• Latest
  • Trending
Already created a processing directory?

Already created a processing directory?

6. November 2019
ChatGPT and lawyers: recordings of the Weblaw launch event

Private AI use in the company

24. October 2025
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025
AI content for subscription platforms

AI content for subscription platforms

29. September 2025
E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

E-sports finally charitable? What the government draft of the Tax Amendment Act 2025 really brings

23. September 2025
Clubs, photos and minors: managing consent properly

Clubs, photos and minors: managing consent properly

22. September 2025
AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

AI faces, voice clones and deepfakes in advertising: rules of the game under the EU AI Act and German law

17. September 2025
Modding in EULAs and contracts – what applies legally in Germany?

Modding in EULAs and contracts – what applies legally in Germany?

8. September 2025
Arbitration agreements in EULAs and developer contracts

Arbitration agreements in EULAs and developer contracts

7. September 2025
Chain of title in game development: building a clean chain of rights

Chain of title in game development: building a clean chain of rights

6. September 2025
Fail-fast clauses in media productions – what are they actually?

Fail-fast clauses in media productions – what are they actually?

5. September 2025
Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

Founder’s agreement vs. shareholder agreement: setting the course for startups at an early stage

12. August 2025
Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

Cheat software without code intervention: What the BGH really decided in the Sony ./. Datel case (I ZR 157/21)

11. August 2025
Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

Digital integrity as a (new) fundamental right: status in Germany and the EU in 2025

10. August 2025
European Economic Interest Grouping (EEIG)

EU Digital Decade 2030: Data law, Data Act & eIDAS 2 – what needs to be implemented in 2025

8. August 2025
Upload filters between copyright and personal rights

Upload filters between copyright and personal rights

7. August 2025
On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

On-demand transmission right in the digital space: streaming, Section 19a UrhG and licensing

6. August 2025
Q&A: Legal issues for game developers

5-day guide: Founding a game development studio

5. August 2025
  • Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact

Already created a processing directory?

6. November 2019
in Data protection Law
Reading Time: 3 mins read
0 0
A A
0
privacy policy 3344455 1280

Obligation since the GDPR was applied

Content Hide
1. Obligation since the GDPR was applied
2. What’s occasional?
3. Contents of the processing directory
4. Electronically, of course:_)
4.1. Author: Marian Härtel

Since last May, many have become aware that a privacy policy is needed on a website, an app and in many other situations. However, no one knows that almost everyone needs a processing directory.

But this is exactly the case: all processing operations must be listed in the processing directory, i.e. where and how customer data is stored, what customer data is stored, how long it is stored, who has access to this data and many things Further. A good overview of the processing directory can be found here.

The processing directory is regulated in Art. 30 GDPR:

Each controller and, where appropriate, his representative shall keep a list of all processing activities which are within its competence. Unfortunately, this now affects more companies/managers than you first think.

The […] obligations mentioned do not apply to companies or institutions that employ fewer than 250 employees, unless […] the processing is not only occasional […].

What’s occasional?

Even if the “occasionally” is not defined, this is likely to affect anyone who processes customer data because you have logged-in users, because you sell products or services to users, offer virtual items, etc.

As data protection authorities are already very active, an audit will ensure that such a directory has been created. This is, of course, all the more true if you are responsible for a data protection incident. The first impression would be catastrophic if you did not create a directory and thus clearly show that one has only given very limited thought to data protection in the company/as a provider.

A processing directory sounds at first similar to a data protection declaration, but is not something that is made publicly available on the homepage etc. Rather, it is a representation of what data protection processes take place and of course concerns the own website, the webshop, but also the transfer of data to the tax advisor, debt collection, dealing with payment providers and all other aspects. Also affected are own employees, moderators, etc., whose salaries you and social security data are stored, for example. For agencies, etc., this would also be classic data that is stored in a CRM system, pitches, offers, applications and all other aspects with personal data.

Contents of the processing directory

What needs to be included in the processing directory? Now at least the purposes of the processing, a description of the categories of data subjects and the categories of personal data, the categories of recipients to whom the personal data have been disclosed or are still being disclosed. Of course, particular attention must be paid to transfers to third countries. In addition, there are the legal bases for storage, the time limits for the deletion of the various categories of data and, if possible, a general description of the technical and organisational measures in accordance with Article 32 (1) GDPR, since the Data security is another issue that is often ignored, but which is very important for data protection authorities.

The fewest processing directories will be perfect, but the effort of having managed one alone is likely to reward many data protection officers in the possible investigation of fines. It also serves, of course, to become aware of the events and, therefore, it is also possible to carry out duties such as the obligation to explain the processing purposes in accordance with Article 5(5) of the 1 lit. (b) GDPR, proof of the legality of the processing is in accordance with Article 5(3) 1 lit. a) GDPR, proof of data minimisation under Article 5(3) 1 lit. c) GDPR, proof of the correctness and timeliness of the data in accordance with Art. 1 lit. d) COMPLY with GDPR and numerous other obligations.

Electronically, of course:_)

By the way, the processing directory can of course also be kept in an electronic format. So no one has to pull pens and paper.

Do you have any questions? Contact me.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: AgenturenPrivacyserviceSicherheitSocial securityTax consultant

Weitere spannende Blogposts

File sharing warning: How to react correctly

f9d66e8b2bf7022d8591e13d3d0e83fe
10. July 2024

Have you received a warning about file sharing from law firms such as Frommer Legal, Daniel Sebastian, Yussof Sarwari or...

Read moreDetails

Navigating AI Generators: Liability, disclosure, and the need for regulation

Navigating AI Generators: Liability, disclosure, and the need for regulation
25. May 2023

Introduction In my daily work as a technology and media law attorney, I come into contact with various forms of...

Read moreDetails

BGH rejects delisting request against Google!

District Court Frankfurt a.M. on the right to be forgotten
7. November 2022

The BGH has ruled in two cases, rejecting the delisting request in one case (confirming the first two instances) and...

Read moreDetails

What legal form as an esport team?

What legal form as an esport team?
7. November 2022

What legal form should you aim for if you want to start or professionalize an esports team? The answer to...

Read moreDetails

Default “Yes” to cookies invalid!

Default “Yes” to cookies invalid!
7. November 2022

There could soon be a ruling by the European Court of Justice that could startle German website providers who have...

Read moreDetails

16 years of innovation and passion in IT law: a personal review

16 jahre innovation und leidenschaft im it recht ein persoenlicher rueckblick
10. January 2024

Sometimes it takes a little reminder to make us realize the importance of a long journey. Yesterday, LinkedIn reminded me...

Read moreDetails

Is participation in a sponsored event subject to labelling?

Is participation in a sponsored event subject to labelling?
4. November 2019

There is already a lot around the topic of influencers and labelling requirements and even if the case law currently...

Read moreDetails

Supreme Federal Courts on Mastodon

Supreme Federal Courts on Mastodon
2. March 2023

Since yesterday, the offerings of the Federal Court of Justice, the Federal Administrative Court, the Federal Fiscal Court, the Federal...

Read moreDetails

Designing your SaaS solution in compliance with data protection regulations as a US company!

Designing your SaaS solution in compliance with data protection regulations as a US company!
5. January 2021

In its judgment of July 16, 2020 (Case C311/18), the European Court of Justice declared the European Commission's Decision 2016/1250...

Read moreDetails
BGH hält Uber Black für wettbewerbswidrig
EU law

Britische Anbieter, deutscher Gerichtsstand

10. December 2025

Der BGH hat mit Urteil vom 7. Oktober 2025 (Az. II ZR 112/24) klargestellt, dass deutsche Verbraucher auch nach dem...

Read moreDetails
LogoRechteck

LawOMate startet in den Alphatest: Legal Automation wird zur Infrastruktur

3. December 2025
EU-Chatcontrol und Digital Services Act: Was sich für Spieleentwickler und Online-Plattformen wirklich ändert

EU-Chatcontrol und Digital Services Act: Was sich für Spieleentwickler und Online-Plattformen wirklich ändert

2. December 2025
Agile Softwareentwicklung in internationalen Projekten

Agile Softwareentwicklung in internationalen Projekten

1. December 2025
Deepfakes im Influencer-Marketing: Rechtliche Grenzen, vertragliche Absicherung und strategische Einsatzfelder

Deepfakes im Influencer-Marketing: Rechtliche Grenzen, vertragliche Absicherung und strategische Einsatzfelder

28. November 2025

Podcastfolge

KI im Rechtssystem: Auf dem Weg in eine digitale Zukunft der Justiz

KI im Rechtssystem: Auf dem Weg in eine digitale Zukunft der Justiz

13. October 2024

In dieser faszinierenden Podcastfolge tauchen wir tief in die Welt der künstlichen Intelligenz (KI) und ihre Auswirkungen auf unser Rechtssystem...

Read moreDetails
Die Rolle des IT-Rechtsanwalts

Die Rolle des IT-Rechtsanwalts

5. September 2024
Rechtliche Herausforderungen innovativer Geschäftsmodelle

Rechtliche Herausforderungen innovativer Geschäftsmodelle

26. September 2024
Der unkonventionelle Anwalt: Ein Nerd im Dienste des Rechts

Der unkonventionelle Anwalt: Ein Nerd im Dienste des Rechts

25. September 2024
Digitale Souveränität: Europas Weg in eine selbstbestimmte digitale Zukunft

Digitale Souveränität: Europas Weg in eine selbstbestimmte digitale Zukunft

12. November 2024

Video

Mein transparente Abrechnung

Mein transparente Abrechnung

10. February 2025

In diesem Video rede ich ein wenig über transparente Abrechnung und wie ich kommuniziere, was es kostet, wenn man mit...

Read moreDetails
Faszination zwischen und Recht und Technologie

Faszination zwischen und Recht und Technologie

10. February 2025
Meine zwei größten Herausforderungen sind?

Meine zwei größten Herausforderungen sind?

10. February 2025
Was mich wirklich freut

Was mich wirklich freut

10. February 2025
Was ich an meinem Job liebe!

Was ich an meinem Job liebe!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung