The GDPR (and other data privacy legislation) uses the concept of a "data controller" and a "data processor". Data controllers use a variety of data processors to deliver a service to their users.
If you ran a SAAS and used Fathom analytics, a SMTP email provider (to send password resets), a newsletter provider (for your monthly newsletter), a blog host etc. each of those would be data processors as you (the SAAS) are making the determination of where user data is going on the backend.
As a data controller, it's your responsibility to make sure that each of those services you are using is handling the data in an appropriate and safe way.
As to who gets fined if there is a data breach: the answer is likely nobody. I say this because it's not like you have a credit card on file and breach automatically means a fine. What really matters is what actions you're taking before and after a breach.
- As a data controller did you notify your users with no undue delay?
- As a data processor did you notify the SAAS with no undue delay?
- Did you identify the source of the breach? Did you take steps to remedy it?
For almost all these privacy regulations if you:
1. Take steps to protect user data/privacy like https, encryption etc.
2. Provide a mechanism to allow users to make data requests for their own identifying data
3. Notify users if there's a data breach
You would be in compliance.