Key takeaways
Almost any of them, provided you check four things and get the answers in writing rather than from a marketing page.
First, the hosting region. Ask for the region by name, for example eu-central-1 or eu-west-1, not the vendor's country of incorporation. A company registered in Germany can still run its production database in Virginia. Fabrico runs on Amazon Web Services in an EU region.
Second, the Data Processing Agreement. Under Article 28 you need one before go-live, and it has to name the processing purposes, the categories of data subjects and the sub-processors.
Third, the sub-processor list. Your vendor's own region is irrelevant if its error tracker, email service or support desk is outside the EU and receives your data.
Fourth, the security baseline. Certification is the cheap proxy: ISO/IEC 27001 for information security management, plus encryption at rest and in transit, documented backup frequency and a stated recovery objective.
Last updated: August 2026.
The confusion in most factories comes from treating "GDPR" as a single yes or no switch. It is not. It is a set of obligations that only attach to personal data, and a maintenance or OEE platform typically holds two very different kinds of data in the same database.
Machine data is generally not personal data. Cycle counts, run states, downtime reasons at the asset level, temperature curves and availability figures describe equipment. On their own they identify nobody.
The people layer is personal data. Technician accounts, who executed which work order, task duration timers, shift assignments and per employee productivity reporting all identify a natural person. So does a QR badge scan on the line. The instant your system records those, you are a controller processing employee data, and you need a lawful basis, a retention period, a way to answer access requests and a record of processing activities.
This is why the useful question is never "is this software GDPR compliant". Software is not compliant. Deployments are. The right question is whether the vendor gives you the contractual and technical building blocks to make your deployment compliant.
If any personal data leaves the European Economic Area, you need a transfer mechanism. In practice that means Standard Contractual Clauses in the contract and a documented transfer impact assessment explaining why the destination country's surveillance laws do not undermine those clauses.
Most factories never write that assessment, which is fine until an auditor, a customer's supplier audit or a works council asks for it. Keeping the processing inside the EU removes the entire question rather than answering it, which is why EU hosting is worth paying attention to even when a non EU vendor is technically usable.
Watch for the second order version of this. A platform hosted in Frankfurt that pipes application logs to a US analytics tool is still transferring. Read the sub-processor list, not the homepage.
Send these verbatim. A vendor that cannot answer them in a working day is telling you something.
Question 8 is the one people forget, and it is often the one that decides whether the project gets approved. If your workforce is represented, the internal visibility rules matter as much as the hosting region. That negotiation is covered separately in our guide to operator adoption for OEE software.
Plants under data pressure often jump straight to on premise. It is a real option, and it genuinely removes the transfer question, but it moves the entire security burden onto your own team: patching, backup verification, disaster recovery testing and access control all become yours. A two person IT department rarely wins that trade. We compare the two models in detail in cloud CMMS versus on premise CMMS.
The middle path most European manufacturers actually take is EU regional cloud hosting with a signed DPA and a short sub-processor list. You get managed security and a defensible data map.
A packaging group runs three plants, two in Poland and one in Germany, with 140 shop floor staff. Their evaluation ran like this.
Vendor A was headquartered in the EU but hosted in us-east-1 and used two US sub-processors. Usable, but it required Standard Contractual Clauses plus a transfer impact assessment the group did not want to own.
Vendor B hosted in an EU region, supplied a signed DPA and a three entity sub-processor list, and held ISO/IEC 27001. The group's data protection officer cleared it in one review cycle instead of three.
The deciding factor was not features. Both platforms calculated OEE the same way. It was that Vendor B's answers were specific enough to paste into a compliance file. That is the whole lesson: specificity wins evaluations, and it wins them early.
Stated plainly, so you can put it in your own comparison sheet.
Apply the same standard to us that this article asks you to apply to everyone. Ask for the certificates rather than the logos, ask for the region by name, and ask which items on a vendor's security page are shipped today versus planned. A vendor that answers that cleanly is telling you how the rest of the relationship will go.
For groups running several sites under one data map, the multi plant view and cross plant benchmarking are covered in our guide to multi site CMMS software. If you operate in a validated environment, the parallel requirements are in CMMS software and FDA 21 CFR Part 11 compliance.
If you want these answers against your own data map rather than in the abstract, book a demo and bring your questionnaire. We will answer it on the call.
Asset level OEE data such as availability, performance and quality for a machine is not personal data. It becomes personal data as soon as it can be linked to an identifiable person, for example when a shift login, an operator badge scan or a per employee productivity report ties output to an individual.
No. GDPR permits transfers outside the EEA using a valid mechanism such as Standard Contractual Clauses combined with a transfer impact assessment. EU hosting is not legally mandatory, it simply removes the need to build and defend that mechanism.
A DPA is the Article 28 contract between you as controller and the vendor as processor. It sets out the subject matter, duration, purposes, categories of personal data and the vendor's obligations. If the platform processes any employee data, you need one in place before go live.
No. ISO/IEC 27001 certifies an information security management system, which is strong evidence of technical and organisational measures under Article 32, but it does not by itself demonstrate a lawful basis, transparency, retention limits or data subject rights handling. You need both.
Frame the deployment at equipment level, run a data protection impact assessment, and agree in writing which person level reports exist and who may see them. Most objections are about individual performance tracking rather than machine data. Our detailed playbook on production line cameras without surveillance covers the camera specific version of the same conversation.