Remote Data Processing Solutions
CRA Article 3(1) defines a product with digital elements as a software or hardware product together with its remote data processing solutions. Anything that qualifies is part of the product for the risk assessment, the essential requirements, the technical documentation and the Article 14 reporting obligations.
Commission guidance C(2026) 5252 section 8 and Figure 9 reduce the definition to two cumulative questions, asked of each remote module rather than of the product as a whole.
The two questions
Would its absence prevent the product performing one of its functions?
Guidance point 189 is explicit that "functions" is not limited to the core functionality or the intended purpose. It covers both functions that directly fulfil the intended purpose as experienced by users, and functions that support the product's overall performance. Sending commands to a device, synchronising files, onboarding a user, configuration, automated distribution of updates, and identity and access management all count.
This is the question manufacturers most often answer incorrectly, by reasoning that something is not core functionality and therefore does not count.
Was the software designed and developed by you, or under your responsibility?
Point 195 defines the second limb. Under your responsibility means tailor-made for you, built by or on behalf of you to your own designs and specifications. Licensing an existing product that a provider offers to its customers generally, or a slightly modified version of one, does not qualify.
The four outcomes
| Q1 | Q2 | Outcome | What you owe |
|---|---|---|---|
| Yes | Yes | Remote data processing solution | Part of the product. Risk assessment, essential requirements, technical documentation, Article 14 reporting |
| Yes | No | Third-party component | Risk-assess it and exercise Article 13(5) due diligence |
| No | Either | Not a remote data processing solution | Assess any risks it poses to the product and mitigate at product level |
| Unanswered | Unanswered | Not yet determined | Answer both questions |
The cloud model shortcut
The tool suggests an answer to the second question from the hosting model, and never decides it for you.
Your own software deployed on a third-party IaaS or PaaS is yours, so it can be a remote data processing solution. The provider's hardware, hypervisor and platform are not part of your product and are treated as third-party components.
A third-party SaaS application you integrate is developed by its provider for its customers generally, so it is not a remote data processing solution. Treat it as a component, risk-assess the integration and exercise due diligence.
On-premises and private-cloud deployments are left open. Point 196 states that who operates the solution is irrelevant, so a solution running on your own servers qualifies on exactly the same terms as one on public cloud.
Direct interaction
Point 205 limits scope to the software modules the product interacts with directly, plus the interfaces those modules use with external services. Deeper back-end systems that carry out subsequent processing, and which the product never touches, are external dependencies rather than part of the product.
The guidance illustrates this with a mobile banking application. The banking interface the app calls is a remote data processing solution. The account-management and ledger systems behind it are not, even though their availability is needed to complete a transfer. They remain dependencies that must be risk-assessed and mitigated through product-level measures such as strong authentication of back-end interfaces and integrity protection of transaction data.
Answering no to direct interaction sets the outcome accordingly and records the reason.
Systems the guidance excludes by name
The tool recognises these and shows a dismissible hint. It never answers either question for you, because a name match is a heuristic rather than the test.
HR systems, payroll, CRM, CI/CD pipelines, distribution of updates to edge locations, penetration testing, threat hunting and red teaming are all outside the definition under point 182. Telemetry collected purely for statistics or future product development is outside it under point 192, because its absence would not stop a function. A website that only presents information is outside it under point 194, even where the product links to it. A cellular network is a communication enabler rather than data processing, and no due diligence is owed to the network provider.
An authentication portal that issues credentials or tokens the product needs to operate is inside the definition.
What gets generated
Saving the determination writes the declaration into the C6.2-IN-06 artifact, which flows through the existing chain into the Annex VII technical documentation. Guidance point 204 requires remote data processing solutions to be described in the technical documentation of every product they serve.
Where the same solution serves several products, the documentation may be reused across them.
Existing assessments
Products assessed before this determination existed carry a single yes-or-no flag captured under earlier guidance. Those are shown as not yet determined rather than converted, because the old flag was recorded against a different test. Nothing is rewritten until you save a determination.