Is it safe to give a developer access to your customer data?
It can be, and most of the time it should be. The difference between a safe handover and a risky one comes down to three things you can check in an afternoon, before a single record leaves your office.
Published · 3 min read
Yes, if three things are true. The developer sees only what the job needs, usually far less than you think. The obligations are written down before anything is shared, in a data processing agreement, which the law requires anyway. And you know where the data will live once the system is built, and who can reach it. A firm with those three in place can hand over its records with a clear conscience. A firm that skips them is trusting to luck, however honest the developer.
What does a developer actually need to see?
Much less than the whole database. To build a job-tracking system, an invoicing tool or a booking app, a developer needs the shape of your data: which fields exist, what format they take, which awkward cases turn up. They do not need the names and addresses. A few dozen sample records with the real details replaced do most of the work. Real data is needed at two moments only: when your existing records are moved into the new system, and when a fault appears that only real data reproduces. Both are short and supervised, not standing access. That is how we work. We build on sample data wherever the job allows, and once a system is handed over we need nothing further from it.
What should be written down before you share anything?
Two documents. A confidentiality agreement covers what the developer learns about your business. A data processing agreement covers your customers’ personal data, and this one is not optional. Under UK GDPR your firm is the controller, meaning the one who decides why and how the data is used, and a developer who handles it on your behalf is a processor. The ICO’s guidance is plain: “whenever a controller uses a processor, there must be a written contract”, and the law sets out what it must say. The developer acts only on your instructions, keeps the data confidential and secure, tells you before bringing in anyone else, helps you if there is a breach or a request from a customer, and deletes or returns the data when the work ends. The same rules apply word for word under the EU’s GDPR, and most countries have an equivalent. A developer who is happy to sign this agreement, and knows what belongs in it, is telling you something about how they work.
Where will the data live once the system is built?
Ask this before the build starts, because the answer shapes the design. There are two options. The system runs on your own machines or your own accounts, so nobody outside the firm can reach the data without you. Or the developer hosts it, running the database on your behalf. We usually advise the first where the job allows, because it keeps you in control and takes us out of the picture once the system is delivered. Some systems need a hosted database, for instance where staff in the field and the office share live records, and then the questions become who holds the keys, where the server is, and what happens if the arrangement ends. Those answers belong in writing too. We are on both sides of this question: our own platform, FireRecord, holds our customers’ records under exactly these obligations.
What should you ask a developer before handing over data?
Five questions, and the answers tell you most of what you need to know.
- What do you need to see, and can you work from a sample with the real details removed?
- Will you sign a data processing agreement before we share anything?
- Who on your side will have access, and when does it end?
- Where will the data live once the system is built, and can we run it ourselves?
- What happens to our data, and to your access, if we stop working together?
A developer who answers all five without hesitation is safe to work with. One who waves them away is not, however good the portfolio looks.
Frequently asked questions
Do we need a data processing agreement with a freelancer as well as with a company?
Yes. The law looks at what is done with the data, not at the size of whoever does it.
Who owns the data in the new system?
You do, always, and you should be able to export it at any time. Who owns the code is a separate question with its own answer, and we will cover it in a later article.
If you are weighing up whether to let a developer near your customer records, describe the system you want and the data it involves on our contact page. We will tell you what we would need to see, and what we would not.
- trust and data
- GDPR
- working with a developer
