Why your company report should not be uploaded to just any online site

An export from your management software looks like “just numbers”. Most of the time it also contains customer names, employee names and sometimes contact details. Uploaded to an online tool, that data lands on someone else’s server. Here is what that means and what to check first.

Rawboard

What a report really contains

Check the columns of your export. Sales and staff reports often include:

  • customer names (sometimes phone, address, email);
  • employee names and their data (sales per employee, hours worked, schedule);
  • order information which, in an optical practice, can reveal health data (prescriptions, lens types, implied diagnoses).

If the report contains such data, it is, under the GDPR, a collection of personal data, and health data belongs to the special categories, with stricter rules.

What changes when you upload it online

An online tool that receives your file is usually your processor: it processes the data on behalf of your company. In that case the GDPR requires a contract or legal act between you and the provider (Article 28) and that processing happens only on your instructions. If the servers are outside the European Economic Area, the transfer rules (Article 44 onwards) apply too.

In short: it is not forbidden, but it means one more provider to check, to mention in your notices to employees and customers and to bind with an agreement. The minimisation principle (Article 5) also requires you to send only what the purpose needs.

A checklist before uploading a report

QuestionWhy it matters
Where are the servers (EU or outside the EU)?transfers outside the EEA have their own rules
Is there a data processing agreement (DPA)?the GDPR requires one between controller and processor
How long do they keep the file, and can I delete it?unlimited retention contradicts minimisation
Do they use my data to train models or for other purposes?any other purpose needs its own legal basis
Who at the provider has access to the file?access should be limited
Can I anonymise the report first (no names, no phone numbers)?the simplest risk-reduction measure

The alternative: it stays with you

An app that runs locally, on your computer, with no internet connection, avoids the problem at its root: there is no third party to receive the data. Rawboard is built that way. It is a single file that opens in the browser; the page is not allowed to open any internet connection (its security policy allows no external connections or scripts), and the first screen shows “External resources loaded right now: 0”. The archive of reports stays in that computer’s browser and your original files are never modified. The licence is checked locally with a digital signature, with no server.

The Rawboard start page: “Raw reports, brought into focus”, with Excel, CSV, PDF and Word
The start screen in Rawboard: you load the report and the app reads it locally; the first screen shows how many external resources are loaded (zero).

That does not mean the app frees you from GDPR duties for the data in your reports: you remain responsible for your customers’ and employees’ data. It only means it does not add one more provider to the chain.

A few common-sense rules, whatever the tool

  • Export only the columns you need; remove phone numbers and addresses if they do not matter for the report.
  • Do not email exports to just anyone; use a secure channel.
  • Delete old exports from the Downloads folder.
  • If you use an online service, read its data terms before the first upload.

More on getting the numbers out of an export without sending the data anywhere in How to build a sales report from Excel.

Frequently asked questions

Is it illegal to upload an export with customer data to an online tool?
Not in itself, but you need a legal basis for processing, an agreement with the provider (the processor) and compliance with the rules for transfers outside the EEA. For health data, the rules are stricter.
What is a data processing agreement?
A contract between the controller (your company) and the processor (the provider) setting out what data is processed, for what purpose and with what security measures. The GDPR requires it in Article 28.
Does Rawboard send my data anywhere?
No. It runs locally, as one file; the page is not allowed to open any internet connection. The licence is checked locally, with no server.
If I use an offline app, do I still have GDPR duties?
Yes, you remain the controller of the data in your reports. An offline app just does not add a third party to receive it.
Note: the article is informational and is not legal advice. For your company’s situation, ask a data-protection specialist.

Sources and further reading