Home / Sectors / Software and apps
Software companies usually have the best technical controls and the worst documentation. The access policy exists in someone's head, the logging captures far more than anyone intended, and the vendor list has never been written down.
The Act applies to every organisation that holds personal data. What reasonable looks like changes a great deal by sector, and this is what it changes to here.
What makes this sector different
A product company holds end user data in production, copies of it in analytics and logging, more copies in backups and staging, and fragments of it inside every third party service the product calls. Engineers understand all of this. It has usually never been recorded anywhere a non engineer could read.
There is also a second role to deal with. If you process data on behalf of your business customers, you carry obligations to them as well as to your own users, and your customers will increasingly ask you to evidence that.
Where personal data usually sits
Drawn from engagements and from the questions that come up most often on first calls in this sector.
| System | What it holds | What usually needs attention |
|---|---|---|
| Production database | End user accounts, profile data, usage records, content | Engineers hold standing production access with no logging or review |
| Analytics and logging | Device identifiers, IP addresses, session recordings, error payloads | Logs capture far more personal data than the product needs |
| Backups and staging | Full copies of live data | Test environments run on real customer data |
| Third party services | Data sent to payment, messaging, support and infrastructure providers | No written list of which vendors receive personal data |
| AI features | Prompts, uploaded files and conversations sent to model providers | Shipped before anyone read the provider's data terms |
| Customer accounts | Data your business customers put into your product | No data processing terms offered to customers who ask for them |
What we look at first here
Staging on production data. Convenient, universal, and the fastest route to an exposure that is difficult to explain.
Over-collection in logs. Error payloads routinely contain whole request bodies, which means personal data sits in a logging system nobody treats as sensitive.
Standing production access. Access that was granted during an incident two years ago and never revoked.
AI features added fast. A feature that sends user content to a model provider changes where your data goes, and the decision is often made inside a sprint.
Customers asking you to evidence compliance. Increasingly a sales blocker, and the answer takes weeks to assemble if nothing was recorded.
Which steps carry the most weight
The full sequence is on the engagement page. In this sector, these three usually do the heavy lifting.
Gap Analysis
Where you process on behalf of business customers, your obligations differ from where you decide things yourself. This gets settled first because it changes everything after it.
Discovery and mapping
Mapping runs through the codebase and the infrastructure as much as through interviews, including what the logs and the third party calls actually carry.
Compliance Support
Data processing terms you can offer customers, an internal access policy, retention and deletion that works across backups, and notices that match the product.
If you sell to customers in Europe or the United Kingdom, more than one framework applies to the same systems. We build one control set and record how it answers each, so you run one programme rather than two.
Not quite your business?
Every engagement is scoped to what you actually run, so none of these pages will match you exactly.
Thirty minutes, and you will know where you stand.
Tell us what your business runs on. We will tell you which gaps matter most, whether or not you engage us.