GDPR Software Guide

Businesses use software to manage employees, customers, payments, inventory, operations and communications. Each system may collect or process personal data, from a customer’s email address to an employee’s attendance record. Choosing the wrong platform can introduce privacy, security and operational risks that extend far beyond the software itself.

Important: This article provides general information and is not legal advice. GDPR responsibilities depend on your organisation, processing activities, jurisdiction and use of the software. Consult a qualified privacy professional when necessary.

GDPR alignment should not be treated as a badge displayed on a vendor’s website. It is a combination of product design, contractual commitments, technical controls and responsible operating practices. The software must support your organisation’s data-protection obligations, while your organisation must configure and use it appropriately.

This guide explains how to evaluate GDPR-aligned business software, what questions to ask prospective vendors and which warning signs should stop you from signing a contract.

What Does GDPR-Aligned Business Software Mean?

GDPR-aligned business software is designed and operated in a way that helps organisations process personal data consistently with the General Data Protection Regulation. It should provide suitable privacy, security and administrative controls without preventing the customer from meeting its own obligations.

The term “GDPR-aligned” is more accurate than assuming that a software product alone can make a business GDPR compliant. Compliance depends on the complete processing activity, including:

  • What personal data the organisation collects.
  • Why the data is processed.
  • The legal basis used for processing.
  • How the software is configured.
  • Who can access the information.
  • How long records are retained.
  • Which vendors and subprocessors receive the data.
  • Whether information is transferred internationally.
  • How requests and security incidents are handled.

A well-designed platform can support compliance, but it cannot select your legal basis, write every required policy or guarantee that employees use the system correctly.

Why Software Selection Matters Under the GDPR

The GDPR is technology-neutral. It applies to personal data regardless of whether that information is processed in a cloud platform, local database, spreadsheet or paper filing system. The European Commission lists staff management, payroll administration and accessing contact databases among common examples of personal-data processing.

The European Commission’s GDPR guidance identifies seven core principles:

Lawfulness, fairness and transparency Purpose limitation Data minimisation Accuracy Storage limitation Integrity and confidentiality Accountability

Your software should make it practical to follow these principles. A platform that collects unnecessary information, keeps every record indefinitely or gives all employees unrestricted access can make responsible data management difficult, even when the vendor describes the product as compliant.

1. Define Your Data and Processing Requirements First

Do not begin with a product demonstration. Begin by understanding how your organisation expects to use the software.

Document:

  • The categories of personal data involved.
  • The people whose data will be processed.
  • The purpose of each processing activity.
  • Whether special-category or otherwise sensitive data is involved.
  • The departments and roles requiring access.
  • Required retention periods.
  • Integrations with other systems.
  • Countries in which users and customers are located.
  • Reporting, export and deletion requirements.

This exercise creates a practical evaluation standard. For example, a workforce platform may need to process employee names, schedules and attendance information, while a restaurant platform may process reservation details, contact information and order history.

2. Establish the Vendor’s Role and Responsibilities

In many SaaS arrangements, the customer determines why and how personal data is processed and acts as the data controller. The software provider processes data on the customer’s instructions and acts as a processor.

Ask the vendor to explain:

  • Whether it acts as a processor, controller or both.
  • Which activities it performs under each role.
  • Whether customer data is used for product analytics.
  • Whether personal data is used to train AI models.
  • Whether optional data uses can be disabled.
  • Which subprocessors participate in service delivery.

The answer should be specific. “We respect privacy” does not explain the vendor’s legal role or how it handles customer data.

3. Review the Data Processing Agreement

A serious business-software provider should make a Data Processing Agreement, or DPA, available when it processes personal data on a customer’s behalf.

Review whether the agreement covers:

  • The subject and duration of processing.
  • The nature and purpose of processing.
  • Categories of personal data and data subjects.
  • Processing based on documented customer instructions.
  • Confidentiality obligations.
  • Security measures.
  • Use and notification of subprocessors.
  • Assistance with data-subject requests.
  • Support for breach response and compliance assessments.
  • Data return or deletion after termination.
  • Audit and information rights.
  • International transfer mechanisms, when applicable.

4. Identify Where Data Is Stored and Processed

“Hosted in Europe” can be useful information, but it is not a complete answer. Data may be stored in one country while support personnel, analytics providers, backup services or AI vendors process it elsewhere.

Ask for a complete data-location map covering:

  • Primary application databases.
  • File and object storage.
  • Backups and disaster-recovery environments.
  • Logs and monitoring systems.
  • Customer-support tools.
  • Email and notification services.
  • Analytics platforms.
  • AI and machine-learning providers.
  • Subprocessor locations.
  • Remote administrative access.

European hosting does not automatically establish GDPR compliance, and processing outside Europe is not automatically prohibited. However, transfers of personal data outside the European Economic Area require an appropriate legal basis and safeguards.

5. Examine Privacy by Design and by Default

Privacy should be part of the product architecture, not an optional setting added after deployment.

  • Optional rather than mandatory personal-data fields.
  • Privacy-friendly default settings.
  • Role-based access controls.
  • Limited administrator privileges.
  • Configurable retention periods.
  • Granular consent or preference records where relevant.
  • Pseudonymisation or anonymisation capabilities.
  • Separation of data between customers, branches or business units.
  • Controls for enabling optional analytics or AI features.

A platform should not require extensive manual work merely to reach a privacy-conscious baseline.

6. Evaluate Access and Permission Controls

Users should only have access to the information required for their responsibilities. This is especially important for platforms containing employee, customer, financial or operational records.

  • Role-based permissions.
  • Custom roles.
  • Least-privilege access.
  • Multi-factor authentication.
  • Single sign-on, if required.
  • Branch or location-level data separation.
  • Time-limited or approval-based administrative access.
  • Session controls.
  • Access reviews.
  • Prompt user deactivation.
  • Audit logs for sensitive actions.

Test permissions during the product trial. Create different user roles and verify what each role can view, export, edit and delete.

7. Assess Security Measures in Context

The GDPR requires appropriate technical and organisational measures, but it does not prescribe one universal security checklist for every organisation.

  • Encryption in transit and at rest.
  • Secure authentication and password controls.
  • Vulnerability management.
  • Independent penetration testing.
  • Secure software-development practices.
  • Infrastructure monitoring.
  • Backup protection and restoration testing.
  • Tenant isolation.
  • Incident detection and response.
  • Business continuity and disaster recovery.
  • Employee confidentiality and security training.
  • Relevant independent certifications or assurance reports.

8. Verify Support for Data-Subject Rights

Individuals may have rights relating to access, correction, deletion, restriction, objection and data portability, depending on the circumstances.

  • Search for a person across relevant records.
  • Export information in an understandable format.
  • Correct inaccurate data.
  • Delete or anonymise eligible records.
  • Restrict processing where required.
  • Record and track requests.
  • Identify data shared through integrations.
  • Apply actions to backups according to the vendor’s documented process.

9. Check Retention, Deletion and Account Closure

Indefinite retention is not a safe default. Personal data should generally be retained only as long as necessary for the relevant purpose, subject to legal or operational requirements.

  • Configurable retention policies.
  • Automated deletion or anonymisation.
  • Separate rules for different record categories.
  • Legal-hold capabilities where necessary.
  • Clear treatment of archived and deleted records.
  • Defined backup-retention periods.
  • Secure deletion after contract termination.
  • Data export before account closure.

Ask the vendor what “delete” means technically. Does the record disappear only from the user interface, or is it removed from active systems?

10. Investigate Subprocessors and Integrations

Modern SaaS platforms rarely operate alone. They may use providers for hosting, monitoring, email delivery, analytics, customer support, payments and AI processing.

  • Provider name.
  • Service provided.
  • Processing location.
  • Categories of data involved.
  • Transfer mechanism where relevant.
  • Process for notifying customers of changes.

Apply similar scrutiny to integrations your organisation enables. A core platform may be well governed while an optional plugin transfers personal data to a separate provider with different terms.

11. Ask How AI Features Use Business Data

AI-enabled software requires additional questions because prompts, uploaded documents, customer records and generated outputs may pass through separate systems.

  • Is customer data used to train shared or public models?
  • Can model training be disabled contractually and technically?
  • Which AI providers process the data?
  • Where does AI processing occur?
  • How long are prompts and responses retained?
  • Can sensitive fields be excluded or masked?
  • Are AI actions logged and reviewable?
  • Is human approval available for consequential actions?
  • Can AI features be disabled by role or workspace?
  • How does the platform prevent one customer’s data from appearing in another customer’s output?

Avoid accepting vague statements that data is “secure with AI.” The vendor should describe the relevant data flow and controls.

12. Evaluate Breach and Incident Procedures

The vendor should have a defined process for detecting, investigating, containing and communicating personal-data incidents.

  • Incident-response responsibilities.
  • Customer-notification process.
  • Contractual notification timeframe.
  • Information included in incident notices.
  • Evidence preservation.
  • Cooperation with customer investigations.
  • Security contact details.
  • Post-incident review and remediation.

Your organisation may operate under regulatory deadlines, so a vendor’s slow or incomplete notification can create additional risk.

GDPR Software Vendor Checklist

Data and Purpose

  • Does the software collect only information required for its stated purpose?
  • Can unnecessary fields and features be disabled?
  • Are data flows and processing purposes documented?

Contracts and Accountability

  • Is a suitable DPA available?
  • Are controller and processor roles clearly explained?
  • Does the vendor provide evidence supporting its privacy claims?

Hosting and Transfers

  • Are storage, backup, support and processing locations disclosed?
  • Are international transfers identified?
  • Are relevant safeguards documented?

Security

  • Does the system provide suitable authentication, encryption and access control?
  • Are sensitive actions logged?
  • Are security testing and incident-response processes documented?

Individual Rights

  • Can records be located, exported, corrected, restricted and deleted?
  • Are those functions protected by appropriate permissions?

Vendors and AI

  • Is the subprocessor list current?
  • Are AI data flows and model-training terms clear?
  • Can optional processing be controlled?

Warning Signs When Evaluating Software

Be cautious when a provider:

  • Claims its product makes every customer automatically GDPR compliant.
  • Refuses to provide a DPA.
  • Cannot identify its subprocessors.
  • Uses “European hosting” without explaining other processing locations.
  • Provides no meaningful retention or deletion controls.
  • Gives all administrators unrestricted access.
  • Cannot explain how AI features use customer data.
  • Treats security certifications as a substitute for answering questions.
  • Uses personal data for unspecified “business purposes.”
  • Has materially different claims across its contract, privacy notice and sales material.

One warning sign may be resolvable. Several together usually indicate weak governance.

How to Compare GDPR-Aligned Software Vendors

Create a weighted evaluation rather than making a yes-or-no compliance judgment. Score each vendor across areas such as:

Evaluation Area Suggested Weight
Functional suitability 20%
Privacy and data controls 20%
Security measures 20%
Contracts and accountability 15%
Data location and transfers 10%
Rights, retention and deletion 10%
Implementation and support 5%

Adjust the weighting according to risk. A system processing health information or extensive employee records may require a much stronger privacy and security weighting than a platform containing only business contact details.

Choose Software That Supports Responsible Operations

The best GDPR-aligned business software does more than publish a privacy statement. It gives organisations meaningful control over personal data throughout the information lifecycle, from collection and access to retention, export and deletion.

TechVerdi develops connected business software platforms for European operations, with a focus on secure systems, operational visibility and European data infrastructure. Businesses evaluating a platform should still assess the specific product, configuration and contractual terms against their own legal and operational requirements.

Frequently Asked Questions

The GDPR provides for certification mechanisms, but a general marketing statement that software is “GDPR certified” should be verified carefully. Ask which approved certification mechanism applies, who issued it, what scope it covers and whether it remains valid.

No. European hosting can simplify certain data-location considerations, but GDPR compliance also depends on lawful processing, transparency, data minimisation, access control, security, retention, individual rights, contracts and organisational practices.

Potentially, but the organisation must assess the transfer and ensure an appropriate legal mechanism and safeguards are in place. The correct approach depends on the destination, providers, data and circumstances.

A Data Processing Agreement defines relevant responsibilities when a processor handles personal data on behalf of a controller. It commonly covers instructions, confidentiality, security, subprocessors, assistance, deletion and audit information.

Responsibility can apply to both parties according to their roles and activities. A vendor may be responsible for its processing and contractual obligations, while the customer remains responsible for matters such as purpose, legal basis, configuration, access and how employees use the platform.

Businesses should ask whether their data is used for model training, which providers receive it, where processing occurs, how long prompts are retained, whether sensitive data can be excluded and whether AI actions can be reviewed or disabled.