What is data processing?
What does Art. 28 GDPR regulate?
Anyone who has a service provider process personal data on their behalf remains responsible. Under Art. 28(1) GDPR, they may therefore only work with processors that provide sufficient guarantees for appropriate technical and organisational measures. The basis is a data processing agreement (DPA). Under Art. 28(3) GDPR, it sets out, among other things: the subject matter and duration, the nature and purpose of the processing, the type of data and the categories of data subjects. It also obliges the service provider to act only on documented instructions, to ensure confidentiality, to implement the security measures under Art. 32 GDPR, to assist with data subject rights, to delete or return data after the end of the contract and to allow audits. The provider may only engage further sub-processors – such as a data centre – with the prior authorisation of the controller (Art. 28(2) GDPR).
In marketing, chains quickly form: campaign platform, hosting, email and SMS sending, lettershop. Each link needs a clear contractual classification. Financial entities additionally assess such service providers as ICT third-party service providers under Regulation (EU) 2022/2554 (DORA).
The bank is the controller for its reinvestment campaign. PBM processes the contact data as a processor in the bank’s installation. The data centre in Germany is a sub-processor; the lettershop that prints the letters becomes, depending on the contractual arrangement, either a sub-processor of PBM or a direct processor of the bank.
Distinction
| Term | Difference |
|---|---|
| Controller (Art. 4(7) GDPR) | decides on purposes and means; bears the main responsibility |
| Joint controllership (Art. 26 GDPR) | two or more parties jointly determine purposes and means; an arrangement instead of a DPA |
| Independent controller | service provider pursues its own purposes with the data; not data processing on behalf |
How the PBM Campaign Platform supports it
PBM offers a DPA; every customer receives their own isolated installation with hosting in Germany as standard (optionally AWS, Microsoft Azure or other environments of your choice, data storage in the EU).
Related pages
-
Trust Centre
Trust CentreDPA, TOMs, subcontractors
-
Blog In preparation
[BLOG: DORA and marketing software: what financial institutions require from service providers]