Take-Aways (AI)
  • Soft­ware deve­lo­pers must obser­ve pri­va­cy by design and pri­va­cy by default (Art. 25 GDPR) when deve­lo­ping, desig­ning, sel­ec­ting and using pro­ducts and services.
  • Deve­lo­pers must be invol­ved in data gover­nan­ce at an ear­ly stage due to pro­ce­du­ral direc­to­ry, docu­men­ta­ti­on, con­sent and data pro­tec­tion impact assess­ment obligations.
  • The CNIL gui­de­lines (“Kit déve­lo­p­peur”) pro­vi­de prac­ti­cal chap­ters on tool sel­ec­tion, deve­lo­p­ment pre­pa­ra­ti­on, code manage­ment, third-par­ty libra­ri­es, code qua­li­ty and documentation.

Soft­ware deve­lo­pers only have to deal with the GDPR direct­ly if they pro­cess per­so­nal data as a con­trol­ler or pro­ces­sor (e.g., cont­act data of your cus­to­mer, employee data, and pos­si­bly per­so­nal data pro­ce­s­sed for test­ing purposes).

Howe­ver, the GDPR pro­vi­des that pri­va­cy by design and pri­va­cy by default obli­ga­ti­ons (Art. 25 GDPR) must also be obser­ved by deve­lo­pers (Reci­tal 78):

[…] In rela­ti­on to Deve­lo­p­ment, design, sel­ec­tion and use of appli­ca­ti­ons, ser­vices and pro­ducts that eit­her rely on the pro­ce­s­sing of per­so­nal data or pro­cess per­so­nal data in order to per­form their tasks, the Manu­fac­tu­rer of the pro­ducts, ser­vices and appli­ca­ti­ons are encou­ra­ged to take into account the right to data pro­tec­tion in the deve­lo­p­ment and design of the pro­ducts, ser­vices and appli­ca­ti­ons and, with due regard to the sta­te of the art Ensu­re that con­trol­lers and pro­ces­sors are able to com­ply with their data pro­tec­tion obli­ga­ti­ons […]

Other obli­ga­ti­ons may make it neces­sa­ry to invol­ve deve­lo­pers in data gover­nan­ce struc­tures at an ear­ly stage, e.g., the obli­ga­ti­on to main­tain a pro­ce­du­re direc­to­ry, the gene­ral docu­men­ta­ti­on obli­ga­ti­on, pos­si­bly the obli­ga­ti­on to obtain docu­men­ted con­sent, an obli­ga­ti­on to per­form a data pro­tec­tion impact assess­ment that may be trig­ge­red by the inten­ded data pro­ce­s­sing, and data secu­ri­ty requirements.

Against this back­ground, the French regu­la­to­ry aut­ho­ri­ty, the CNIL, Gui­de­lines for deve­lo­pers published (“Kit déve­lo­p­peur”), with the fol­lo­wing chapters:

  • Choi­sir ses outils de tra­vail R
  • Prépa­rer son développement
  • Les bon­nes pra­ti­ques pour gérer vot­re code source
  • Biblio­t­hè­ques, SDK ou outils tiers : com­ment les inté­grer dans vos applications ?
  • Ren­forcer la qua­li­té du code
  • Docu­men­tez vot­re code et vot­re architecture