Saltar al contenido

Integrations

What data leaves when you integrate

An integration opens a door. Worth knowing what fits through before opening it.

Updated on 13/08/2026

An integration is not just a convenience: it is a route by which information leaves here and enters somewhere else with its own rules, its own access controls and its own backups. Decide deliberately what goes through it.

The three questions before connecting

  1. 1

    What can that connection read?

    The minimum its case needs, not everything for convenience.

  2. 2

    Where does what leaves end up?

    If the other system is in another country or run by a third party, your obligations change.

  3. 3

    Who can use that key?

    A key circulating in a team chat is no longer a key.

Important

The second is most often forgotten and has consequences beyond the technical. Personal data leaving for another system remains your responsibility, even if the problem happens there.

What is better left in

DataWhy
Full documents, when status sufficesAlmost no ERP needs the PDF: it needs to know whether it is current
Personal data the other system does not useIf it does not use it, it only adds risk
The whole history, when only live mattersClosed material is rarely consulted from outside

Watch out

The first row prevents half of all integration problems. "This supplier is current / is missing insurance" is a sentence; sending the insurance PDF is exporting documentation to a system that may not protect it the same way.

How to look after an access key

That last point is what you need on the bad day. If you do not know which integration uses which key, revoking as a precaution breaks something and nobody knows what.

Worth knowing

Everything an integration does lands in the activity log just like what a person does. If something leaves here, you can find out when and by which route.

Can it be limited to read-only?

Yes, and for most cases that is the right choice.

What if the other platform's vendor changes?

Revoke and issue a new key; hence one per integration.

Do we need a contract with the other vendor?

If they will process your personal data, yes. Not optional.

A real case

The situation

A company wants to dump all supplier documentation into its ERP.

What you do

  1. Sends only document status and expiry date
  2. Issues a read-only key for that integration

What you get

The ERP shows what purchasing needs and no document leaves the platform.

The situation

Integration goes live and more data leaves than was needed.

What you do

  1. Limits the integration to the fields that get used

What you get

What travels is only what is necessary.

The situation

A client asks what data of theirs goes to another system.

What you do

  1. Checks which fields the integration includes

What you get

The answer is specific and verifiable.

The situation

Personal data leaves without anyone deciding it.

What you do

  1. Reviews the content with the adviser before enabling

What you get

The decision is taken beforehand rather than after.

The situation

The data lands in a system with weaker access control.

What you do

  1. Checks who will see that data on the other side

What you get

Protection does not drop along the way.

The situation

Nobody knows what went out last month.

What you do

  1. Checks the call log

What you get

What was sent is auditable.

This article answers

  • what data does an integration share
  • security of an integration with another system
  • limiting what an access key can read
  • risks of connecting two platforms