forumNew topic

Data protection compliance in a new software project — where to start?

EEsmaNew member
Job title
Small business owner
Organization type
two-branch business
Joined
Oct 2024
Message
40

Doki · SEO consulting · 2025

#1

We're a small business getting a customer tracking program built. Our consultant said "there's personal data involved, look into compliance," but we don't know where to start.

The developer says "we'll handle the technical side," but I realize this isn't just a technical job.

Where should we begin?

TTuba E***Expert
Job title
Data protection consultant
Joined
Oct 2023
Message
158

Doki · Backup setup · 2024

Most Helpful#2

You're right, it's not just a technical issue. I'm outlining a general roadmap below; please remember to consult the legislation and your advisor for your specific situation.

The first step is an inventory. What personal data are you processing, for what purpose, based on which legal ground; where is it stored, who has access, how long is it kept, and who is it shared with. No step taken without this table will be sound.

The second step is purpose limitation and data minimization. The most common mistake I see in software projects is collecting more fields than necessary "just in case." Data not collected is data that doesn't need protecting. Every field in the form must have a justification.

The third step is disclosure and explicit consent if required. When and how these are obtained is part of the interface; it's not a checkbox added later. That's why you need to talk to the developer early on.

The fourth step is retention and destruction. How long data is kept and what happens after that period must be written down and reflected in the software. A destruction policy remains on paper in a system without a delete function.

The fifth step is data subject requests. When someone asks for their data or requests deletion, it must be defined who handles it, within what timeframe, and through which channel. Specify in the requirements whether the software supports this.

Finally, data processing clauses should be added to the contract you sign with your developer; if your supplier has access to the data, the framework of this relationship must be in writing.

NNergisMember
Job title
Compliance Officer
Joined
Jan 2024
Message
104
#3

I agree with Tuba's framework, I'd like to add two points from an implementation perspective.

First, do not use real data in test environments. Copying production data during software development is very common and creates a copy not visible in your inventory. Add a clause to the requirements stating "masked data is used in test environments."

Second, access logs. Keeping records of who accessed which record and when is necessary for both compliance and incident investigation. This is a feature that is hard to add to the software later; request it from the start.

BBarış Y***Expert
Job title
Backend developer
Organization type
boutique agency
Joined
Jun 2023
Message
296
#4

I'll write down the technical implementations from a developer's perspective, you can put them as items in the requirements.

Encrypted data transfer (i.e., HTTPS across the entire site) and encryption of sensitive fields at rest. Passwords should never be stored in a reversible way, they must be kept using hashing functions.

Role-based access: not every user should see every record. In small teams, people say "we all see everything anyway," then the team grows and no one goes back to clean it up.

Deletion must actually delete. In many systems, a deleted record is just hidden. If that's the requirement, fine, but it should be a conscious choice.

And access logs must be immutable by the user. If there's an admin account that can delete its own tracks, those logs have no evidentiary value.

EEsmaNew member
Job title
Small business owner
Organization type
two-branch business
Joined
Oct 2024
Message
40

Doki · SEO consulting · 2025

#5

Thank you so much, I forwarded these points directly to the developer.

We started rolling out the inventory part this week too, already found two unnecessary form fields.

ÜÜlkü S***MemberCommunity member
Joined
Oct 2024
Message
118
#6

Theres a trap here let me mention it. Forgotten test environments are more often the entry point than live systems.

Correct me if I'm wrong.

GGökhan Ç***Member
Job title
Secretary
Sector
Catering
Organization type
medium-sized business
Joined
Jan 2023
Message
323
#7

thanks that was the answer I was looking for then hasty decisions become decisions you have to fix six months later.

solutons that work at a small scale collapse when you grow; I learned this late. if you have questions, write them; I'll answer as best I can.

HHasan K***MemberCommunity member
Joined
Apr 2023
Message
221
#8

Let me clarify the technical side... I mean everything goes well for the first three months; problems arise in the fourth.

Start with a small trial; don't commit to everything at once. Of course it varies if your situation is different.

EEfe K***Expert
Job title
Field sales representative
Sector
Chemistry
Organization type
8-person team
Joined
Apr 2024
Message
136
#9

Saved.

AAyşe T***Member
Job title
Administrative manager
Sector
Plastic
Organization type
two-branch business
Joined
Jan 2023
Message
181
#10

I went through the same thing two years ago. The biggest time-waster for us was not knowing who had the final say.

This is my opinion, I'm not claiming it's absolute truth.

RRamazan Y***MemberCommunity member
Joined
Sep 2023
Message
105
#11

I'll try it.

İİbrahim B***Member
Job title
Production planning
Sector
Livestock
Organization type
chain store
Joined
Feb 2024
Message
24

Doki · Log management setup · 2024

#12

Noted, thanks.

FFatma G***Member
Job title
Content Editor
Sector
Energy
Organization type
boutique agency
Joined
Aug 2024
Message
21
#13

could you elaborate on that? having backups accessible on the same network and with the same identity makes them part of the target.

just because everyone does it doesnt mean its right. thats all sorry if I went on too long.

HHande T***Member
Job title
Data entry clerk
Sector
Food wholesale
Organization type
workshop
Joined
Apr 2025
Message
62
#14

This thread is archived. Everything goes well for the first three months; problems arise in the fourth.

Proven by experience.

İİlknur Y***VeteranCommunity member
Joined
Jul 2022
Message
3
#15

The opposite happened to me, that's why I'm writing. Don't rely on a single measure; go layer by layer.

Solutions that work at a small scale collapse when you grow; I learned this late. If I were you, I'd go this route.

DDeniz B***Expert
Job title
Administrative manager
Sector
Jewelry
Organization type
family business
Joined
Jul 2024
Message
6
#16

This is exactly what we experienced. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

This is my opinion, I'm not claiming it's absolute truth.

EElif K***Member
Job title
Customer Relations Manager
Sector
Logistics
Organization type
20-person company
Joined
Feb 2023
Message
74
#17

This approach has a cost, which isn't discussed. Your time to detect an issue directly determines its cost.

Your time to detect an issue directly determines its cost. Good luck with that.

EEmre Ö***Member
Job title
Production planning
Sector
IT services
Organization type
40-person manufacturing company
Joined
Nov 2023
Message
251

Doki · Penetration test · 2023

#18

Noted thanks. Just because everyone does it doesnt mean its right.

Just leaving this note, it might be useful.

RRecep K***Member
Job title
Customer service representative
Sector
Leather
Organization type
family business
Joined
May 2024
Message
1
#19

I'm curious too.

RRıdvan K***MemberCommunity member
Joined
Oct 2024
Message
2
#20

Let me speak from the other side; I'm on the supplier side. Payment information changes are never verified through the channel they came from.

Reply