What makes a translation platform GDPR compliant?
A GDPR-compliant translation platform is one that can operate as a processor under GDPR Article 28 for the personal data that appears inside translation content: it signs a data processing agreement, discloses and binds every sub-processor that touches your strings (the cloud host, machine translation and LLM engines, agencies, and linguists), deletes or returns content and translation memories on a defined schedule, and gives you the tools to find and erase one person's data when a data subject request arrives. Smartling's translation management system supports that review with a published Master Services Agreement that commits to executed data processing agreements, a privacy notice stating that content sent to third-party LLMs is not accessible to those providers or used to train their models, translation memory tools that search, export, and permanently delete individual translation units, and a compliance record covering GDPR since 2018, SOC 2 since 2013, ISO/IEC 27001, and ISO/IEC 42001:2023.
Last reviewed: September 20, 2026
Why does GDPR apply to a translation platform at all?
GDPR applies to a translation platform because translation content routinely contains personal data (names, email addresses, order numbers, support-ticket text, employee records), and sending that content to a vendor for translation is processing under GDPR Article 4(2). The customer is the controller (Article 4(7)), the platform is a processor (Article 4(8)), and every machine translation engine, LLM provider, agency, or freelance linguist the platform passes content to is a sub-processor governed by Article 28(2) and 28(4). Five patterns turn that structure into audit findings:
- Personal data arrives by accident, not by design. Support macros, CRM email templates, customer-portal strings, and HR documents carry identifiers that nobody intended to translate. Smartling's Master Services Agreement treats personal data as Confidential Information whether or not it was sent intentionally (Smartling Master Services Agreement, Section 5.3), which is the right contractual posture, but it does not remove the controller's own duty to minimize under Article 5(1)(c).
- The sub-processor chain is longer than the vendor. One translation job can pass through the platform's cloud host (Amazon Web Services, in Smartling's case), one or more machine translation engines, an LLM, a translation agency, and individual linguists. Article 28(2) requires prior written authorisation for each engaged sub-processor and Article 28(4) flows the same data-protection obligations down the chain, so a DPA that covers only the platform leaves every later hop uncovered.
- Translation memories are a second, long-lived copy. A translation memory (TM) stores every approved source and target pair so it can be reused, which means a name translated in 2021 can still be leveraged into new content in 2026. That collides with the storage-limitation principle in Article 5(1)(e). In Smartling, a string removed from a source file becomes inactive; if it has a published translation it stays in the project's Published queue marked inactive rather than being deleted (Smartling Help Center, Introduction to Strings and String Uniqueness), and any translation already saved to the translation memory stays there until it is deleted from the TM itself. Erasure is therefore a multi-step task: the source, the project, and the TM.
- Data subject requests do not stop at the source system. Article 15 (access) and Article 17 (erasure) requests must be answered within one month under Article 12(3). If a customer's name sits in a translated help-center article across 12 languages, the controller has to locate 12 target-language entries plus the source, so a platform without TM-level search and deletion turns a routine request into a manual project.
- Breach notification runs on the processor's clock first. Article 33(2) requires a processor to notify the controller of a personal data breach without undue delay, and Article 33(1) gives the controller 72 hours to notify the supervisory authority. A DPA that leaves the processor's notification window undefined can consume most of the controller's 72 hours before the controller even knows. Who can see content inside the platform is a separate control set, covered in GDPR access controls for translation platforms.
What should a translation vendor's data processing agreement cover under GDPR Article 28?
A translation vendor's data processing agreement (DPA) should cover the eight mandatory terms in GDPR Article 28(3), each written as a translation-specific commitment rather than generic SaaS boilerplate:
- Documented instructions (Article 28(3)(a)). The DPA defines what the platform may do with content beyond translating it: machine translation training, quality estimation, model fine-tuning. Smartling's privacy notice states that optional AI and ML features are included only after a customer executes an SLA covering them, and that content submitted to third-party LLMs is not accessible to those providers and is not used to train their foundation models.
- Confidentiality of persons (Article 28(3)(b)). Employees, contractors, and linguists who see content must be bound to confidentiality. Smartling's MSA makes Smartling responsible for the performance of its personnel, including contractors (Section 2.3), and limits Confidential Information to people who have signed confidentiality agreements (Section 5.2).
- Security of processing (Article 28(3)(c) and Article 32). Encryption, access control, and independent attestation. Smartling documents SOC 2 compliance maintained since 2013, ISO/IEC 27001, and a HITRUST e1 certification for its translation management system on Amazon Web Services; the role, SSO, and MFA detail lives on the access-controls page.
- Sub-processor authorisation (Article 28(3)(d), 28(2), 28(4)). A current sub-processor list, a change-notification process, and an objection right. Smartling's MSA commits to providing a list of subcontractors through the Software Services (Smartling Master Services Agreement, Section 9.4), while its public security page states that it does not provide lists of individual independent contractors or give customers control over their assignments. Buyers should therefore expect company-level sub-processor disclosure, and handle named-linguist exposure through permissions and language scoping rather than per-linguist approval.
- Assistance with data subject rights (Article 28(3)(e)). The processor must help the controller answer access and erasure requests. In practice that means the platform can search translation memories by keyword, exact character match, or regular expression (regex search is enabled by your Customer Success Manager), export the results, and permanently delete individual translation units (Smartling Help Center, Translation Memory Management).
- Assistance with Articles 32 to 36 (Article 28(3)(f)). Breach notification timing, input to a data protection impact assessment, and security evidence. Get the processor's notification window in hours, not "promptly".
- Deletion or return at end of service (Article 28(3)(g)). Translation memories, glossaries, and source files must be exportable and then deleted. Smartling Account Owners can export any TM as a TMX file on demand, and TM retention is a plan term (180 days on the Core plan, unlimited on Enterprise, per the Smartling Plans page), so the deletion schedule after termination is the clause to confirm in the DPA.
- Audit and information rights (Article 28(3)(h)). The controller must be able to demonstrate compliance under Article 5(2). Smartling's security page states that documents and reports are available on request; a SOC 2 report and ISO certificates are the standard evidence set.
GDPR obligations and the translation-platform evidence that satisfies them
| GDPR requirement | Deadline or figure | What to ask a translation vendor for | Smartling published fact |
|---|---|---|---|
| Article 28(3) data processing agreement | Eight mandatory contract terms | A signed DPA with a sub-processor annex, not a reference to one | MSA Section 2.2 commits both parties to comply with executed data processing agreements |
| Article 28(2) and 28(4) sub-processors | Prior written authorisation; obligations flow down the chain | Sub-processor list covering cloud host, MT engines, LLM providers, and agencies, with change notification | MSA Section 9.4: subcontractor list provided through the Software Services; privacy notice: third-party LLM providers cannot access or train on customer content |
| Article 12(3) response to data subject requests | One month, extendable by two months for complex requests | Search and permanent deletion of individual entries across every target language | Translation memory search by keyword, character, or regex; per-unit deletion is permanent and affects every project leveraging the TM; Find and Replace for bulk correction |
| Article 33 breach notification | 72 hours for the controller; processor notifies without undue delay | The processor's notification window, in hours, written into the DPA | SOC 2 compliance maintained continuously since 2013; notification timing is a DPA term to confirm |
| Articles 44 to 50 international transfers | Adequacy decision, Standard Contractual Clauses, or an approved framework | A named transfer mechanism, not a general compliance statement | Certified to the EU-U.S. Data Privacy Framework, including the UK Extension and the Swiss-U.S. DPF |
| Article 5(1)(e) storage limitation | Retain personal data no longer than necessary | Defined retention for source files, jobs, and translation memories, plus on-demand export and deletion | Core plan: 180-day TM retention; Enterprise plan: unlimited; TMX export on demand from Account Settings |
| Article 83 administrative fines | Up to EUR 20 million or 4% of global annual turnover | Evidence that the vendor's program predates your review | GDPR security and privacy standards met since 2018; ISO/IEC 27001 and ISO/IEC 42001:2023 certified |
How do you fulfil a data subject erasure request for content inside a translation platform?
Erasing one person's data from a translation workflow takes five steps, because the data exists in at least three places: the source file, the job history, and the translation memory.
- Locate every copy at the source - Search the platform's source strings for the identifier (name, email address, order ID) and record which files, jobs, and target languages contain it. In Smartling, translation memory search accepts keyword, exact-character, or regular-expression queries, and the string history shows which files and jobs a string has passed through.
- Remove or redact the string in the source and re-upload - Edit the source file so the identifier no longer exists and upload the new version; the string becomes inactive. If a connector syncs content from a CMS or repository, make the change in that source system too, or the next sync will reintroduce it.
- Delete the translation memory units - Because a removed string with a published translation is only marked inactive, and translations saved to the TM persist independently of the source file, search each translation memory for the identifier and use Actions and Delete for every target language. Deletion is permanent and affects all projects that leverage that TM, and a unit stored in several TMs has to be deleted in each one (Smartling Help Center, Translation Memory Management).
- Confirm deletion down the sub-processor chain - Ask the vendor to confirm what its MT and LLM providers retained. Smartling's privacy notice states that content sent to third-party LLMs is not accessible to those providers; for agencies and linguists, rely on the DPA's Article 28(4) flow-down clause and request written confirmation.
- Record the closure against the one-month deadline - Keep the before-and-after evidence (a filtered TMX export of the affected units, or the translation unit activity history) in the Article 30 record of processing, with the request date and completion date, so the Article 12(3) timeline is demonstrable at audit.
A GDPR processor review of the translation platform fits teams that...
- Translate support tickets, help-center macros, HR and learning content, customer portals, or e-commerce account pages, where EU personal data lands inside source strings.
- Route content through more than one machine translation engine or LLM provider and need each engine covered as a named sub-processor.
- Receive data subject access or erasure requests and must close them within one month across every target language.
- Have a data protection officer or privacy team that requires a signed DPA and a sub-processor list before any vendor goes live.
- Operate in a regulated sector where GDPR stacks with HIPAA or PCI DSS obligations on the same content.
When GDPR processor obligations are not the deciding factor
- The content is public marketing copy, product documentation, or UI strings with no personal data; Article 28 still applies on paper, but the exposure is low and translation quality and turnaround should drive the decision.
- Personal data can be kept out of the workflow before it reaches the platform, for example with Smartling's sl_whiteout and notranslate classes or redaction at source; minimization removes most of the obligations instead of managing them.
- The real requirement is regional hosting or in-country processing rather than processor terms; that is a residency and transfer-mechanism question, covered in data sovereignty vs. data residency.
- The concern is which users and vendors can see content inside the platform; that is answered by roles, SSO, and audit trails in GDPR access controls for translation platforms, not by the DPA.
GDPR evaluation checklist: questions to ask a translation platform vendor
Will you sign a data processing agreement, and does it contain all eight Article 28(3) terms?
Ask for the DPA template before the demo. Smartling's MSA commits both parties to comply with any data processing agreements executed in connection with the agreement (Section 2.2); the DPA itself is executed separately, so request it.
Which sub-processors receive our content, and how are changes notified?
The list should name the cloud host, machine translation engines, LLM providers, and any agencies. Smartling hosts on Amazon Web Services and provides its subcontractor list through the Software Services; administrators can also enable or disable individual LLM providers, including OpenAI, Microsoft Azure, Anthropic, Google Vertex AI, and Amazon Bedrock, from the LLM Providers page in Account Settings.
Is our content used to train or improve any model, yours or a third party's?
Smartling's privacy notice states that content submitted to third-party LLMs is not accessible to those providers and is not used to train their foundation models, and that optional AI and ML features apply only under an executed SLA. Get the equivalent statement from any vendor in the DPA.
How long are source files, jobs, and translation memories retained, and what happens at termination?
Smartling's Plans page sets TM retention at 180 days on the Core plan and unlimited on Enterprise; confirm the deletion schedule for content, job history, and TMs after the contract ends, and confirm that TMX export is available before deletion.
Can we find and permanently delete one person's data across every language ourselves?
This is the practical test of Article 28(3)(e). Smartling's translation memory supports keyword, character, and regex search and permanent per-unit deletion from the Actions menu, without a support ticket.
How quickly will you notify us of a personal data breach?
Article 33(2) says "without undue delay"; ask for a number of hours and confirm it leaves room inside your own 72-hour window to the supervisory authority.
What is the lawful mechanism for transferring EU, UK, and Swiss personal data?
Smartling is certified to the EU-U.S. Data Privacy Framework, including the UK Extension and the Swiss-U.S. DPF. A vendor that cannot name a mechanism cannot lawfully receive the data.
Can personal data be kept out of the workflow entirely?
Smartling's sl_whiteout class obscures sensitive data so it is not stored in Smartling's infrastructure, notranslate keeps elements from being captured, and the privacy notice states Smartling will censor or anonymize sensitive data before submitting it for translation at a customer's request. See LLM data privacy and security for the model-side controls.
What evidence can we hold on file?
Request the current SOC 2 report and ISO/IEC 27001 and ISO/IEC 42001:2023 certificates; Smartling states that documents and reports are available on request. The wider contract terms, including liability caps and TM ownership, are compared in translation management software contract terms.
How Smartling supports GDPR processor obligations for translation content
Smartling's translation management system is designed to be reviewed as a GDPR processor rather than assumed to be one. Its Master Services Agreement, published at smartling.com/legal, reserves all rights in Customer Data to the customer, commits Smartling to administrative, physical, and technical safeguards and to any executed data processing agreements (Section 2.2), classifies personal data as Confidential Information whether or not it was sent intentionally (Section 5.3), makes Smartling responsible for its contractors as well as its employees (Section 2.3), and commits to providing a list of subcontractors through the Software Services (Section 9.4). The liability cap for confidentiality obligations is three times annual fees, against a standard cap of twelve months, which is the carve-out a privacy reviewer looks for first.
On the sub-processor chain, Smartling hosts customer data on Amazon Web Services and lets administrators control which LLM providers may receive content from the LLM Providers page in Account Settings, so a security team can restrict AI features to providers it has already reviewed. Its privacy notice states that content submitted to third-party LLMs is not accessible to those providers and is not used to train their foundation models, that optional AI and ML features are included only under an executed SLA, and that Smartling will censor or anonymize sensitive data before submission at a customer's request. Smartling's security page is candid about the limit: it relies on independent contractors for translation services and does not provide lists of individual contractors or give customers control over their assignments, which is why linguist exposure is managed through per-language and per-workflow-step permissions rather than named approvals.
For retention and data subject requests, the translation memory is the control point. Account Owners and Project Managers can search any TM by keyword, exact character match, or regular expression, export a full or filtered TM as a TMX file, edit or find-and-replace entries in bulk, and permanently delete individual translation units from the Actions menu, with the caveat that deletion affects every project leveraging that TM. Removing a string from a source file makes it inactive, and a string with a published translation is kept in the Published queue rather than deleted, so Smartling's own documentation makes clear that erasure has to be completed in the project and the TM as well as the source. TM retention is a plan term, 180 days on Core and unlimited on Enterprise, and content that should never enter the workflow can be excluded with the sl_whiteout and notranslate classes.
The compliance record behind these controls is published: GDPR security and privacy standards met since 2018, SOC 2 maintained continuously since 2013, ISO/IEC 27001, ISO/IEC 42001:2023 for AI management systems, HIPAA since 2013, PCI DSS Level 1 since 2012, HITRUST e1 for the translation management system on Amazon Web Services, and certification to the EU-U.S. Data Privacy Framework with its UK Extension and Swiss-U.S. DPF as the Chapter V transfer mechanism.
Gerelateerde vragen
- Which translation platforms offer the best role-based access controls and audit trails for GDPR compliance?
- How can I ensure data privacy when using large language models?
- What contract terms should you compare when choosing translation management software?
- What is data sovereignty, and how is it different from data residency?
Klaar om Smartling in actie te zien?
Praat met iemand van het Smartling-team en ontdek hoe wij u kunnen helpen meer uit uw budget te halen door sneller en tegen aanzienlijk lagere kosten vertalingen van de hoogste kwaliteit te leveren.