Every explainer of the General Data Protection Regulation starts from the data subject. A software company meets it from the other side: as the party that holds other people's data, in two roles at once, with a set of duties that switches on and off with the size of the company and the kind of data. This is the reading from that side, provision by provision, for a company that ships or runs software in the Union. The free determination asks nine questions and writes the same reading down for your case.
Two roles, per processing, not per company
Article 4(7) makes you the controller of every processing whose purposes and means you determine. Your customer relationship data, your prospect list, your staff records, the analytics on your own website: you decide why and how, so you are the controller, whatever your product does.
Article 4(8) makes you a processor for the processing you carry out on behalf of a controller. A SaaS that stores its customers' end-user data, a hosted API that receives personal data to return a result, a managed service that administers a customer's systems: for that data the customer decides, and you process on its instructions. Most software companies are therefore both, and the roles attach to the processing, not to the company. The catalogue behind the GDPR hub carries the rows for each role, and the determination lists the processor rows separately.
The processor role brings a contract. Article 28(3) requires the processing to be governed by a contract that sets out the subject matter, duration, nature and purpose, the types of data and categories of data subjects, and eight terms: processing only on documented instructions, confidentiality of the persons authorised, the security measures of Article 32, the conditions for engaging another processor, assistance with data subject rights, assistance with Articles 32 to 36, deletion or return at the end, and the information needed to demonstrate compliance, audits included. A bank customer under DORA sends its own clauses on top; the two sets sit side by side in the same agreement.
The record of processing, and why the 250-person exemption never spares a product in use
Article 30(1) requires each controller to maintain a record of processing activities: the name and contact details of the controller, the joint controller, the representative and the officer where there is one; the purposes; the categories of data subjects and of personal data; the categories of recipients; transfers to third countries with the documentation of safeguards where Article 49(1) is relied on; where possible the time limits for erasure; and where possible a general description of the security measures of Article 32(1). Article 30(2) requires each processor to keep the mirror record of the processing carried out for each controller.
Article 30(5) says the obligation does not apply to an enterprise employing fewer than 250 persons, and then takes it back in the same sentence: unless the processing is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data or data relating to criminal convictions. A product in use processes personal data every day of the year. That processing is not occasional, so the exemption is gone before the size of the company is counted. The record is a duty at any size for any software company with a live product, and it is the document every other duty in this article refers back to.
The data protection officer
Article 37(1) requires a data protection officer in three cases, two of which reach a private company: where the core activities consist of processing operations which, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale (point (b)), and where the core activities consist of processing on a large scale of special categories of data under Article 9 or of data relating to criminal convictions and offences under Article 10 (point (c)).
"Core activities" is the test that decides most cases. A company whose product is behavioural analytics, ad-tech, location tracking or workforce monitoring monitors people as its business; a company that runs an invoicing product does not, however many records it holds. The officer may be a staff member or a contractor (Article 37(6)), is designated on professional qualities and expert knowledge of data protection law (Article 37(5)), and the contact details are published and communicated to the supervisory authority (Article 37(7)).
Where Article 37(1) does not require one, member state law may (Article 37(4)). Germany does: section 38 of the BDSG requires an officer from 20 persons regularly engaged in automated processing of personal data. A company selling into Germany from elsewhere is not caught by that rule; a company established there is.
The impact assessment
Article 35(1) requires a data protection impact assessment before any processing likely to result in a high risk to the rights and freedoms of natural persons, in particular using new technologies. Article 35(3) names three cases where it is required in any event: a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based; large-scale processing of special categories or criminal data; and systematic monitoring of a publicly accessible area on a large scale. The supervisory authorities publish further lists under Article 35(4).
The content is Article 35(7): a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks, and the measures envisaged to address them. Where the residual risk stays high, Article 36(1) requires prior consultation of the supervisory authority before the processing starts. For a software company the first case is the one to watch: a scoring, ranking or screening feature that produces decisions about people is a systematic and extensive evaluation whether or not anyone calls it profiling.
The representative, for a company outside the Union
Article 3(2) applies the Regulation to a controller or processor not established in the Union where the processing relates to offering goods or services to data subjects in the Union, or to monitoring their behaviour there. Where it applies, Article 27(1) requires a representative in the Union, designated in writing. Article 27(2)(a) exempts processing which is occasional, does not include large-scale special categories, and is unlikely to result in a risk. A product offered to people in the Union is not occasional processing, so a company outside the Union with customers in it will normally need the representative; the exemption is written for the company that meets the Regulation by accident, not for one that sells into it.
Transfers, and the grounds a cloud contract has to name
Article 44 allows a transfer to a third country only under the conditions of Chapter V, onward transfers included. The grounds are three: an adequacy decision of the Commission under Article 45, the one for the United States being the Data Privacy Framework decision of 10 July 2023, which covers only the companies certified under it; appropriate safeguards under Article 46, in practice the standard contractual clauses the Commission adopted on 4 June 2021; and the derogations of Article 49 for specific situations, which are not a basis for a running service. A cloud provider with European regions is still a transfer question the day support, backups or telemetry reach outside the EEA, and the record of Article 30 is where the ground for each transfer is written down.
The two clocks
Article 33(1) requires the controller to notify a personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it; a later notification carries the reasons for the delay. Article 33(2) requires the processor to notify the controller without undue delay after becoming aware, which for a SaaS means the clock the customer runs starts with your message. Article 34(1) adds the communication to the data subjects where the breach is likely to result in a high risk to them.
Article 12(3) sets the other clock: information on action taken on a data subject's request is provided without undue delay and in any event within one month of receipt, extendable by two further months where necessary, taking into account the complexity and number of requests. Both clocks run from an event, not from a date, which is why they belong in the incident and request records rather than in a calendar; NIS2 and the CRA run theirs the same way, from becoming aware.
What ISO 27701 gives you, and what it does not
ISO/IEC 27701 extends an ISO 27001 management system to privacy: Annex A lists the controls for a controller, Annex B those for a processor, and the catalogue behind the determination names, for each duty, the control whose record is the evidence in StandardOS's reading. The record of processing, the processor contract terms, the breach procedure, the transfer register and the data subject request handling all have a control behind them. The Regulation names no standard and grants no presumption of conformity: a certificate is evidence that the process exists, and the supervisory authority reads the process against the text. Article 83 sets the ceilings for getting it wrong at EUR 10 million or 2% of worldwide annual turnover for the duties of Articles 25 to 39, and EUR 20 million or 4% for the principles, the lawful bases, the data subjects' rights and the transfers.
Nine answers decide which of these duties turn on for your company. The determination writes them down with the provision behind each line, in your language, to copy or download.