What to Settle About Your Data Flow Before You Commission an Automation
Data protection is decided before you sign, not at handover. Which data flow facts belong in a quote, and what a late answer costs.
This article was generated by AI. Labelled in accordance with Article 50 of the EU AI Act. Responsible for publication: Sophera Consulting.
Calling an automation compliant says nothing about the software. It is a claim about the route your data takes, and that route fits on a single page. A provider who cannot write it down cannot support the claim either.
This is not a legal technicality. It is a question you can ask before you commission anything, and the answer tells you more about a provider than any reference list.
What a data flow is, and why nobody has the full picture
A data flow records where data originates, which systems it passes through, where copies are held, and when those copies disappear. An automation has more stops than most people expect.
Suppose an enquiry arrives through a contact form. It passes the web server, is picked up by an automation platform, stored there in an execution log, sent to an enrichment service for company details, written into a CRM, and finally triggers a notification to sales. That is six stops, and every one of them holds the name, the email address and the text of the enquiry.
The reason nobody has written this down is undramatic. Each stop was configured by someone who knew what they were doing. Documenting the whole route in one place was never anyone's job, because no ticket produces it and nobody asks while everything runs.
Three places where the route quietly leaves Europe
The first is the automation platform itself. Many vendors run data centres in several regions, and the region a workspace uses is fixed at sign-up. Whoever accepted the default made a decision without recognising it as one.
The second is language models and enrichment services. The moment an automation summarises an email, reads an order or looks up a company, that content leaves your own infrastructure. European options exist with the major vendors, but they are rarely the default.
The third is logging. An automation platform stores what went in and what came out on every run. That is useful when something breaks and awkward under data protection law, because complete personal data sits there for months in a system nobody in the building treats as a data store and that appears in no retention policy.
The objection that is often correct
At this point someone usually points out that this is only business data. Company name, order number, article, quantity. That is frequently true and it genuinely simplifies the picture.
It stops being true at a clear point. As soon as a contact person, a personal email address, a direct line or a handwritten note on a delivery slip is in the record, it is no longer purely business data. In wholesale and logistics that is the normal case, because a human sits behind every transaction. In hospitals the line is tighter still, since ward, article and date together already allow inferences.
The practical difference is large. A pure order data flow is far cheaper to secure than one carrying employee or health data. That is why the question belongs at the start, not in the acceptance meeting.
What belongs in the quote
Four statements should be in writing before you sign.
First, a list of every service involved and where it is operated. Second, which personal data is processed at which stop. Third, how long execution logs are retained and who can read them. Fourth, which processing agreements are required and who obtains them.
If these are missing, that is not a reason to reject a provider. It is a reason to ask. Answering costs little at the start, because the information is produced while building anyway. It costs a multiple later, when an audit forces the answer and the automation is already live, so every correction is surgery on a running process.
Is a US cloud automatically the wrong choice
No. There are legal bases for transfers to the United States, and the large vendors supply both the contracts and European hosting options. The question is not whether it is permitted, but whether it is documented and whether you can explain it when asked.
In practice that cuts two ways. For an internal process with no personal data, paying extra for a European deployment is rarely justified. As soon as employee records, applications, health data or hospital patient data are involved, the calculation reverses. There the surcharge for European hosting, or for running the stack in your own building, is not caution. It is the cheaper option, because it removes a whole class of questions in advance.
Getting your own data flow onto paper quickly
Take one existing automation and walk it stop by stop. For each stop note five columns: which system, which data, where it runs, how long it is kept, which contract covers it. This rarely exceeds one page, and nobody involved needs to read code.
The payoff appears immediately in two places. You see whether your record of processing activities still describes what actually happens. And you hold a document you can hand to any provider, instead of explaining the setup from scratch in every conversation.
The recommendation
Treat the data flow as part of the specification, not as an annex to the handover. Ask for those four statements in writing, inside the quote. A provider who can tell you where the data sits and for how long before naming a price has understood your process. One who answers with a certificate has dodged the question rather than answered it.
Sophera Consulting produces that record before building anything, fixes hosting locations, retention and contracts in writing, and only then quotes a fixed price with no subscription. The entry point is free in the Automation Check.
This article was created with the help of AI.