• Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Rechtsanwalt Marian Härtel - ITMediaLaw

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Kurzberatung
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
Rechtsanwalt Marian Härtel - ITMediaLaw

Already created a processing directory?

6. November 2019
in Data protection Law
Reading Time: 3 mins read
0 0
A A
0
privacy policy 3344455 1280

Obligation since the GDPR was applied

Content Hide
1. Obligation since the GDPR was applied
2. What’s occasional?
3. Contents of the processing directory
4. Electronically, of course:_)
4.1. Author: Marian Härtel

Since last May, many have become aware that a privacy policy is needed on a website, an app and in many other situations. However, no one knows that almost everyone needs a processing directory.

But this is exactly the case: all processing operations must be listed in the processing directory, i.e. where and how customer data is stored, what customer data is stored, how long it is stored, who has access to this data and many things Further. A good overview of the processing directory can be found here.

The processing directory is regulated in Art. 30 GDPR:

Each controller and, where appropriate, his representative shall keep a list of all processing activities which are within its competence. Unfortunately, this now affects more companies/managers than you first think.

The […] obligations mentioned do not apply to companies or institutions that employ fewer than 250 employees, unless […] the processing is not only occasional […].

What’s occasional?

Even if the “occasionally” is not defined, this is likely to affect anyone who processes customer data because you have logged-in users, because you sell products or services to users, offer virtual items, etc.

As data protection authorities are already very active, an audit will ensure that such a directory has been created. This is, of course, all the more true if you are responsible for a data protection incident. The first impression would be catastrophic if you did not create a directory and thus clearly show that one has only given very limited thought to data protection in the company/as a provider.

A processing directory sounds at first similar to a data protection declaration, but is not something that is made publicly available on the homepage etc. Rather, it is a representation of what data protection processes take place and of course concerns the own website, the webshop, but also the transfer of data to the tax advisor, debt collection, dealing with payment providers and all other aspects. Also affected are own employees, moderators, etc., whose salaries you and social security data are stored, for example. For agencies, etc., this would also be classic data that is stored in a CRM system, pitches, offers, applications and all other aspects with personal data.

Contents of the processing directory

What needs to be included in the processing directory? Now at least the purposes of the processing, a description of the categories of data subjects and the categories of personal data, the categories of recipients to whom the personal data have been disclosed or are still being disclosed. Of course, particular attention must be paid to transfers to third countries. In addition, there are the legal bases for storage, the time limits for the deletion of the various categories of data and, if possible, a general description of the technical and organisational measures in accordance with Article 32 (1) GDPR, since the Data security is another issue that is often ignored, but which is very important for data protection authorities.

The fewest processing directories will be perfect, but the effort of having managed one alone is likely to reward many data protection officers in the possible investigation of fines. It also serves, of course, to become aware of the events and, therefore, it is also possible to carry out duties such as the obligation to explain the processing purposes in accordance with Article 5(5) of the 1 lit. (b) GDPR, proof of the legality of the processing is in accordance with Article 5(3) 1 lit. a) GDPR, proof of data minimisation under Article 5(3) 1 lit. c) GDPR, proof of the correctness and timeliness of the data in accordance with Art. 1 lit. d) COMPLY with GDPR and numerous other obligations.

Electronically, of course:_)

By the way, the processing directory can of course also be kept in an electronic format. So no one has to pull pens and paper.

Do you have any questions? Contact me.

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Tags: AgenturenPrivacyserviceSicherheitSocial securityTax consultant

Weitere spannende Blogposts

Drafting contracts for SaaS companies: Tips from an IT law expert

Drafting contracts for SaaS companies: Tips from an IT law expert
10. October 2024

Software as a Service (SaaS) has established itself as the dominant business model in the IT industry. For SaaS companies,...

Read moreDetails

OLG Hamm: Information on the manufacturer’s warranty

OLG Hamm: Information on the manufacturer’s warranty
7. November 2022

The Higher Regional Court of Hamm has ruled that manufacturer's warranty statements in operating instructions can give rise to a...

Read moreDetails

Warning because of double optin e-mail

Warning because of double optin e-mail
7. November 2022

Today I became aware of a decision of the Berlin Regional Court that obligated a sender of a confirmation e-mail...

Read moreDetails

Defend yourself against IGD warnings?

LG Munich: Data protection consent on dating platform
7. November 2022

Actually, the behaviors when you receive a warning under competition law are always the same. A summary can be found...

Read moreDetails

Office 365 in schools illegal under data protection law

Office 365 in schools illegal under data protection law
7. November 2022

1. preliminary remark For years, there has been a debate in Germany about whether schools can use Microsoft's Office 365...

Read moreDetails

Core violations in online marketing: An important ruling for agencies

Core violations in online marketing: An important ruling for agencies
24. September 2024

As a lawyer specializing in IT and media law, I would like to present a recent ruling by the Higher...

Read moreDetails

Legal tech: contract generator permissible

Legal tech: contract generator permissible
7. November 2022

An electronic generator of legal documents does not violate the Legal Services Act. This was decided by the 6th Civil...

Read moreDetails

Online shops and payment services supervision law

Online shops and payment services supervision law
18. March 2019

Some online services offer a fiduciary process for your business model when customers interact with each other. This is also...

Read moreDetails

Corona crisis: Where is aid available from development banks?

Corona crisis: Where is aid available from development banks?
7. November 2022

In Germany, we live under federalism, and therefore the various state banks and other institutions in this country are what...

Read moreDetails
Contractual regulations for no-code/low-code software development
Other

Contractual regulations for no-code/low-code software development

21. May 2025

No-code and low-code platforms enable rapid software development without extensive manual programming. Applications are increasingly being developed on the basis...

Read moreDetails
Erotic content on OnlyFans: Copyright and personality rights protection for creators

Erotic content on OnlyFans: Copyright and personality rights protection for creators

20. May 2025
Goodbye hustle culture? Startup life between 24/7 grind and work-life balance

Goodbye hustle culture? Startup life between 24/7 grind and work-life balance

19. May 2025
Startup buzzwords 2025: Bullshit bingo in marketing German Introduction: Bullshit bingo in marketing German

Startup buzzwords 2025: Bullshit bingo in marketing German Introduction: Bullshit bingo in marketing German

18. May 2025
From the metaverse boom to AI euphoria – a tech lawyer in the hype cycle

From the metaverse boom to AI euphoria – a tech lawyer in the hype cycle

17. May 2025

Podcastfolge

238a909c26a0302cbd4792cbd18e4922

Global challenges for start-ups – A legal guide

10. October 2024

This informative podcast offers a comprehensive insight into the legal challenges faced by start-ups when expanding internationally. The experienced lawyer...

Read moreDetails
247f58c28882e230e982fa3a32d34dea

Digital sovereignty: Europe’s path to a self-determined digital future

8. December 2024
4f3597d5481e0f38e37bf80eaad208c7

The IT Media Law Podcast. Episode No. 1: What is this actually about?

26. August 2024
da884f9e2769f2f96d6b74255be62c27

The role of the IT lawyer

5. September 2024
AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

AI in law: opportunities, risks and regulation – the IT Media Law Podcast Episode 3

24. September 2024

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung