In the same way that AWS wasn't originally certified for government work, and then developed GovCloud: they realized there was a lot of money in it.
If supporting GDPRs is a requirement for having European B2B customers, SaaS providers are going to start certifying against and architecting around that.
How do you guarantee that the SaaS you chose is enforcing the privacy of the data you're paying them to process?