2026-09-05
GDPR for a small office: client data in online tools
GDPR for a small office using online tools: controller vs processor, when you need a data processing agreement, EU hosting and purpose limitation in practice.
When your office puts client data into an online tool, the GDPR picture is usually this: your office is the controller, the tool is your processor, and the relationship must be covered by a data processing agreement. EU hosting keeps the data inside the simplest legal territory, and purpose limitation means the tool uses the data for your job and nothing else. This is practical orientation, not legal advice.
Controller or processor: which is your office?
The GDPR defines the two roles in Article 4 (gdpr-info.eu/art-4-gdpr/). The controller determines the purposes and means of processing personal data: it decides why the data is processed and, in essence, how. The processor processes personal data on behalf of the controller: it executes, under instructions, for someone else’s purpose.
For a small office the mapping is straightforward. You decided to collect the client’s ID data to prepare a contract, so for that data you are the controller. The online tool that reads the scan and fills the document did not decide anything; it processes the data because you sent it, for your purpose. It is your processor. This is not a technicality: the controller carries the primary responsibility toward the client, which is why you are entitled to be demanding about what the processor does. Choosing tools carefully is not paranoia. Under the GDPR it is literally your job.
Do you need a data processing agreement?
Yes. Article 28 of the GDPR (gdpr-info.eu/art-28-gdpr/) requires that processing by a processor be governed by a contract, the data processing agreement, and it requires the controller to use only processors that provide sufficient guarantees of appropriate technical and organisational measures. A serious tool aimed at professional users offers a DPA as a standard document; needing to ask twice for one is a signal in itself.
- Processing only on your documented instructions, not for the provider’s own purposes.
- Confidentiality obligations on the people processing the data.
- Security measures appropriate to the risk.
- No sub-processors without authorisation, so the data cannot be quietly passed down a chain you have never seen.
- Deletion or return of the data at the end of the service.
- Cooperation with audits and with your own GDPR obligations, such as breach notification.
Why does EU hosting matter?
Because the GDPR restricts transfers of personal data outside the EU and EEA: such transfers are lawful only through specific mechanisms such as adequacy decisions or standard contractual clauses, and those mechanisms are exactly the part of the regime that has been repeatedly litigated and revised. A small office has no capacity to track that. Data stored and processed on servers inside the EU never enters that discussion, which turns a hard legal question into one you do not need to ask. When you evaluate a tool, look for a plain statement of where the data is stored, not just where the company is registered: the two can differ.
Purpose limitation in practice
Purpose limitation is the GDPR principle, in Article 5 (gdpr-info.eu/art-5-gdpr/), that personal data collected for one purpose must not be reused for incompatible ones. For an office using online tools it reduces to one question to ask every provider: is my clients’ data used for anything besides doing my work? The answer you want covers analytics, product improvement and, increasingly, model training. Consumer tools often reserve broader rights in their default settings than business tiers do, so the account type and its settings matter as much as the brand name. If the client’s data helps improve a product the client never chose, that is a second purpose the client never agreed to.
A checklist before you upload client data
- Where is the data stored? You want a named region, ideally the EU, in writing.
- Is there a DPA you can actually download and countersign?
- Is the data used for anything besides providing the service to you, including training?
- Can data be deleted, and what happens to it when you close the account?
- Who inside the provider can access it, and is transport encrypted?
- Does the tool need the data at all? The cheapest compliance is not sending data a task does not require.
The short version
- Your office is the controller; an online tool handling your client data is your processor. The definitions live in Article 4 GDPR.
- Article 28 requires a data processing agreement: documented instructions, confidentiality, security, controlled sub-processors, deletion, audits.
- EU hosting sidesteps the shifting rules on international transfers; ask where the data physically lives.
- Purpose limitation in one question: is client data used for anything besides my work? Get the answer in writing, and prefer tools that answer it without hesitation.
See it on your own documents
Your first 50 fills are free. Upload a document you already use and the materials you have, and download the finished file.