Data protection

GDPR-compliant software and hosting in Germany: a checklist

If you use software that processes personal data, you share responsibility for using it in a compliant way. This checklist summarises the points against which a GDPR-compliant solution can be measured - regardless of the vendor.

Hosting location and third-country transfers

Hosting inside the EU - ideally in Germany - avoids the legal complexity of third-country transfers (to the USA, for instance) that require additional safeguards. Clarify where the data physically sits and who has access.

The data processing agreement

If a provider processes data on your behalf, a data processing agreement under Article 28 GDPR is mandatory. It should be available, comprehensible and ready to sign - and should name the technical and organisational measures concretely.

Technical and organisational measures

Look for demonstrable protective measures, in particular:

  • Encryption of sensitive fields (passwords, tokens, API keys) and transport encryption (TLS).
  • A role and permission model with fine-grained access control.
  • Two-factor authentication and/or single sign-on.
  • Logging of security-relevant events (an audit log).
  • A documented deletion and retention policy.

Data subject rights and export

The GDPR grants data subjects rights to information, correction and deletion. In practice it matters that data can be exported - both for those requests and for a later change of provider without lock-in.

Frequently asked questions

Is hosting in Germany enough for GDPR compliance?

The location is an important building block but not the only one. A processing agreement, technical and organisational measures, a deletion and retention policy and respecting data subject rights all belong to it.

What is a data processing agreement and when do I need one?

An agreement under Article 28 GDPR governing how a provider processes personal data on your behalf. It is required whenever a provider processes such data for you - with SaaS, for instance.

Does software have to encrypt data?

Sensitive data such as passwords, tokens and API keys should be stored encrypted and always transmitted over TLS. That is part of the expected technical measures.

How important is data export?

Very. It matters both for information and deletion obligations towards data subjects and for avoiding lock-in when changing provider.

Related in IDA

Try IDA free for 30 days

No payment details, ready in minutes - hosted in Germany.