I often accompany startups in so-called asset deals. In principle, contracts are mentioned, for example, in which an online project, a computer game or other rights and content is sold to another party, without- only – the change of the shareholders of the corporation operating the project being changed. This is often the case, for example, when a limited liability company operates more than one project and therefore does not want to sell the entire corporation.
In addition to various aspects of company law as well as tax law, full compliance with copyright and trademark law is also required. The problems arising from data protection law are readily forgotten. This is the case, for example, if user data is also to be purchased, so that the purchaser does not just buy an empty shell. If the GTC was not carefully designed here in advance, this can also make an asset deal quite impossible. But even with good terms and conditions, there are some requirements to consider.
The Conference of the Independent Data Protection Authorities of the Federal Government and the German Federal States has agreed on a catalog of case groups that are to be examined in the context of the
Balancing of interests in accordance with Article 6(6) 1 set 1 lit. f i.V.m. Abs. 4 GDPR must be taken into account in an asset deal.
The case groups are:
1. Customer data for current contracts
In this case, the transfer of the contract requires the approval of the customer under civil law.
2. existing customers without current contracts and last contractual relationship older than 3 years
Data of existing customers for whom the last active contractual relationship dates back more than 3 years are subject to data protection in the event of an acquiring
Represents a restriction on processing. This data may be transmitted, but it may only be used due to legal retention periods.
3. data of customers with advanced contract initiation; Existing customers without current contracts and last contractual relationship less than 3 years
Data of such customers are available in accordance with Article 6(4) of the 1 set 1 lit. (f) to transmit the GDPR by means of the opt-out (opt-out model) with a sufficiently reasonable period of opposition. However, bank data are excluded from the transfer by means of a solution to the opposition and can only be transmitted with the express consent of the customer.
4. Customer data in case of open claims
The transfer of outstanding claims against customers is governed by civil law in accordance with Section 398 et seq. BGB and constitutes an assignment of claims. The assignor may transfer data in this context to the assignee – based on Art. 6 para. 1 set 1 lit. f) GDPR.
5. Customer data of a special category in accordance with Article 9(4) 1 GDPR
Such data may only be provided by means of informed consent in accordance with Article 9(3) of the 2 lit. (a) Article 7 GDPR.
Even if the decision was not co-sponsored by the Berlin Commissioner for Data Protection and Freedom of Information and the Saxon Data Protection Supervisor, the listing certainly makes sense in order to clarify in advance of negotiations what everything is thought of. must be carried out. In principle, the contractual details should only be worked out with experienced help. Game developers, software providers or other service providers are welcome to inquire with me without obligation via my contact form, so that we can elicit the costs for a consultation and the sensible course of action.
Zugehörige Beiträge:
- Job offer: Trainee lawyer or student wanted for…
- Do Free2Play games violate the Pricing Ordinance?
- Warning letters due to missing basic prices
- BGH makes salesman the trick madig
- Anti-competitive misleading by claiming to be…
- "Invested" in tokens and nothing happened? Get money back?
- OLG Frankfurt: No liability for lost profits when…
- Smart Contracts, DeFi and AI: Innovative Business…