GDPR for a One-Person SaaS: What You Actually Need (UK)

If your side project has a signup form, it processes personal data, and UK GDPR applies to you the same way it applies to a bank. There's no revenue or headcount threshold below which the law stops caring. What changes with size is how much of it is actually relevant to you, and most solo founders either ignore it completely or drown in generic checklists that don't distinguish the two.

The fee almost everyone misses

Most UK organisations that process personal data must pay the ICO's annual data protection fee, separately from being GDPR-compliant in general. A narrow exemption exists (mainly for processing limited to your own staff admin, advertising or accounts), but a SaaS product collecting customer emails, usage data or account details almost never qualifies. The fee is tiered:

Almost every indie SaaS is Tier 1. You self-assess and pay directly to the ICO; there's a free checker on their site if you're unsure whether the exemption applies to you.

What "compliant" actually means day to day

Strip away the consultancy language and a solo SaaS needs four things:

What's compliance theatre for a solo founder

A cookie consent banner is only required if you're setting non-essential cookies (most third-party analytics and ad trackers). If you're using privacy-first, cookieless analytics, you likely don't need one at all, check the specific tool's documentation rather than adding a banner by default because everyone else has one. Similarly, a Data Protection Officer is not required for most small SaaS businesses; that's a Tier 3-scale obligation, not a Tier 1 one.

Where this connects to the rest of going commercial

GDPR compliance, your Terms of Service, and how your payment provider is configured aren't three separate problems, they're one coherent legal picture of how your product handles customers and their data. Read the guide on Terms of Service and Privacy Policy for the consumer-facing half of this.

If working through subprocessor agreements, breach procedures and the ICO fee sounds like a distraction from actually building the product, that's the exact gap Qeetoto exists to close. We handle this alongside the rest of the compliance and legal work needed to charge money properly, in exchange for a share of revenue, while you keep your IP. Get in touch if you want a second pair of eyes on where your project actually stands.

FAQ

Do I need to register with the ICO if I have zero paying customers yet? If you're processing any personal data (even just signups on a waitlist), the fee obligation generally still applies, unless you qualify for the narrow exemption. Check the ICO's self-assessment tool; don't assume pre-revenue means exempt.

Is US-based hosting a GDPR problem? It can be, though most major US cloud providers (Vercel, AWS, Google Cloud) offer standard contractual clauses or equivalent mechanisms to make cross-border transfers lawful. Check your specific provider's data processing terms rather than assuming either way.

What happens if I just don't register and pay the fee? The ICO can issue fines for non-payment, separately from any GDPR compliance issues. It's a small, fixable admin task; leaving it undone is one of the easiest things to get flagged for.

Do I need consent to send a "your account was created" email? No. Transactional emails necessary to deliver the service you were contracted for don't need marketing-style consent. Marketing emails (a newsletter, a "check out our new feature") do.