Skip to content
Glossary
Glossary · A · LAW · STATUS 09/2026

What is data processing?

What does Art. 28 GDPR regulate?

Anyone who has a service provider process personal data on their behalf remains responsible. Under Art. 28(1) GDPR, they may therefore only work with processors that provide sufficient guarantees for appropriate technical and organisational measures. The basis is a data processing agreement (DPA). Under Art. 28(3) GDPR, it sets out, among other things: the subject matter and duration, the nature and purpose of the processing, the type of data and the categories of data subjects. It also obliges the service provider to act only on documented instructions, to ensure confidentiality, to implement the security measures under Art. 32 GDPR, to assist with data subject rights, to delete or return data after the end of the contract and to allow audits. The provider may only engage further sub-processors – such as a data centre – with the prior authorisation of the controller (Art. 28(2) GDPR).

In marketing, chains quickly form: campaign platform, hosting, email and SMS sending, lettershop. Each link needs a clear contractual classification. Financial entities additionally assess such service providers as ICT third-party service providers under Regulation (EU) 2022/2554 (DORA).

Regionalbank Musterstadt eG Example

The bank is the controller for its reinvestment campaign. PBM processes the contact data as a processor in the bank’s installation. The data centre in Germany is a sub-processor; the lettershop that prints the letters becomes, depending on the contractual arrangement, either a sub-processor of PBM or a direct processor of the bank.

Distinction

Distinction: data processing and related terms
TermDifference
Controller (Art. 4(7) GDPR) decides on purposes and means; bears the main responsibility
Joint controllership (Art. 26 GDPR) two or more parties jointly determine purposes and means; an arrangement instead of a DPA
Independent controller service provider pursues its own purposes with the data; not data processing on behalf

How the PBM Campaign Platform supports it

PBM offers a DPA; every customer receives their own isolated installation with hosting in Germany as standard (optionally AWS, Microsoft Azure or other environments of your choice, data storage in the EU).

Related terms

Related pages

  • Trust Centre

    Trust Centre

    DPA, TOMs, subcontractors

  • Blog In preparation

    [BLOG: DORA and marketing software: what financial institutions require from service providers]

Next step

Bring a real use case with you.

In 45 minutes, we will sketch out your journey together – with your attributes, your channels, your brand. Afterwards, you will know whether the PBM Campaign Platform is right for you.

Hosting in Germany · single-tenant · consent check before every send