Skip to content

SaaS, IT/ITES and e-commerce

This playbook distinguishes three activities: customer-directed processing as Processor, the provider’s own account/security/billing processing as Fiduciary, and marketplace/consumer purposes that may create additional Fiduciary roles.

ActivityTypical role questionRequired record
hosted customer contentdoes customer choose purpose/essential means?tenant instruction and prohibited reuse
product account/billingprovider’s own operational purpose?provider notice and retention
telemetry/supportstrictly service/security or product analytics?purpose, minimisation and access
marketplace fulfilmentwho decides seller/buyer data use?per-party purpose and disclosure
advertising/personalisationwho selects audience/purpose?consent/section 7 decision and partners

“We are only a processor” is not a company-wide answer.

Tenant keys on every row and event; scoped object paths and queues; tenant-aware caches/search; per-tenant connector credentials; cross-tenant negative tests; just-in-time support; export maker-checker; and tenant-specific retention/hold. Metadata used for security or billing must not silently become an advertising profile.

Maintain instruction versions, contract, subprocessors/locations, purpose boundaries, incidents, rights assistance, legal holds, deletion/return, audit evidence and exit. Each customer receives an evidence room with no access to other tenants or shared secrets. Incident propagation targets the affected customer and records the Fiduciary’s independent notification decision.

Consumer and telecom overlays

E-commerce and consumer apps apply dark-pattern review and TCCCPR where relevant. Basket, subscription, recommendation, loyalty, cookies/SDKs, marketing and account closure are separate purposes. Withdrawal/account deletion cannot be hidden behind support while grant is one tap.

Inventory hosting, backup, logs, CDN, email, support, source-control issue attachments and AI assistants. A support screenshot can contain customer PII; use session approval, redaction, recording policy, expiry and geography enforcement.

Customer-versus-provider role matrix, subprocessor catalogue and change notice, tenant data classes, support access policy, product telemetry switch, consumer purpose/notice pack, TCCCPR linkage, incident routing, deletion/return and exit export.

Freeze changes, produce a documented export with manifest, preserve only contractual/legal hold records, delete active stores/search/caches, expire backups on schedule, revoke keys and connector credentials, obtain subprocessor acknowledgements and issue a scoped certificate. “Account closed” is not proof of this chain.

  • Which provider telemetry uses create an independent Fiduciary purpose?
  • When does an e-commerce marketplace jointly determine processing with a seller/logistics partner?
  • Which Intermediary Rules apply to the service/activity?
  • Which overseas support, subprocessors and AI tooling create transfer or confidentiality risk?