EnglishDeutsch
Germany flag

Germany

Auftragsverarbeitungsvertrag (AVV): When Art. 28 DSGVO Requires One and What It Must Contain

By Recording Law Editorial Team18 min read
Auftragsverarbeitungsvertrag (AVV): When Art. 28 DSGVO Requires One and What It Must Contain

Frequently Asked Questions

When is an Auftragsverarbeitungsvertrag required?

Whenever an external party processes personal data on behalf of an organisation and on its instructions. Cloud hosting, email services, payroll bureaus, newsletter tools, support systems and IT contractors with remote access are the standard cases. Art. 28 DSGVO then requires a contract or other legal act binding the processor to the controller.

What is the difference between a Verantwortlicher and an Auftragsverarbeiter?

A Verantwortlicher decides the purposes and the means of the processing. An Auftragsverarbeiter processes the data on behalf of that controller and on documented instructions. Where each party decides its own purposes, they are separate controllers and an AVV is the wrong instrument.

What has to be in an AVV under Art. 28 Abs. 3 DSGVO?

The subject matter, duration, nature and purpose of the processing, the type of personal data, the categories of data subjects and the obligations and rights of the controller, plus specific processor duties: processing only on documented instructions, confidentiality, the security measures under Art. 32 DSGVO, the sub-processor conditions, assistance with data subject requests, assistance with Art. 32 to Art. 36 DSGVO, deletion or return of the data at the end of the service, and information and audit rights.

Does an AVV have to be signed on paper?

No. Art. 28 DSGVO requires written form and expressly includes electronic form, so accepting a provider standard AVV through an account portal is sufficient. The accepted version should be retrievable if a supervisory authority asks for it.

Do I need an AVV with my tax adviser or my bank?

Both are widely treated as independent controllers rather than processors, because each decides for itself how to meet its own professional or regulatory duties. Classification always depends on the actual facts of the engagement, and the label the parties put on the document does not decide it.

Can my provider use sub-processors without telling me?

Not without authorisation. A processor may only engage another processor with the prior specific or general written authorisation of the controller, and where the authorisation is general the processor has to inform the controller of intended additions or replacements so the controller can object. The processor stays liable for the sub-processor performance.

What happens to the data when the contract ends?

Art. 28 Abs. 3 DSGVO requires the contract to provide that, at the choice of the controller, the processor deletes or returns all the personal data after the end of the provision of the services, and deletes existing copies unless Union or Member State law requires storage. The choice belongs to the controller, not the provider.

What is the fine for having no AVV?

A breach of Art. 28 DSGVO falls in the lower tier under Art. 83 Abs. 4 DSGVO, up to ten million Euro or two percent of total worldwide annual turnover, whichever is higher. That is a different tier from breaches of data subject rights, which sit in Art. 83 Abs. 5 DSGVO at twenty million Euro or four percent.

Sources and References

  1. Verordnung (EU) 2016/679 (DSGVO), konsolidierte Fassung(eur-lex.europa.eu).gov
  2. Datenschutzkonferenz, Kurzpapier Nr. 13, Auftragsverarbeitung, Art. 28 DS-GVO(datenschutzkonferenz-online.de).gov
  3. § 62 BDSG, Auftragsverarbeitung im Anwendungsbereich der Richtlinie (EU) 2016/680(gesetze-im-internet.de).gov
  4. § 40 BDSG, Aufsichtsbehoerden der Laender(gesetze-im-internet.de).gov
  5. § 9 BDSG, Zustaendigkeit der oder des Bundesbeauftragten fuer den Datenschutz und die Informationsfreiheit(gesetze-im-internet.de).gov
  6. § 43 BDSG, Bußgeldvorschriften(gesetze-im-internet.de).gov
  7. § 30 BDSG, Verbraucherkredite(gesetze-im-internet.de).gov
  8. § 29 BDSG, Rechte der betroffenen Person und aufsichtsbehoerdliche Befugnisse im Fall von Geheimhaltungspflichten(gesetze-im-internet.de).gov
  9. BfDI, Beschwerde ueber Datenschutzverstoesse bei den Aufsichtsbehoerden(bfdi.bund.de).gov
  10. BfDI, Anschriften und Links der Landesdatenschutzbehoerden(bfdi.bund.de).gov
Share: