TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: GDPR for CMS SaaS app?

2 pointsby going_to_800about 7 years ago
Let&#x27;s say you have a SaaS where your customers can create mini-websites which have sign up pages, members area, etc.<p>MY question, what is the SaaS for the data of those users who sign up on the customers&#x27; &quot;mini-portals&quot;?<p>Is it a processor or a controller? The SaaS customer can customize pages, send emails etc...so it looks like the controller is the customer and the SaaS is just the processor, but after talking with some lawyers I&#x27;m not so sure about that.<p>What do you think?

2 comments

smelabout 7 years ago
Both I think you&#x27;re responsible for your scope and also customers if they have access to APIs or export feeds.<p>Any data about final users should be available and controlled via consentement mgt ui
termsfeedabout 7 years ago
This ICO guide can help know the difference between the data controller and the data processor:<p><a href="https:&#x2F;&#x2F;ico.org.uk&#x2F;media&#x2F;for-organisations&#x2F;documents&#x2F;1546&#x2F;data-controllers-and-data-processors-dp-guidance.pdf" rel="nofollow">https:&#x2F;&#x2F;ico.org.uk&#x2F;media&#x2F;for-organisations&#x2F;documents&#x2F;1546&#x2F;da...</a>