Been going through the GDPR audit criteria for my own SaaS. Turned it into a 50-point self-audit checklist (Google Sheets). Covers: consent flows, cookie policies, DPA requirements, data subject requests, privacy policy gaps.
Happy to share the free version. Also building out a full kit -- privacy policy template, DPA template, consent flow mockups. Drop a reply if any of that is useful to you.