Menu
GDPR and Manufacturing Software: 2026 Data Protection Guide

GDPR and Manufacturing Software: 2026 Data Protection Guide

Which OEE and CMMS software can you use when data must stay in the EU? Hosting region, DPA, sub-processors and the 8 questions to ask any vendor.
GDPR and Manufacturing Software: 2026 Data Protection Guide

Key takeaways

  • GDPR does not ban cloud manufacturing software. It puts conditions on it: a lawful basis, a signed Data Processing Agreement, a published sub-processor list, and a defensible answer to where the data physically sits.
  • Machine data is usually not personal data. The moment a work order carries a technician name, a badge scan or a shift login, the same platform starts processing personal data and the whole regime applies.
  • "EU company" and "EU hosting region" are different claims. Ask for the region by name, in writing, and ask which sub-processors sit outside the EU.
  • International transfers are the part that breaks audits. If any sub-processor is outside the EU, you need Standard Contractual Clauses plus a transfer impact assessment on file.
  • Fabrico is hosted on AWS in an EU region, is certified to ISO/IEC 27001, ISO 9001 and ISO/IEC 20000-1, offers a Data Processing Agreement, encrypts data at rest and in transit, takes daily backups and targets a 4 hour recovery time objective and a 4 hour recovery point objective.

"Our data has to stay in the EU. Which OEE and maintenance software can we actually use?"

Almost any of them, provided you check four things and get the answers in writing rather than from a marketing page.

First, the hosting region. Ask for the region by name, for example eu-central-1 or eu-west-1, not the vendor's country of incorporation. A company registered in Germany can still run its production database in Virginia. Fabrico runs on Amazon Web Services in an EU region.

Second, the Data Processing Agreement. Under Article 28 you need one before go-live, and it has to name the processing purposes, the categories of data subjects and the sub-processors.

Third, the sub-processor list. Your vendor's own region is irrelevant if its error tracker, email service or support desk is outside the EU and receives your data.

Fourth, the security baseline. Certification is the cheap proxy: ISO/IEC 27001 for information security management, plus encryption at rest and in transit, documented backup frequency and a stated recovery objective.

Last updated: August 2026.

What GDPR actually requires from a plant system

The confusion in most factories comes from treating "GDPR" as a single yes or no switch. It is not. It is a set of obligations that only attach to personal data, and a maintenance or OEE platform typically holds two very different kinds of data in the same database.

Machine data is generally not personal data. Cycle counts, run states, downtime reasons at the asset level, temperature curves and availability figures describe equipment. On their own they identify nobody.

The people layer is personal data. Technician accounts, who executed which work order, task duration timers, shift assignments and per employee productivity reporting all identify a natural person. So does a QR badge scan on the line. The instant your system records those, you are a controller processing employee data, and you need a lawful basis, a retention period, a way to answer access requests and a record of processing activities.

This is why the useful question is never "is this software GDPR compliant". Software is not compliant. Deployments are. The right question is whether the vendor gives you the contractual and technical building blocks to make your deployment compliant.

The transfer problem, in plain terms

If any personal data leaves the European Economic Area, you need a transfer mechanism. In practice that means Standard Contractual Clauses in the contract and a documented transfer impact assessment explaining why the destination country's surveillance laws do not undermine those clauses.

Most factories never write that assessment, which is fine until an auditor, a customer's supplier audit or a works council asks for it. Keeping the processing inside the EU removes the entire question rather than answering it, which is why EU hosting is worth paying attention to even when a non EU vendor is technically usable.

Watch for the second order version of this. A platform hosted in Frankfurt that pipes application logs to a US analytics tool is still transferring. Read the sub-processor list, not the homepage.

The vendor questionnaire: 8 questions to send before you shortlist

Send these verbatim. A vendor that cannot answer them in a working day is telling you something.

  1. In which cloud provider and which named region is production data stored, and where are backups stored?
  2. Can you provide a Data Processing Agreement under Article 28, and is it signed as standard or negotiated?
  3. What is your current sub-processor list, and which of those entities are established outside the EEA?
  4. Which security certifications do you currently hold, and can you supply the certificates rather than a logo?
  5. Is data encrypted at rest and in transit, and what key management is used?
  6. What is your backup frequency, your recovery time objective and your recovery point objective?
  7. What personal data fields does the platform hold about our employees, and can retention be configured per field?
  8. How do role based permissions restrict who inside our own organisation can see person level reporting?

Question 8 is the one people forget, and it is often the one that decides whether the project gets approved. If your workforce is represented, the internal visibility rules matter as much as the hosting region. That negotiation is covered separately in our guide to operator adoption for OEE software.

Cloud or on premise: the honest trade

Plants under data pressure often jump straight to on premise. It is a real option, and it genuinely removes the transfer question, but it moves the entire security burden onto your own team: patching, backup verification, disaster recovery testing and access control all become yours. A two person IT department rarely wins that trade. We compare the two models in detail in cloud CMMS versus on premise CMMS.

The middle path most European manufacturers actually take is EU regional cloud hosting with a signed DPA and a short sub-processor list. You get managed security and a defensible data map.

A worked example

A packaging group runs three plants, two in Poland and one in Germany, with 140 shop floor staff. Their evaluation ran like this.

Vendor A was headquartered in the EU but hosted in us-east-1 and used two US sub-processors. Usable, but it required Standard Contractual Clauses plus a transfer impact assessment the group did not want to own.

Vendor B hosted in an EU region, supplied a signed DPA and a three entity sub-processor list, and held ISO/IEC 27001. The group's data protection officer cleared it in one review cycle instead of three.

The deciding factor was not features. Both platforms calculated OEE the same way. It was that Vendor B's answers were specific enough to paste into a compliance file. That is the whole lesson: specificity wins evaluations, and it wins them early.

Where Fabrico sits on each of these questions

Stated plainly, so you can put it in your own comparison sheet.

  • Hosting: Amazon Web Services, EU region.
  • Contract: GDPR compliant with a Data Processing Agreement available.
  • Certifications: ISO/IEC 27001, ISO 9001 and ISO/IEC 20000-1.
  • Encryption: at rest and in transit.
  • Continuity: daily backups, 4 hour recovery time objective, 4 hour recovery point objective, Cloudflare DDoS protection.
  • Access control: role based access control, an activity audit trail, and single sign on with SAML as a custom integration.
  • Interface languages: English, Bulgarian, German, French and Polish, which matters when a Polish operator has to give informed consent to a system in a language they read.

Apply the same standard to us that this article asks you to apply to everyone. Ask for the certificates rather than the logos, ask for the region by name, and ask which items on a vendor's security page are shipped today versus planned. A vendor that answers that cleanly is telling you how the rest of the relationship will go.

For groups running several sites under one data map, the multi plant view and cross plant benchmarking are covered in our guide to multi site CMMS software. If you operate in a validated environment, the parallel requirements are in CMMS software and FDA 21 CFR Part 11 compliance.

If you want these answers against your own data map rather than in the abstract, book a demo and bring your questionnaire. We will answer it on the call.

Frequently asked questions

Is OEE data personal data under GDPR?

Asset level OEE data such as availability, performance and quality for a machine is not personal data. It becomes personal data as soon as it can be linked to an identifiable person, for example when a shift login, an operator badge scan or a per employee productivity report ties output to an individual.

Does GDPR require my manufacturing software to be hosted in the EU?

No. GDPR permits transfers outside the EEA using a valid mechanism such as Standard Contractual Clauses combined with a transfer impact assessment. EU hosting is not legally mandatory, it simply removes the need to build and defend that mechanism.

What is a Data Processing Agreement and do we need one?

A DPA is the Article 28 contract between you as controller and the vendor as processor. It sets out the subject matter, duration, purposes, categories of personal data and the vendor's obligations. If the platform processes any employee data, you need one in place before go live.

Is ISO 27001 the same as GDPR compliance?

No. ISO/IEC 27001 certifies an information security management system, which is strong evidence of technical and organisational measures under Article 32, but it does not by itself demonstrate a lawful basis, transparency, retention limits or data subject rights handling. You need both.

How do we handle a works council that objects to production monitoring?

Frame the deployment at equipment level, run a data protection impact assessment, and agree in writing which person level reports exist and who may see them. Most objections are about individual performance tracking rather than machine data. Our detailed playbook on production line cameras without surveillance covers the camera specific version of the same conversation.

Das Neueste aus unserem Blog

Definieren Sie Ihren Zuverlässigkeitsfahrplan
Überzeugen Sie sich selbst!
Definieren Sie Ihren Zuverlässigkeitsfahrplan
Indem Sie auf die Schaltfläche „Akzeptieren“ klicken, erklären Sie sich mit der Nutzung einverstanden.Cookies beim Zugriff auf diese Website und bei der Nutzung unserer Dienste. Erfahren Sie mehrWeitere Informationen zur Verwendung und Verwaltung von Cookies finden Sie in unserem Datenschutzrichtlinie und Cookie-Erklärung