DEV Community

LOL Pc
LOL Pc

Posted on Originally published at rgpdmalaga.com

Your SaaS stack is also your personal-data map

Your SaaS stack is also your personal-data map

Servidor conectado visualmente con servicios cloud, mensajería, correo y aplicaciones empresariales

A small company may say “we do not share customer data with third parties” while using a hosting provider, Microsoft 365, WhatsApp, a CRM, a booking service, backups and an external accountant.

The statement may reflect perception rather than the real architecture.

Inventory services before writing policies

Build a map of:

  • hosting;
  • email;
  • CRM;
  • booking;
  • support;
  • analytics;
  • messaging;
  • backups;
  • payroll;
  • accounting;
  • marketing.

For each service, ask what personal data it can access and why.

Provider does not automatically mean processor

Some vendors never touch personal data. Others process it under instructions. Others may act as independent controllers for specific purposes.

Role classification should follow the real function.

Article 28 is not a generic checkbox

Where a vendor acts as a processor, review the processing agreement, security, subprocessors, deletion, assistance with rights and incident handling.

EU hosting is only one layer

Data may still be accessed through support teams, subprocessors or connected services outside the same region.

Revisit the map when tooling changes

A company can move from spreadsheets to a CRM and marketing platform in a few months. Documentation should follow the real environment, not an old template.

The goal is not “zero vendors”. The goal is visibility and governance.

Full Spanish guide: Third parties, processors and online services under GDPR.

Top comments (0)