further: the EDPB says authorities may follow up after gathering facts 1, Italy announced "targeted follow-up", and some authorities take part through formal investigations, which can end in orders or fines.

What will the answers be measured against?

Three requirements decide whether a customer's answer holds up, and each depends on facts a vendor holds or on how a vendor writes:

  • Complete. Every item GDPR lists for the notice, including who receives the data, how long it is kept and, for data obtained from someone else, its source 2.
  • On time. For data obtained from someone else, the notice is due one month after obtaining the data at the latest, and earlier if the data is used to contact the person (at first contact) or passed to another company (at first disclosure) 2 3.
  • No hedging. The EDPB-endorsed transparency guidelines say words such as "may", "might", "some", "often" and "possible" should be avoided, and an organisation that uses them should be able to show why it could not avoid them 3. Ulf counted how often generated privacy policies use them in what to check in a generated privacy policy.

The questionnaire itself has not been published, so these three come from the law and the guidelines.

What should you have ready?

If your product brings in data about people that your customers did not collect from those people, write these answers down before a customer asks. Most of them already exist in documents you keep:

  • Data categories. Every kind of personal data your product imports about those people. Start from your data model or your import field mappings.
  • Sources. Where each kind comes from. Start from your integrations list.
  • Recipients. Every other company the data reaches. Start from your published sub-processor list, with the country each is in.
  • Retention. What your product deletes, when, and what it keeps. Start from the deletion clause in your DPA.
  • Plain wording. Write the answers without "may" or "some", because your customer will copy them into its notice.

If you build your own database of people, also check whether you have ever told the people in it that you hold their data and where you got it. If you have not, that is your own Article 14 gap.

Lawcel, the product we make, reads your pull requests and tickets and flags the changes that alter what your privacy policy or DPA has to say. The changes that make your privacy policy out of date are the same ones that make this list out of date.

FAQ

Probably not as a sector target, since none of the authorities that named sectors picked software. More likely, a customer in recruitment, health, finance or marketing will ask you for the facts its answers need.
Not as of 7 October 2026. Brandenburg's authority confirms a common questionnaire exists. The standard it measures against is GDPR Articles 12 to 14 and the EDPB-endorsed transparency guidelines.
The authorities pool their findings in the second half of 2026 and the EDPB then adopts a combined report. Finland's authority expects the results at the start of 2027.
A questionnaire only gathers facts, but the EDPB says authorities may follow up, and some take part through formal investigations, which can end in orders or fines.

References

  1. EDPB, CEF 2026: EDPB launches coordinated enforcement action on transparency and information obligations under the GDPR, 19 March 2026 - accessed 7 Oct 2026
  2. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 12, 13 and 14 - accessed 7 Oct 2026
  3. Article 29 Working Party, Guidelines on transparency under Regulation 2016/679 (WP260 rev.01), endorsed by the EDPB - accessed 7 Oct 2026

About the author

Kenneth Graupner

Kenneth Graupner

Co-founder, Chief Product Officer

Kenneth is Co-founder and CPO at Lawcel. He focuses on product strategy and on shaping workflows so legal, engineering, and GTM teams can ship continuously without treating compliance as a late-stage gate.

  • Product strategy
  • Compliance operations
  • SaaS delivery
GDPR

Remove "we may" or "possible" from your privacy policy. EU regulators call for plain language.

Search your own privacy policy for "we may". I did it to 336 published policies from Product Hunt launches and 231 of them had it. The EU data protection authorities' transparency guidance names that word, with "might", "some", "often" and "possible", as wording to avoid. Every hit is a claim about your product that somebody has to go and check.

GDPR

Scraping the whole internet is the easy case. Your small, targeted scrape is not.

The EDPB's draft Guidelines 03/2026 cover web scraping for generative AI, and they reach the team that re-uses someone else's scraped dataset, including for fine-tuning. The Article 14(5)(b) escape from telling people individually turns on whether you could contact them, so a small, recent, directly identifiable dataset is in a worse position than a web-scale crawl. Consultation runs until 30 October 2026.

Drift

Shipping every week? Five changes that put your privacy policy out of date.

Privacy policy drift is a document written once against a product that ships every week. Regulators name five changes users should hear about: reusing data you already hold, moving the contracting entity, changing how people exercise rights, adding a vendor that receives data, and sending data outside the EEA. The first has to be disclosed before you ship, and "check this page for updates" is not enough.

GDPR

Every contact you publish for GDPR data requests must be easy to use on its own

Spain's regulator fined Securitas Direct 100,000 euros for a paid 902 phone line on its camera signs, even though its privacy policy listed a free email address. It judged each route for data requests on its own. For a software product, a deletion route behind a login can fail the same test, and a request sent to support@ counts from the day it arrives.