Cloud data security: what to ask a provider
Ten questions, with the GDPR article behind each, to ask any cloud software before you store your customers' data in it.
Héctor RedondoCEO and founder of BAI Business
Contents
> Declaration of interest: BAI Business offers a cloud platform that stores customer data and publishes this article. It is signed by Héctor Redondo, CEO and founder of BAI Business. This is not legal advice: confirm your case with your lawyer or your data protection officer.
Today I want to talk about what to ask a provider before storing your customers' data in cloud software. It is the step almost nobody takes and the one that weighs most on the day something goes wrong.
Before signing up, ask the provider in writing for ten things: the data processing agreement, where the data is hosted, which other providers touch it, which security measures it applies, how and when it tells you about a breach, how it makes backups and how long recovery takes, who on your team sees what, what happens to your data if you leave, whether you can audit it and how it helps when a customer asks for theirs to be deleted. An answer given by word of mouth, with no paper, does not count.
Why you are the one who has to ask
If you store your customers' data in software, you are the controller and the provider is your processor. The General Data Protection Regulation (GDPR) requires you to choose "only a processor that provides sufficient guarantees" to implement appropriate technical and organisational measures (article 28.1). That guarantee is not presumed: it is requested and kept. According to the INE, 44.3% of companies with 10 or more employees pay for cloud services (first quarter of 2025), so the question is yours, and almost everyone's.
The ten questions
| No. | Question | What the GDPR says | What answer you want |
|---|---|---|---|
| 1 | Is there a data processing agreement? | Processing by the processor is governed by a contract that sets the subject matter, duration, nature, purpose, type of data and categories of people (art. 28.3) | A document you can sign, not a sentence in the general terms |
| 2 | Do you process my data only on my instructions? | The processor processes the data "only on documented instructions" from the controller (art. 28.3.a) | Yes, written into the contract |
| 3 | Where is the data hosted and is it transferred outside the EU? | Transfers to a third country or an international organisation follow their own rules (art. 28.3.a and chapter V) | Country and hosting provider, and what safeguard covers any transfer |
| 4 | Which other providers touch my data? | The processor does not engage another without prior written authorisation, specific or general, and informs of changes (art. 28.2) | List of sub-processors and prior notice of changes |
| 5 | Which security measures do you apply? | Measures appropriate to the risk, which may include pseudonymisation and encryption, confidentiality, integrity, availability and resilience, and regular testing (art. 32.1) | Encryption, access control, logs and tests described; an approved code of conduct or certification can help demonstrate it (art. 32.3) |
| 6 | How and when do you tell me about a breach? | The processor notifies the controller "without undue delay" (art. 33.2), and you must notify the authority, where required, within 72 hours at most (art. 33.1) | A notice period in the contract, much shorter than 72 hours |
| 7 | Do you make backups and how long does recovery take? | You must be able to restore availability and access "in a timely manner" after an incident (art. 32.1.c) | Backup frequency, where they are kept and a recovery time |
| 8 | Who on my team sees what? | Anyone acting under the controller's authority and with access to data processes it only on the controller's instructions (art. 32.4) | Users with permissions by role and a log of who changed what |
| 9 | What happens to my data if I leave the service? | At your choice, the processor deletes or returns all the data at the end and deletes the copies (art. 28.3.g) | Export in an open format and confirmed deletion |
| 10 | Can I audit you and do you help with my customers' rights? | The processor provides the information needed to demonstrate compliance and allows audits (art. 28.3.h), and assists you with data subjects' requests (art. 28.3.e) | A written procedure, with deadlines |
Answers that should worry you
- "We comply with the GDPR." Without the agreement from question 1 and concrete answers to the rest, it is a sentence.
- A certification with no scope. A certification is useful if it covers the service you are buying, not just the provider's office.
- They cannot say where the data is. If they cannot name the country, that is a bad sign.
- No way to take your data out. If you cannot export it, it is not entirely yours.
Imagine a renovation firm with three hundred customers in a shared spreadsheet that decides to move them to cloud software. Before uploading anything, it emails the ten questions and files the answers with the contract. A year later a customer asks for their data to be deleted and the firm has at hand who handles it and how. (An invented example, not a real customer.)
When you do not need this much
If the tool stores nobody's personal data (a calculator, a file converter), you do not need a processing agreement. If it stores health data, children's data or other special categories (article 9 of the GDPR), this list is not enough: get advice before you start.
What we have built at BAI
According to what we publish on our website, BAI asks permission by purpose before storing anything, deletes data on request while keeping invoices for as long as the law requires, and keeps signatures with their trail. The AI assistant leaves each change pending until a person with permission confirms it and can be switched off with a switch; the receptionist says it is an artificial intelligence and asks permission before saving data or booking; and in tasks each board is private or shared with whoever you choose.
What this article does not tell you about BAI is where the data is hosted, which certifications it has or which processing agreement it offers, because it is not on the pages we publish and I will not state it in passing. Ask BAI the same ten questions you ask any other provider and demand the answers in writing.
What to do now
Pick the software where you store the most customer data today and send it the ten questions. The answers, or the lack of them, already tell you a lot. If you are starting to put the rest of the business in order, see how to digitalise a small business. And to know how long to keep your customers' data, there is GDPR for your small business: how long to keep your customers' data.
How we checked this
Articles 9, 28, 32 and 33 and chapter V of the GDPR are from the official text on EUR-Lex (Regulation (EU) 2016/679), read on 11 October 2026. The INE figure is from its press release for the first quarter of 2025. What I say about BAI comes from the published pages of our website. The ten questions are my way of ordering what the text requires, not an official template. I wrote it with the help of artificial intelligence from those sources; I sign it myself.
Sources
- Regulation (EU) 2016/679 (GDPR), articles 9, 28, 32 and 33 and chapter V: https://eur-lex.europa.eu/legal-content/ES/TXT/HTML/?uri=CELEX:32016R0679 (accessed on 11 October 2026).
- INE, "Encuesta sobre el uso de TIC y del comercio electrónico en las empresas. Año 2024 - Primer trimestre 2025. Datos definitivos": https://www.ine.es/dyngs/Prensa/ETICCE20241T2025.htm (accessed on 11 October 2026).
- Description of BAI's solutions: published pages Platform and Tasks and projects.
Keep reading
Regulation
Digital signature: what it is, the types and which you need
What an electronic signature is, the difference between simple, advanced and qualified under eIDAS, what each is worth and how to obtain a qualified certificate.
Regulation
Working-time recording in Spain: what the law requires
What the Workers' Statute requires on working-time records, the fine the law sets, what the digital record draft proposes and how to do it well.
Regulation
Verifactu and e-invoicing guide for small businesses (Spain)
Verifactu and mandatory e-invoicing are not the same. What the BOE says about each, which dates stand at 10 October 2026 and what to do now.
