ERP Systems

The Platform Handles Compliance. It Does Not Handle Yours.

Buying a ready-made platform really does take work off your desk, and the list is longer than most builders admit. It does not take the decisions with your name on them: what you collect, how long you keep it, and who answers when a customer asks. Here is the line, and which side of it each job sits on.

There is a good argument for buying a ready-made platform instead of having something built, and it deserves to be made properly before it is argued with. Somebody else patches the servers. Somebody else renews the certificates. Somebody else is awake at three in the morning when a disk fills up. If your card payments run through their checkout, the card numbers never touch your systems at all, which takes an entire category of risk off your desk and is worth paying for on its own.

All of that is real. None of it is marketing. If you are choosing on who keeps the lights on, and only on that, the platform wins, and anyone telling you otherwise is selling. Whether the thing then fits how your business actually runs is a separate axis and a separate argument, and it is not the one this piece is about.

The trouble starts with the sentence owners actually hear, which is shorter than any of that: the platform handles compliance. It does not. It handles some of it, precisely, and the part it cannot handle is the part with your name on it.

The line, in one sentence

A vendor can take over the work. A vendor cannot take over the answering.

Which of you the law is actually talking to, when customer phone numbers get collected at your counter and kept for two years, is not a question this page is going to answer for you. It has a real answer, it turns on a test written into the Act rather than on what your vendor contract says about it, and we set it out with the citations on the DPDP readiness page, along with the rule that governs what your contract with that vendor has to carry. Read that page before you sign anything, and read it with your own counsel if the answer matters to money.

This is not legal advice and it is not a ruling about your business. Whether any particular exemption reaches you is a question for counsel. What is safe to say is narrower and more useful: no purchase moves the question off your desk.

THEY CAN TAKE THISTHIS STAYS YOURSPatching the serversKeeping it upHandling card numbersCollecting the taxWhat you collect at allHow long you keep itWho on your team can see itAnswering the customer who asks
What a platform genuinely takes off your desk, and what stays on it no matter what you buy.

The one that catches people: merchant of record

Some platforms sell themselves as the merchant of record. It is a genuine and valuable thing to be. It means the platform, not you, is the seller on the invoice, so the platform works out which country’s sales tax applies, collects it, and files it. If you sell a digital product to buyers in thirty countries, that alone can be worth the fee.

Read what it actually covers, which is who counts as the seller for sales tax. Whether the same arrangement also moves who is accountable for the personal data of the customers behind those invoices is a separate question, and it is one for your vendor’s contract and your own counsel to answer, not this page. Two different questions, and the same word, compliance, sitting on top of both of them. That is why the sentence keeps misleading people who are not being careless.

What building actually costs you, said plainly

The honest counter to all this is that a custom build puts more on you, and it does. When a platform holds your data, its engineers have already made a hundred decisions you never see. When it is your own system, those decisions are yours, and a build that skips them is genuinely worse than buying.

So the useful question is not whether custom is safer in the abstract. It is whether the thing being built for you can prove four boring facts:

  • One user cannot read another user’s rows. Not because the screen does not show them, but because the database refuses. Ask to be shown the rule, and ask what happens when it is removed.
  • The restore has been run. Not scheduled. Run, on a real copy, with somebody watching the data come back. A backup nobody has ever restored is a hope.
  • There is a way to erase one person. When a customer asks to be removed, someone has to be able to do it, everywhere, without a developer writing a one-off query at eleven at night.
  • You can see who looked. If four branches share a system, being able to answer who opened which record is the difference between an incident and a mystery.

Those four are not exotic. They are the ones that quietly get skipped, because none of them shows up on a screen and none of them is what anybody asks for in a first meeting. If you are commissioning a build, they are the things to put in writing before the first invoice, and if you are buying a platform, they are exactly what to make it show you.

So which one

The comparison that gets drawn, platform against build, is usually drawn on cost and speed, and on those two the platform generally wins. Fine. Draw it on a third axis as well: which obligations can actually be transferred, and which only look like they can.

Uptime transfers. Patching transfers. Card handling transfers, and it should. Tax can transfer, if you buy from someone who takes it. Deciding what you collect, how long you hold it, who inside your own business can see it, and what happens when a customer asks you to delete it: nobody has yet sold me a plan that does any of those four for me, and I have looked. Whether any of them could be transferred in law is a different question, it turns on the Act rather than on a pricing page, and it is one for the readiness page and for your own counsel.

Which means the real choice was never between being responsible and not being responsible. It was between knowing that and finding out later.