The company says it uses twenty SaaS tools.
Finance says forty-one.
Engineering knows about twenty-seven.
Marketing has another nine.
Nobody has a complete list.
That is shadow SaaS.
The privacy problem begins when employees connect those tools to systems containing personal data.
A marketer adds a new enrichment tool. A product manager installs a session recorder. An engineer connects an AI coding assistant to a repository. Someone builds a Zapier workflow.
No procurement ticket. No privacy review. No DPA.
Data starts moving anyway.
Where shadow SaaS comes from
Common sources:
- Zapier / Make / n8n workflows
- Browser extensions
- Marketing pixels
- Slack integrations
- AI tools
- Analytics SDKs
- Free trial SaaS
- Developer tooling
- Spreadsheet add-ons
The important point is that vendor discovery cannot depend on asking people to remember.
Use multiple discovery signals
SSO
List applications connected to your identity provider.
Finance
Review recurring software spend.
Codebase
Search for SDKs and external endpoints.
Network
Review outbound destinations.
Browser
Inspect production pages for third-party requests.
Automation platforms
Inventory workflows that copy data from one service to another.
Then ask the privacy questions
For each discovered vendor:
- What data does it receive?
- Why?
- Is it a processor or another role?
- Where is the data processed?
- Who are the sub-processors?
- What happens when the data should be deleted?
- What contract governs the relationship?
AI tools deserve extra attention
Generative AI tools create a new shadow-SaaS problem.
An employee pastes:
“Here is our customer export. Find the users who churned.”
The security team may never see the action.
Privacy still has to consider it.
The right question is not “Did IT approve ChatGPT?”
It is:
What personal data is being sent to which model provider, under what business purpose, and with what controls?
Build a lightweight approval path
Do not create a six-week procurement process for every SaaS tool.
Create a fast privacy intake:
New vendor
↓
What data?
↓
Why?
↓
Where?
↓
Processor / other role?
↓
DPA / contract?
↓
Deletion path?
↓
Approved
Low-risk tools can move quickly.
High-risk tools get deeper review.
Detect drift after approval
Approval is not the end.
A vendor can add:
- New sub-processors
- New regions
- New AI features
- New retention practices
Your vendor inventory should have a review mechanism.
Where teams fail
Only tracking paid vendors. Free tools can still process data.
Only tracking SSO apps. Not everything uses SSO.
No codebase discovery. SDKs can send data silently.
No AI review. Employees are now externalising data through prompts.
Where Privra fits
Privra combines infrastructure, code, SaaS, and data-flow signals to surface privacy-relevant third parties and connect them to your compliance program.
The goal is not to ban tools.
It is to stop data from travelling into places nobody knows about.