[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:the-gdpr-for-a-software-company-controller-of-your-own-data-processor-for-your-customers-and-the-five-duties-that-turn-on-size-and-data":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","the-gdpr-for-a-software-company-controller-of-your-own-data-processor-for-your-customers-and-the-five-duties-that-turn-on-size-and-data","The GDPR for a software company: controller of your own data, processor for your customers', and the five duties that turn on size and data","Regulation (EU) 2016\u002F679 reaches every software company, so the question is which duties turn on. The two roles per processing (Article 4), the record of processing that the 250-person exemption never spares a product in use (Article 30), the officer (Article 37), the impact assessment (Article 35), the representative for a company outside the Union (Article 27), the transfer grounds (Chapter V), the 72-hour and one-month clocks, and what ISO 27701 produces for each. Read from the Official Journal, with the free determination that writes it down.","2026-09-12",{"who":10,"when":11,"do":12},"Every software company that processes personal data in the Union or offers its product to people in it: controller of its own customer, prospect and staff data, and, for a SaaS, processor of the data its customers put into the product.","Applying since 25 May 2018; the breach clock is 72 hours from becoming aware, a data subject's request is answered within one month, and the record, the officer, the impact assessment and the representative turn on the day the answer that triggers them changes.","Run the free determination: nine answers give the duties as a table with the provision behind each, then keep the record of processing, it is the document every other duty rests on.","\nEvery explainer of the General Data Protection Regulation starts from the data subject. A software company meets it from the other side: as the party that holds other people's data, in two roles at once, with a set of duties that switches on and off with the size of the company and the kind of data. This is the reading from that side, provision by provision, for a company that ships or runs software in the Union. The [free determination](\u002Fgdpr\u002Fduties) asks nine questions and writes the same reading down for your case.\n\n## Two roles, per processing, not per company\n\nArticle 4(7) makes you the controller of every processing whose purposes and means you determine. Your customer relationship data, your prospect list, your staff records, the analytics on your own website: you decide why and how, so you are the controller, whatever your product does.\n\nArticle 4(8) makes you a processor for the processing you carry out on behalf of a controller. A SaaS that stores its customers' end-user data, a hosted API that receives personal data to return a result, a managed service that administers a customer's systems: for that data the customer decides, and you process on its instructions. Most software companies are therefore both, and the roles attach to the processing, not to the company. The catalogue behind the [GDPR hub](\u002Fgdpr) carries the rows for each role, and the determination lists the processor rows separately.\n\nThe processor role brings a contract. Article 28(3) requires the processing to be governed by a contract that sets out the subject matter, duration, nature and purpose, the types of data and categories of data subjects, and eight terms: processing only on documented instructions, confidentiality of the persons authorised, the security measures of Article 32, the conditions for engaging another processor, assistance with data subject rights, assistance with Articles 32 to 36, deletion or return at the end, and the information needed to demonstrate compliance, audits included. A bank customer under DORA sends [its own clauses on top](\u002Farticles\u002Fdora-for-a-software-vendor-the-article-30-contract-clauses-your-bank-customer-will-send-the-register-of-information-and-what-iso-27001-already-answers); the two sets sit side by side in the same agreement.\n\n## The record of processing, and why the 250-person exemption never spares a product in use\n\nArticle 30(1) requires each controller to maintain a record of processing activities: the name and contact details of the controller, the joint controller, the representative and the officer where there is one; the purposes; the categories of data subjects and of personal data; the categories of recipients; transfers to third countries with the documentation of safeguards where Article 49(1) is relied on; where possible the time limits for erasure; and where possible a general description of the security measures of Article 32(1). Article 30(2) requires each processor to keep the mirror record of the processing carried out for each controller.\n\nArticle 30(5) says the obligation does not apply to an enterprise employing fewer than 250 persons, and then takes it back in the same sentence: unless the processing is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data or data relating to criminal convictions. A product in use processes personal data every day of the year. That processing is not occasional, so the exemption is gone before the size of the company is counted. The record is a duty at any size for any software company with a live product, and it is the document every other duty in this article refers back to.\n\n## The data protection officer\n\nArticle 37(1) requires a data protection officer in three cases, two of which reach a private company: where the core activities consist of processing operations which, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale (point (b)), and where the core activities consist of processing on a large scale of special categories of data under Article 9 or of data relating to criminal convictions and offences under Article 10 (point (c)).\n\n\"Core activities\" is the test that decides most cases. A company whose product is behavioural analytics, ad-tech, location tracking or workforce monitoring monitors people as its business; a company that runs an invoicing product does not, however many records it holds. The officer may be a staff member or a contractor (Article 37(6)), is designated on professional qualities and expert knowledge of data protection law (Article 37(5)), and the contact details are published and communicated to the supervisory authority (Article 37(7)).\n\nWhere Article 37(1) does not require one, member state law may (Article 37(4)). Germany does: section 38 of the BDSG requires an officer from 20 persons regularly engaged in automated processing of personal data. A company selling into Germany from elsewhere is not caught by that rule; a company established there is.\n\n## The impact assessment\n\nArticle 35(1) requires a data protection impact assessment before any processing likely to result in a high risk to the rights and freedoms of natural persons, in particular using new technologies. Article 35(3) names three cases where it is required in any event: a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based; large-scale processing of special categories or criminal data; and systematic monitoring of a publicly accessible area on a large scale. The supervisory authorities publish further lists under Article 35(4).\n\nThe content is Article 35(7): a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks, and the measures envisaged to address them. Where the residual risk stays high, Article 36(1) requires prior consultation of the supervisory authority before the processing starts. For a software company the first case is the one to watch: a scoring, ranking or screening feature that produces decisions about people is a systematic and extensive evaluation whether or not anyone calls it profiling.\n\n## The representative, for a company outside the Union\n\nArticle 3(2) applies the Regulation to a controller or processor not established in the Union where the processing relates to offering goods or services to data subjects in the Union, or to monitoring their behaviour there. Where it applies, Article 27(1) requires a representative in the Union, designated in writing. Article 27(2)(a) exempts processing which is occasional, does not include large-scale special categories, and is unlikely to result in a risk. A product offered to people in the Union is not occasional processing, so a company outside the Union with customers in it will normally need the representative; the exemption is written for the company that meets the Regulation by accident, not for one that sells into it.\n\n## Transfers, and the grounds a cloud contract has to name\n\nArticle 44 allows a transfer to a third country only under the conditions of Chapter V, onward transfers included. The grounds are three: an adequacy decision of the Commission under Article 45, the one for the United States being the Data Privacy Framework decision of 10 July 2023, which covers only the companies certified under it; appropriate safeguards under Article 46, in practice the standard contractual clauses the Commission adopted on 4 June 2021; and the derogations of Article 49 for specific situations, which are not a basis for a running service. A cloud provider with European regions is still a transfer question the day support, backups or telemetry reach outside the EEA, and the record of Article 30 is where the ground for each transfer is written down.\n\n## The two clocks\n\nArticle 33(1) requires the controller to notify a personal data breach to the supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it; a later notification carries the reasons for the delay. Article 33(2) requires the processor to notify the controller without undue delay after becoming aware, which for a SaaS means the clock the customer runs starts with your message. Article 34(1) adds the communication to the data subjects where the breach is likely to result in a high risk to them.\n\nArticle 12(3) sets the other clock: information on action taken on a data subject's request is provided without undue delay and in any event within one month of receipt, extendable by two further months where necessary, taking into account the complexity and number of requests. Both clocks run from an event, not from a date, which is why they belong in the incident and request records rather than in a calendar; [NIS2 and the CRA run theirs the same way](\u002Farticles\u002Fnis2-or-cra-which-incident-clock-runs-for-a-software-company-and-what-makes-an-incident-significant), from becoming aware.\n\n## What ISO 27701 gives you, and what it does not\n\nISO\u002FIEC 27701 extends an ISO 27001 management system to privacy: Annex A lists the controls for a controller, Annex B those for a processor, and the catalogue behind the determination names, for each duty, the control whose record is the evidence in StandardOS's reading. The record of processing, the processor contract terms, the breach procedure, the transfer register and the data subject request handling all have a control behind them. The Regulation names no standard and grants no presumption of conformity: a certificate is evidence that the process exists, and the supervisory authority reads the process against the text. Article 83 sets the ceilings for getting it wrong at EUR 10 million or 2% of worldwide annual turnover for the duties of Articles 25 to 39, and EUR 20 million or 4% for the principles, the lawful bases, the data subjects' rights and the transfers.\n\nNine answers decide which of these duties turn on for your company. The [determination](\u002Fgdpr\u002Fduties) writes them down with the provision behind each line, in your language, to copy or download.\n",1789383984442]