What's your beef with using "a lot of SaaS services, with no on-premises solution"? Why waste money by locking it into on-premises hardware?
How do you guarantee that the SaaS you chose is enforcing the privacy of the data you're paying them to process?
If supporting GDPRs is a requirement for having European B2B customers, SaaS providers are going to start certifying against and architecting around that.
https://aws.amazon.com/compliance/gdpr-center/ https://aws.amazon.com/blogs/security/aws-and-the-general-da...