• Mehr als 3 Millionen Wörter Inhalt
  • |
  • in**@********aw.com
  • |
  • Tel: 03322 5078053
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Kurzberatung
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Already created a processing directory?

6. November 2019
in Data protection Law
Reading Time: 3 mins read
0 0
A A
0
privacy policy 3344455 1280

Obligation since the GDPR was applied

Content Hide
1. Obligation since the GDPR was applied
2. What’s occasional?
3. Contents of the processing directory
4. Electronically, of course:_)
4.1. Author: Marian Härtel

Since last May, many have become aware that a privacy policy is needed on a website, an app and in many other situations. However, no one knows that almost everyone needs a processing directory.

But this is exactly the case: all processing operations must be listed in the processing directory, i.e. where and how customer data is stored, what customer data is stored, how long it is stored, who has access to this data and many things Further. A good overview of the processing directory can be found here.

The processing directory is regulated in Art. 30 GDPR:

Each controller and, where appropriate, his representative shall keep a list of all processing activities which are within its competence. Unfortunately, this now affects more companies/managers than you first think.

The […] obligations mentioned do not apply to companies or institutions that employ fewer than 250 employees, unless […] the processing is not only occasional […].

What’s occasional?

Even if the “occasionally” is not defined, this is likely to affect anyone who processes customer data because you have logged-in users, because you sell products or services to users, offer virtual items, etc.

As data protection authorities are already very active, an audit will ensure that such a directory has been created. This is, of course, all the more true if you are responsible for a data protection incident. The first impression would be catastrophic if you did not create a directory and thus clearly show that one has only given very limited thought to data protection in the company/as a provider.

A processing directory sounds at first similar to a data protection declaration, but is not something that is made publicly available on the homepage etc. Rather, it is a representation of what data protection processes take place and of course concerns the own website, the webshop, but also the transfer of data to the tax advisor, debt collection, dealing with payment providers and all other aspects. Also affected are own employees, moderators, etc., whose salaries you and social security data are stored, for example. For agencies, etc., this would also be classic data that is stored in a CRM system, pitches, offers, applications and all other aspects with personal data.

Contents of the processing directory

What needs to be included in the processing directory? Now at least the purposes of the processing, a description of the categories of data subjects and the categories of personal data, the categories of recipients to whom the personal data have been disclosed or are still being disclosed. Of course, particular attention must be paid to transfers to third countries. In addition, there are the legal bases for storage, the time limits for the deletion of the various categories of data and, if possible, a general description of the technical and organisational measures in accordance with Article 32 (1) GDPR, since the Data security is another issue that is often ignored, but which is very important for data protection authorities.

The fewest processing directories will be perfect, but the effort of having managed one alone is likely to reward many data protection officers in the possible investigation of fines. It also serves, of course, to become aware of the events and, therefore, it is also possible to carry out duties such as the obligation to explain the processing purposes in accordance with Article 5(5) of the 1 lit. (b) GDPR, proof of the legality of the processing is in accordance with Article 5(3) 1 lit. a) GDPR, proof of data minimisation under Article 5(3) 1 lit. c) GDPR, proof of the correctness and timeliness of the data in accordance with Art. 1 lit. d) COMPLY with GDPR and numerous other obligations.

Electronically, of course:_)

By the way, the processing directory can of course also be kept in an electronic format. So no one has to pull pens and paper.

Do you have any questions? Contact me.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: AgenturenPrivacyserviceSicherheitSocial securityTax consultant

Weitere spannende Blogposts

Extraordinary termination options for influencer contracts

1. October 2024

In my practice as a lawyer for IT and media law, I encounter the challenges of the digital age on...

Read moreDetails

Digitization in medium-sized businesses: opportunities and legal hurdles

Digitization in medium-sized businesses: opportunities and legal hurdles
4. September 2023

Introduction Digitization has become a central topic in business in recent years, which is also manifested in the increasing number...

Read moreDetails

Geoblocking Regulation: Apps and the like?

Geoblocking Ordinance: Attention Warning Trap
7. November 2022

Does the geoblocking regulation I reported on here actually apply to apps and/or computer games? And if so, under what...

Read moreDetails

Dual holding structure: Does it make sense for startups?

75e587bf074ffac7562428e0a31d365b
13. August 2024

Start-ups and young companies are often faced with the question of the optimal corporate structure. One option that can offer...

Read moreDetails

Esports tournament winnings: when and how are they taxable?

ce956c7a26bdb4f4bc2bf92a0fb460ec
13. August 2024

As a lawyer who represents many tournament organizers, esports players and esports teams, I realize that the issue of taxation...

Read moreDetails

Regulation on requirements for electronic securities registers entered into force at the end of October.

Regulation on requirements for electronic securities registers entered into force at the end of October.
1. December 2022

The Ordinance on Requirements for Electronic Securities Registries (eWpRV) specifies the requirements for maintaining electronic securities registries under the Electronic...

Read moreDetails

Ever heard of it? Cyber Resilence Act!

Ever heard of it? Cyber Resilence Act!
6. January 2023

Suppliers of modern technologies and products in particular must always be up to date with regard to current case law...

Read moreDetails

Looking to the future: AI and blockchain as trailblazers for 2024

Digital sovereignty: Europe’s path to a self-determined digital future
22. December 2023

As 2023 draws to a close, it has been a year full of exciting developments and challenges, particularly in the...

Read moreDetails

ECJ ruling on the GDPR: Consequences and recommendations for action for companies processing personal data

Lego brick still protected as a design patent
15. May 2023

The General Data Protection Regulation (GDPR) has fundamentally changed the way companies handle personal data. It has set new standards...

Read moreDetails
Right to data portability

Right to data portability

16. October 2024

The right to data portability is an important data protection right that was established in the European Union with the...

Read moreDetails

Property

10. November 2024
b5bcca07c04e0521ce70fdb3950344a4

Adhesion procedure

10. November 2024
Publishing contract

Publishing contract

27. June 2023
Liquidation preference

Liquidation preference

16. October 2024

Podcast Folgen

Der unkonventionelle Anwalt: Ein Nerd im Dienste des Rechts

Der unkonventionelle Anwalt: Ein Nerd im Dienste des Rechts

25. September 2024

In dieser fesselnden Episode des Podcasts "Der Unkonventionelle Anwalt" tauchen wir ein in die Welt eines Juristen, der die traditionellen...

Das Metaverse – Rechtliche Herausforderungen in virtuellen Welten

Das Metaverse – Rechtliche Herausforderungen in virtuellen Welten

25. September 2024

In dieser faszinierenden Episode tauchen wir tief in die rechtlichen Aspekte des Metaverse ein. Als Rechtsanwalt und Technik-Enthusiast beleuchte ich...

Digitale Souveränität: Europas Weg in eine selbstbestimmte digitale Zukunft

Digitale Souveränität: Europas Weg in eine selbstbestimmte digitale Zukunft

12. November 2024

In dieser spannenden Episode des itmedialaw.com Podcasts tauchen wir tief in das hochaktuelle Thema der digitalen Souveränität ein. Vor dem...

Der IT Media Law Podcast. Folge Nr. 1: Worum geht es hier eigentlich?

Der IT Media Law Podcast. Folge Nr. 1: Worum geht es hier eigentlich?

26. August 2024

Yeah, die erste richtige Folge mit mir selbst! In diesem Podcast tauchen wir ein in die spannende Welt des IT-Rechts...

  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung