Certix

Technology & digital

Data protection for
technology companies

Technology companies process data at scale, may operate as data processors for their clients depending on their business model, and use global sub-processors. The GDPR imposes specific obligations regarding product design, client contracts and international transfers.

Art. 25

GDPR — privacy by design

Art. 28

GDPR — data processor

SCCs

international transfers

24 h

personalised proposal

Sector challenges

General obligations for technology companies

Data controller vs data processor

SaaS companies typically act as data processors for their clients. They must be clear about which role they occupy in each processing activity in order to determine their specific obligations.

Data Processing Agreements (DPA) with clients and sub-processors

Each client for whom data is processed requires a signed DPA. Sub-processors (cloud, support tools, analytics) also require their own DPA and must be notified to clients.

International transfers

Using cloud services in the US, providing technical support from third countries, or remote access from outside the EEA constitutes an international transfer that requires adequate safeguards (SCCs or Data Privacy Framework).

Privacy by design and by default

Architecture and product design decisions must incorporate data protection from the outset. The default configuration must be the most restrictive for end users.

Cookies and product analytics

Session recording, heatmap and product analytics tools require user consent. In-app behavioural analytics are subject to cookie regulations.

Breach notification to clients

As a data processor, the company must notify its clients (data controllers) of security breaches within the DPA timeframes, typically 24–72 hours from detection.

The service

What the service includes for your technology company

RoPA (Record of Processing Activities)

Tailored RoPA: users, clients, employees, sub-processors, and own vs processor processing activities.

Information clauses

Texts for the product privacy policy, terms of service and in-app notices.

Privacy policy and legal notice

Documentation for the corporate website and the digital product.

DPA and sub-processor contracts

DPA template to offer to clients and agreements with sub-processors (cloud, SaaS tools used).

Data breach protocol

Response procedure with notification to the client and the AEPD within 72 hours.

Data subject rights management

Procedure for requests from end users and enterprise clients.

Document management platform

Access to a private platform with documents and electronic signature.

Ongoing support

Unlimited consultations. Updates on regulatory changes.

External DPO (if applicable)

As a general rule, technology companies are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will nonetheless depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.

Do you need a proposal for your technology company?

Tell us about your product type and business model. Proposal within 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection for technology companies

Is a technology company that develops software a data controller or a data processor?

It depends on the business model and the specific processing activity. When a SaaS product processes its clients' customers' data exclusively on their instructions, it may act as a data processor (art. 28 GDPR). When it collects and uses data for its own purposes (usage analytics, product improvement), it acts as a data controller. Many technology companies are both, depending on the processing activity, and some relationships may be configured as joint controllership. The exact legal status must be analysed on a case-by-case basis.

What are sub-processors and when are they required?

Sub-processors are vendors to whom the data processor sub-contracts part of the processing of its clients' data. For example, a SaaS company that uses AWS or Google Cloud to host its clients' data must notify those clients of these sub-processors and have a Data Processing Agreement (DPA) with each one. The list of sub-processors must be public or accessible to clients and kept up to date.

Can Spanish technology companies transfer data to servers in the United States?

International data transfers to the United States require adequate safeguards. Since July 2023 the EU-US Data Privacy Framework (DPF) has been in place, but its applicability depends on whether the recipient organisation is certified. For non-certified organisations, the European Commission's Standard Contractual Clauses (SCCs) are one of the available mechanisms. In any case, each transfer must be analysed individually with specialist advice.

What does privacy by design mean for software development companies?

Art. 25 GDPR establishes the principle of privacy by design and privacy by default, which applies to those who develop digital products or services. In practice, this means integrating data protection into technical decisions from the outset and configuring products with the most restrictive options by default. The AEPD has published specific guidance on how to apply this principle, which is worth consulting.

Must the technology company notify its clients of security breaches in its systems?

Yes. If the company acts as a data processor and suffers a security breach affecting its clients' data, it must notify the data controller (the client) without undue delay and, pursuant to the DPA, within the agreed timeframe (usually 24–72 hours). The data controller is responsible for notifying the AEPD within 72 hours if required.

Do product analytics cookies require consent?

Yes. Cookies used to analyse user behaviour within the platform (session recording, heatmaps, funnel analytics) using tools such as Hotjar, FullStory or Mixpanel require prior user consent. Even though the purpose is to improve the product, processing browsing data with these tools is not technically necessary to provide the service.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Technology & digital

GDPR compliance
for your technology company.

An expert analyses your product and business model and proposes the right solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal note: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.