B2B SaaS vendor track
A B2B SaaS vendor plays two roles: responsible party for its own data (employees, prospects, metrics) and service provider for the information its customers put in the product (s. 18.3: written contract, use limited to the mandate, notice in case of incident).
Multi-tenancy and isolation
A leak between customers is a confidentiality incident. Enforce isolation at the database level:
ALTER TABLE documents ENABLE ROW LEVEL SECURITY;
CREATE POLICY tenant_isolation ON documents
USING (tenant_id = current_setting('app.tenant_id')::uuid);
Test isolation automatically (cross-tenant integration tests) with every release.
Service data vs telemetry
Separate the data needed to perform the contract from telemetry and marketing: distinct schemas or databases, opt-in for analytics, traced consent (immutable log).
AI and LLMs
Do not train a model (internal or third-party) on customer data without the customers' explicit written consent; check AI providers' retention and training clauses.
Location and subprocessors
Hosting in a Canadian region (e.g. ca-central-1) simplifies the assessment; a US region triggers a PIA
(s. 17). Every new supplier (payments, email, analytics, AI) goes through RPRP validation, and the
subprocessor catalogue is kept up to date.
When a customer leaves
At contract end: final data export, then deletion (including backups on their cycle) and written confirmation.