In brief
- Regulation: GDPR.
- Any publisher processing personal data on behalf of its clients is a data processor, with no threshold.
- Sign a compliant DPA.
- Process under instruction.
- Secure (Article 32).
- Fines can reach €20 M or 4% of global annual turnover.
Regulatory deadlines
The key dates of this regulation.
May 2018
Entry into application
In forceWhat does GDPR cover?
The GDPR distinguishes between the data controller, who determines the purposes, and the processor, who acts on their behalf. The SaaS publisher is the archetypal processor: it hosts and processes data whose purposes are defined by its client.
Article 28 requires a written contract strictly governing what the processor may do, how it secures the data, and what happens to it at the end of the relationship.
Is the 'Software Publishers' sector concerned?
Any software publisher processing personal data on behalf of its clients is a data processor, with no threshold. The qualification depends neither on size nor sector, but on the reality of the processing.
The software publisher becomes a data controller, however, as soon as it defines its own purposes: product audience measurement, commercial prospecting, or training AI models on its clients' data. It then holds both capacities simultaneously, along with the corresponding obligations.
Detailed obligations
Sign a compliant DPA
Provide each client with a data processing agreement compliant with Article 28: subject matter, duration, nature and purpose of the processing, categories of data and data subjects, obligations and rights of the controller.
Process on instruction
Process data only on documented instructions from the client, and alert the client if an instruction appears to conflict with GDPR.
Secure (Article 32)
Implement appropriate technical and organisational measures: encryption, access and authorisation management, strong authentication, logging, backups and restoration testing.
Govern sub-processors.
Maintaining an up-to-date list of sub-processors (hosting providers, third-party services), subjecting them to the same obligations and notifying the client of any change.
Govern transfers outside the EU
Legally secure data transfers outside the European Union by means of standard contractual clauses and supplementary measures where necessary.
Assist the client
Assist the controller in responding to data subject rights requests, carrying out impact assessments, and notifying breaches, and notify the client without delay of any breach identified.
Sanctions & risks
Fines can reach €20M or 4% of global turnover. A non-compliant vendor exposes all of its customers in a cascade effect, making it a major contractual failure point and a recurring topic in due diligence.
On top of administrative risk comes contractual risk: clients now require guarantees (DPA, certifications, tests) and may hold the publisher liable in the event of a breach.
Common mistakes in the sector
- 1No standardised DPA. Negotiating on a case-by-case basis in the absence of a standard contract, which slows down sales and leaves gaps.
- 2Hidden sub-processors. Failing to disclose the hosting provider or third-party services, in breach of the information obligation.
- 3Unregulated transfers outside the EU. Using non-EU services without contractual clauses or supplementary measures.
- 4Deficient notification. Failing to notify the client without delay in the event of a breach.
Practical case
An HR software publisher hosts candidate data for its clients via an undeclared non-EU cloud sub-processor. During a security audit conducted by a major account, the absence of any mention of the sub-processor and transfer clauses blocks the signing of the contract. The publisher regularises the situation by declaring the sub-processor, activating standard contractual clauses, and publishing a standard DPA — now a systematic requirement for its enterprise sales.
Compliance roadmap
- 1
Map data flows. Map the data processed, its location, sub-processors, and transfers outside the EU.
- 2
Publish a standard DPA. Make a standard DPA and security documentation readily available to clients.
- 3
Maintaining the list of subprocessors. Keep the list of sub-processors and the client information mechanism up to date.
- 4
Document security. Formalise Article 32 measures in a register and keep them up to date.
- 5
Equip the notification process. Establish a procedure for detecting and notifying breaches to the client without delay.
Frequently asked questions
Yes, for its own purposes: product analytics, marketing, model training. It then combines the roles of controller and processor.
Take action on GDPR
Free assessment or a chat with an expert dedicated to software publishers.
They already trust us
See how organisations in the software publishers sector secured their compliance with DCO.