What compliance support can a software development provider deliver?
Wavesteam can provide product and technical compliance support, but cannot guarantee that an entire business is compliant. We turn requirements confirmed by the client, counsel, or authority into data inventories, permissions, logs, user-rights workflows, content controls, security tests, filing material, and remediation evidence. We do not issue legal opinions, hold the client's operating licence, or replace continuing moderation and incident decisions.
Compliance is not a privacy policy added before launch. Jurisdiction, user group, business activity, data category, and third parties change the duties. A community app that only displays content is different from one that accepts posts, intermediates transactions, serves children, or ranks content. Begin with a factual system and business record, let authorized professionals determine the requirement, and implement that decision.
When translating compliance duties into evidence and controls, also compare When does a product need real-name verification or facial identity checks?; the linked guidance adds context that should be considered in the same decision.
| Work | Wavesteam can deliver | Client responsibility | External specialist |
|---|---|---|---|
| Data facts | Data flow, fields, SDKs, accounts, and locations | Confirm actual purpose, source, and owner | Counsel or security review for complex regulated or cross-border data |
| Product controls | Minimization, permissions, logs, deletion, export, review, and security | Supply rules, staff, and continuing operation | Qualified testing or certification body where required |
| Policy and contract input | Accurate system facts and interface placement | Decide purpose, sign, and assume public responsibility | Counsel approves legal text and applicability |
| Licence and platform filing | Prepare technical material and fixes | Apply through the client's entity and keep facts and licence current | Authority advice where scope is uncertain |
| Post-launch work | Alerts, cases, evidence, and contracted operations | Complaints, rights requests, moderation, and incident decisions | Regulators and response specialists for serious events |
Turn every requirement into an action. “Protect personal information” means naming fields, purpose, basis, retention, roles, recipients, and access, correction, and deletion routes. The system can then mask fields, approve exports, enforce retention, and audit operations. A generic policy is not evidence when the product lacks deletion and the backend retains data indefinitely.
User content or transactions require prohibited-content and goods rules, pre- or post-publication review, reporting, authority, appeal, repeat-offender handling, and evidence retention. Models and keywords route work but should not decide every high-impact case. Recommendation or generation may add disclosure, choice, filing, or assessment duties depending on the service; calling a third-party API does not transfer the operator's responsibility.
China's Personal Information Protection Law distinguishes personal-information handlers and entrusted processors. The Regulations on Network Data Security Management, effective in 2025, add network-data security and platform governance duties. The contract should identify who determines purpose, handles rights requests, controls keys, and coordinates notification.
Deliverables may include a jurisdiction and business fact sheet, data inventory and flow, vendor and SDK register, role matrix, retention and deletion rules, threat model, test report, filing material, launch checklist, and residual-risk record. Each has an owner, source, result, and review date. Acceptance proves deletion across active stores and expiry from backups, rejection of unauthorized access, log hygiene, moderation traceability, actual SDK traffic, and tested recovery.
Wavesteam divides work into client decision, legal confirmation, technical implementation, operational execution, and third-party assessment in the statement of work. We collaborate with counsel and assessors and pause high-risk functions when the operator, licence, or core data source remains unresolved. The Transparent Delivery Standard explains the evidence-based delivery boundary.