Technology

Data protection in tech: from your client's data to the model that uses it

Nextica Law & Tax implements GDPR compliance in technology and product companies: the lawful basis for each processing activity, processor agreements with cloud providers and the chain of sub-processors, international transfers, impact assessments when the product profiles or automates decisions, breach response, and the fit with Regulation (EU) 2024/1689 on artificial intelligence when models are involved.

In tech, data is the product. A badly built GDPR setup does not fine you on day one: it kills your contract with the first big client.

What's included

1. Mapping what data the product processes and who is controller of each processing operation, which in a company handling its customers' customers' data is almost never obvious.

2. A record of processing activities with the real purposes and legal bases, not the ones copied from another policy.

3. An impact assessment where the processing requires one by its nature, scope or technology, with the risk analysis documented.

4. The chain of processors and sub-processors

infrastructure providers, analytics tools, email, support and any third-party models integrated.

5. International transfers with their mechanism identified and assessed, provider by provider.

6. A breach and data subject rights procedure, rehearsed before it is needed and with internal deadlines shorter than the legal ones.

7. Documentation that stands up before the corporate customer, who asks for evidence long before the authority does.

DATA IS THE PRODUCT, AND THE BIG CUSTOMER AUDITS IT BEFORE THE AUTHORITY DOES

In tech, badly built GDPR compliance does not fine you on day one: it kills the contract with the first corporate customer who asks for evidence.

An impact assessment not carried out where the processing required one

it is mandatory where, by its nature, scope, context or technology, the processing is likely to result in a high risk, and in products that profile, handle sensitive data or use new technology that threshold is crossed more often than people think.

art. 35 General Data Protection Regulation

Confusing the role

when you process data on the customer's behalf you are a processor, and the obligations and contracts are different. Presenting yourself as controller in the policy and acting as processor in the contract is a contradiction the customer spots before anyone else.

arts. 4 and 28 General Data Protection Regulation

Unnamed sub-processors and transfers

adding a new provider without updating the annex or informing the customer breaches the processing agreement, and it is the first thing a supplier audit reviews.

art. 28 General Data Protection Regulation

Frequently asked questions

My client demands a DPA and a list of sub-processors. What do I need?

A data processing agreement for every provider that touches your clients' data —hosting, email, analytics, support, AI tools—, an up-to-date published list of sub-processors, a procedure for notifying provider changes, and documentation of where the data is hosted and where it is transferred. It is the first folder any corporate buyer asks for, and the first one an investor reviews.

We integrate a third-party AI model. Does anything change for data protection?

The analysis changes, not the obligation. Three questions must be answered: what personal data goes into the model and on what lawful basis, whether the provider uses it for training and what the contract says about it, and whether the use involves automated decisions or profiling that require an impact assessment. On top of that comes Regulation (EU) 2024/1689, which classifies the system by risk level and adds its own documentation duties.

Results, not names

Cases we have worked on

  • tecnologia

    Pacto de socios que desbloqueó la entrada de un inversor

Equipo Nextica

Content reviewed by

Equipo Nextica

Dirección

Meet the team

Let's talk about your company.

Tell us your situation and we'll reply within 24 working hours.

Step 1 of 2

Your data is processed according to our privacy policy.