Skip to main content
Thinking about applying?See how the assessment works
Ask Remi

Remi · Working remotely · 9 min read

GDPR Compliance for Remote Engineers

Remi’s short answer

GDPR is not just a legal concern for compliance teams, it shapes how engineers write queries, structure databases, and handle data in local environments. What remote engineers are responsible for and how to stay compliant.

Six Principles Every Engineer Must Understand

UK GDPR Article 5 establishes six principles that govern the processing of personal data. These are not aspirational, they are legal requirements. Engineers who write code that processes personal data are participating in that processing and must understand these principles.

  • Lawfulness, fairness, and transparency, personal data must be processed on a lawful basis (consent, contract, legal obligation, legitimate interest, etc.) and in a way that is transparent to the data subject.
  • Purpose limitation, data collected for one specific purpose cannot be repurposed without a new lawful basis. Do not build features that use data for purposes beyond what users were told at collection.
  • Data minimisation, collect only the data you need for the specific purpose. If a feature works without a field, do not store it. This is an engineering decision as much as a policy one.
  • Accuracy, personal data must be kept accurate and up to date. Systems must allow for correction of inaccurate data.
  • Storage limitation, personal data must not be kept longer than necessary. Engineers must implement data retention and deletion mechanisms, not just collection.
  • Integrity and confidentiality, personal data must be protected against unauthorised access, loss, or destruction. Security is a GDPR requirement, not an optional extra.

What GDPR Means in Practice for Engineers

Most GDPR failures in technical environments are not caused by deliberate misuse of data. They are caused by engineers who do not consider data protection implications during the design and build phase, what the ICO calls 'privacy by design.'

Database and schema design

  • Do not store personal data in fields you do not need. If you do not need date of birth, do not add the column.
  • Implement soft delete carefully, 'deleted' records that remain in the database still contain personal data. Consider whether hard deletion or anonymisation is required.
  • Personal data in logs, application logs frequently capture request bodies, query parameters, or error messages containing personal data. Review what your logging captures.
  • Database access controls, personal data tables should have scoped access. Not every developer needs read access to a users table in production.

Local development environments

  • Never use real production data in local development or staging environments. Use anonymised or synthetically generated data.
  • Production database dumps on a developer's laptop are a significant GDPR risk, if the device is lost or compromised, the data is breached.
  • If production access is necessary for debugging, use audit-logged, time-limited access rather than permanent production credentials.

The ICO can issue fines of up to £17.5 million or 4% of global annual turnover under UK GDPR for serious violations. Engineers who knowingly or negligently contribute to a data breach may face professional and contractual consequences independent of their employer or client's regulatory exposure.

Data Subject Rights and Your Engineering Responsibilities

UK GDPR grants individuals a set of rights over their personal data. These rights must be technically enforceable, which means they must be built into the systems engineers create.

  • Right of access (Subject Access Request), individuals can request a copy of all personal data held about them. Systems must be capable of producing this within 30 days.
  • Right to erasure ('right to be forgotten'), individuals can request deletion of their personal data in many circumstances. Your system must support this, it cannot be an exclusively manual process at scale.
  • Right to rectification, individuals can request correction of inaccurate data. Your system must allow authorised updates to personal data fields.
  • Right to data portability, in some circumstances, individuals can request their data in a machine-readable format. Consider this in your data export design.
  • Right to restrict processing, individuals can request that their data is not processed for certain purposes. This may require feature-level flags in your application.

If your client's product handles personal data and does not have technical mechanisms to fulfil these rights, raising this is part of your professional responsibility as a senior engineer. It is not a legal or policy matter that sits outside your scope.

Specific Obligations for Remote Contractors

Remote contractors occupy a specific position in the GDPR framework. Depending on the nature of the engagement, a contractor may be acting as a data processor, processing personal data on behalf of the client, who is the data controller. This is the most common position for software engineers working through an intermediary such as VERTX.

  • As a data processor, you must only process personal data on the documented instructions of the data controller (your client).
  • You must not transfer personal data outside of agreed environments without explicit authorisation, this includes copying data to personal cloud storage, local machines, or third-party tools.
  • You must report a personal data breach, or a suspected one, straight away. Under the VERTX Engineer Terms that means telling VERTX within 24 hours. UK GDPR requires the controller to notify the ICO within 72 hours of becoming aware of a breach.
  • Never put personal data, or a company's confidential code, into an AI tool that keeps it, shares it or trains on it.
  • The VERTX Engineer Terms set out your data protection duties: act only on the company's instructions, keep personal data secure, never copy it out of the company's systems, and use it for nothing else. The data protection terms VERTX has agreed with that company also apply to what you do. Read and understand them, because not knowing a contractual duty is not a defence.

The simplest GDPR compliance principle for a remote contractor: treat personal data as if it belongs to the individual it describes, because legally, it does. Build systems that protect it accordingly.

Last updated 2026-10-06