Skip to content

Häufig gestellte Fragen

When is an AVV required?
A data processing agreement (AVV) is always required when an external service provider processes personal data exclusively on instructions from and on behalf of a company (Art. 28 GDPR). Typical examples are cloud hosts, ERP and SaaS providers, payroll service providers or newsletter tools, provided they have access to personal data. By contrast, no processor relationship exists when a third party uses the data on its own responsibility for its own purposes – such as banks, tax advisors or lawyers acting as controllers in their own right; for tax advisors this has even been clarified by statute since the revision of § 11 StBerG. What matters is therefore not data access alone, but whether the service provider acts purely on instructions.
What mandatory content must an AVV contain under Art. 28 GDPR?
Art. 28(3) GDPR prescribes a fixed minimum content covering, among other things, the subject matter, duration, nature and purpose of the processing, the categories of data subjects and types of data, and the processor's obligation to act on instructions. Added to this are the confidentiality obligation of staff, the technical and organisational measures (TOM), rules on the use of sub-processors, and support with data subject rights and notification obligations. Also prescribed are provisions on the deletion or return of the data after the end of the engagement and the controller's inspection and audit rights. If any of these building blocks is missing, the contract is considered incomplete and does not satisfy the statutory requirement.
What are TOM in an AVV?
TOM stands for technical and organisational measures, with which the processor ensures an appropriate level of protection for the data entrusted to it. These include encryption, pseudonymisation, tiered access and authorisation concepts, backup and recovery procedures, and regular staff training. The TOM are usually documented as a separate annex to the AVV and form the basis for later evidence provided to supervisory authorities. Their specific design depends on the protection requirements of the data being processed and should be reviewed individually with the respective ERP provider.
Do I need an AVV with every ERP provider?
An AVV is required with every ERP provider that processes personal data on the company's behalf, which is practically always the case with cloud and SaaS solutions. With on-premise systems without external data access, the obligation only arises once the vendor or an implementation partner accesses the live system via remote maintenance. If further subcontractors are used for the processing, such as an underlying cloud infrastructure operator, these must be included in the contractual chain as sub-processors. In case of doubt, it should be clarified before signing the contract whether and to what extent the provider will have access to personal data.
What happens to the AVV in the case of data transfers to third countries such as the USA?
If personal data is transferred to a processor or sub-processor outside the European Economic Area, the AVV alone is not sufficient; an appropriate transfer basis under Chapter V of the GDPR must also be in place. For the USA, since the adequacy decision of 10 July 2023 this has been the EU-US Data Privacy Framework, provided the receiving company is certified accordingly. If no certification or adequacy decision exists, the EU Standard Contractual Clauses (SCC) are usually used, often supplemented by a risk assessment of the third country. The AVV and the transfer instrument should be aligned with each other without contradictions.
What are the consequences of not having a valid AVV?
Without an effective data processing agreement, passing personal data to an external processor is generally unlawful and constitutes a data protection violation in its own right. Under Art. 83(4) GDPR, supervisory authorities can impose fines of up to 10 million euros or 2 percent of global annual turnover, whichever is higher; in practice, fines imposed so far have mostly been in the four- to five-figure range, for example 5,000 euros in the well-known case handled by the Hessian supervisory authority or 50,000 euros in Brandenburg. Responsibility fundamentally remains with the commissioning controller, while the processor is liable above all if it acts contrary to instructions or to its obligations under the AVV. A missing AVV also stands out immediately and negatively in regulatory audits and cannot be remedied retroactively.