SaaS, IT/ITES and e-commerce
This playbook distinguishes three activities: customer-directed processing as Processor, the provider’s own account/security/billing processing as Fiduciary, and marketplace/consumer purposes that may create additional Fiduciary roles.
Role boundary
Section titled “Role boundary”| Activity | Typical role question | Required record |
|---|---|---|
| hosted customer content | does customer choose purpose/essential means? | tenant instruction and prohibited reuse |
| product account/billing | provider’s own operational purpose? | provider notice and retention |
| telemetry/support | strictly service/security or product analytics? | purpose, minimisation and access |
| marketplace fulfilment | who decides seller/buyer data use? | per-party purpose and disclosure |
| advertising/personalisation | who selects audience/purpose? | consent/section 7 decision and partners |
“We are only a processor” is not a company-wide answer.
Multi-tenant controls
Section titled “Multi-tenant controls”Tenant keys on every row and event; scoped object paths and queues; tenant-aware caches/search; per-tenant connector credentials; cross-tenant negative tests; just-in-time support; export maker-checker; and tenant-specific retention/hold. Metadata used for security or billing must not silently become an advertising profile.
Processor plane
Section titled “Processor plane”Maintain instruction versions, contract, subprocessors/locations, purpose boundaries, incidents, rights assistance, legal holds, deletion/return, audit evidence and exit. Each customer receives an evidence room with no access to other tenants or shared secrets. Incident propagation targets the affected customer and records the Fiduciary’s independent notification decision.
Consumer journeys
Section titled “Consumer journeys”E-commerce and consumer apps apply dark-pattern review and TCCCPR where relevant. Basket, subscription, recommendation, loyalty, cookies/SDKs, marketing and account closure are separate purposes. Withdrawal/account deletion cannot be hidden behind support while grant is one tap.
Cross-border and support
Section titled “Cross-border and support”Inventory hosting, backup, logs, CDN, email, support, source-control issue attachments and AI assistants. A support screenshot can contain customer PII; use session approval, redaction, recording policy, expiry and geography enforcement.
Minimum configuration
Section titled “Minimum configuration”Customer-versus-provider role matrix, subprocessor catalogue and change notice, tenant data classes, support access policy, product telemetry switch, consumer purpose/notice pack, TCCCPR linkage, incident routing, deletion/return and exit export.
Sample exit
Section titled “Sample exit”Freeze changes, produce a documented export with manifest, preserve only contractual/legal hold records, delete active stores/search/caches, expire backups on schedule, revoke keys and connector credentials, obtain subprocessor acknowledgements and issue a scoped certificate. “Account closed” is not proof of this chain.
Open counsel questions
Section titled “Open counsel questions”- Which provider telemetry uses create an independent Fiduciary purpose?
- When does an e-commerce marketplace jointly determine processing with a seller/logistics partner?
- Which Intermediary Rules apply to the service/activity?
- Which overseas support, subprocessors and AI tooling create transfer or confidentiality risk?