# The pre-launch compliance checklist for a SaaS campaign or feature announcement
A SaaS company once shipped a pricing page redesign on a Friday afternoon. By Monday, three state attorneys general had inquiries open about a "50% off forever" banner that didn't disclose the discount only applied to year one. The campaign was pulled, the legal fees outlasted the promotion, and the marketing lead spent a quarter rebuilding trust with the legal team. None of this needed to happen. A 90-minute sign-off process would have caught it.
This lesson builds that process: who signs off, on what, and in what order, before any SaaS go-to-marketgo-to-marketThe strategy defining how you'll launch a product: target segments, channels, value proposition and coordinated action plan.View full definition → campaign or feature announcement ships.
SaaS marketing sits at the intersection of three regulatory zones that don't exist together in most other industries:
In the US, the Federal Trade Commission (FTC) enforces against deceptive or unfair marketing practices under the FTC Act, and has specifically targeted "dark patterns" (interface designs that trick users, like hard-to-find cancel buttons) in SaaS subscription flows. The FTC's 2024 "click-to-cancel" rule push targeted exactly this. See the FTC's business guidance on negative option marketing for the current requirements.
In the EU, the Digital Services Act (DSA) and the Unfair Commercial Practices Directive cover similar ground, banning dark patterns and requiring clear disclosure of automatic renewals. The EU also enforces the General Data Protection Regulation (GDPR), which governs how you describe data use in marketing copy, not just in your privacy policy.
Every pricing page, comparison chart, and "starting at $X" banner needs a legal read before publish. Specific triggers:
Practical rule: any page with a price, a percentage, or a comparison claim on it gets a legal sign-off ticket before it ships.
Web accessibility means digital content is usable by people with disabilities, including screen reader compatibility, keyboard navigation, and sufficient color contrast. The controlling standard is the Web Content Accessibility Guidelines (WCAG), currently at version 2.2, maintained by the W3C.
In the US, the Americans with Disabilities Act (ADA) has been interpreted by courts to apply to websites, and SaaS landing pages are a common lawsuit target because they're public-facing and easy to audit automatically. Plaintiffs' firms run automated scans across thousands of SaaS marketing sites looking for WCAG failures.
In the EU, the European Accessibility Act (enforceable from June 2025 across member states) extends accessibility obligations to e-commerce and many digital services, including SaaS.
Minimum pre-launch check for any new landing pagelanding pageA standalone web page built for a single campaign goal, designed to maximise conversions by removing distractions and focusing visitors on one action.View full definition → or campaign microsite:
Any feature announcement that touches customer data (a new AI assistant reading support tickets, a new integration pulling calendar data, a new analytics dashboard aggregating usage) needs privacy language reviewed before the announcement, not after.
Under GDPR, if the new feature changes *how* data is processed (a new purpose, a new third party, a new data category), you likely need a Data Protection Impact Assessment (DPIA), a required risk assessment for processing that's likely to result in high risk to individuals, before the feature ships, not just before it's marketed.
This matters a lot in 2026 because most "new AI feature" launches involve sending customer data to a model, sometimes a third-party one. Marketing copy claiming "your data is never used to train models" is a factual, auditable claim. If it's wrong, it's not a copywriting error, it's a regulatory exposure under both FTC and GDPR frameworks (California's California Consumer Privacy Act (CCPA) adds a state-level layer with similar disclosure duties).
Checklist for any AI or data-related feature announcement:
A workable pre-launch checklist has four gates, run in sequence, not in parallel, because each gate can send the campaign back to an earlier stage:
1. Claims and pricing gate (legal): every quantified or comparative claim has a source document attached.
2. Privacy gate (legal plus security/data team): every data claim matches the DPIA or privacy review.
3. Accessibility gate (design/engineering): automated and manual checks pass WCAG 2.2 AA.
4. Final marketing sign-off (marketing lead): confirms all three gates cleared, with named approvers logged.
Keep this as a shared ticket, not an email thread. A simple structure:
Campaign: [name]
Launch date: [date]
Gate 1 - Claims/Pricing: [Approver name] [Date] [Link to substantiation doc]
Gate 2 - Privacy: [Approver name] [Date] [Link to DPIA/privacy review]
Gate 3 - Accessibility: [Approver name] [Date] [Scan report link]
Gate 4 - Final sign-off: [Marketing lead] [Date]This is not bureaucracy for its own sake. A named approver on each line means when something goes wrong, you know exactly where the process broke, and you fix the process, not just the page.
Knowledge check
1. The opening story about the pricing page redesign illustrates what core lesson about SaaS marketing compliance?
2. Why does SaaS marketing face a distinct combination of regulatory exposure compared to many other industries?
3. A SaaS company is designing a subscription cancellation flow. Based on the concept of 'dark patterns' as regulators define it, which design choice would raise the most compliance concern?
4. Select ALL correct answers about why a feature announcement might trigger data privacy compliance review even if it seems purely product-focused.
Select all the correct answers.
5. Select ALL correct answers about regulatory frameworks relevant to SaaS marketing described in the lesson.
Select all the correct answers.
Companies with mature compliance processes build these gates into their project management tooling so a campaign literally cannot move to "scheduled" status without all four sign-offs logged. This is standard practice at large, publicly traded SaaS vendors precisely because they've been through FTC consent decrees or GDPR enforcement actions and rebuilt process afterward.
The cost of the checklist is small: a few hours per campaign. The cost of skipping it shows up as legal fees, regulator inquiries, and, less visibly, in customer trust. Trial-to-paid conversion language that feels sneaky gets screenshotted and shared long before any regulator gets involved.