Your SaaS stack is also your personal-data map
A small company may say “we do not share customer data with third parties” while using a hosting provider, Microsoft 365, WhatsApp, a CRM, a booking service, backups and an external accountant.
The statement may reflect perception rather than the real architecture.
Inventory services before writing policies
Build a map of:
- hosting;
- email;
- CRM;
- booking;
- support;
- analytics;
- messaging;
- backups;
- payroll;
- accounting;
- marketing.
For each service, ask what personal data it can access and why.
Provider does not automatically mean processor
Some vendors never touch personal data. Others process it under instructions. Others may act as independent controllers for specific purposes.
Role classification should follow the real function.
Article 28 is not a generic checkbox
Where a vendor acts as a processor, review the processing agreement, security, subprocessors, deletion, assistance with rights and incident handling.
EU hosting is only one layer
Data may still be accessed through support teams, subprocessors or connected services outside the same region.
Revisit the map when tooling changes
A company can move from spreadsheets to a CRM and marketing platform in a few months. Documentation should follow the real environment, not an old template.
The goal is not “zero vendors”. The goal is visibility and governance.
Full Spanish guide: Third parties, processors and online services under GDPR.

Top comments (0)