The most important facts at a glance
- Data protection agreements for IT maintenance have been mandatory since the GDPR - without them, fines may be imposed
- Maintenance service providers are legally classified as processors - this triggers comprehensive documentation and monitoring obligations
- Technical and organizational measures must be contractually regulated in detail - blanket clauses are not sufficient and can lead to liability risks
Why data protection agreements are essential for IT maintenance
Digitalization has presented companies of all sizes with new challenges. While IT systems are becoming ever more complex, the need for professional maintenance and care of these systems is also increasing. However, many companies overlook this: As soon as external service providers gain access to IT systems that process personal data, far-reaching data protection obligations arise.
The General Data Protection Regulation (GDPR) has significantly tightened the legal requirements for such constellations. Companies that have their IT systems maintained externally without concluding corresponding data protection agreements are operating in a legal gray area that can result in severe fines. At the same time, liability risks arise towards data subjects whose data may be processed unlawfully.
Legal basis of the data protection agreement for IT maintenance
GDPR as a central source of law
The General Data Protection Regulation forms the foundation of all data protection considerations when maintaining IT systems. Article 28 GDPR explicitly regulates order processing and sets out clear requirements for order processing contracts (AVV) between controllers and processors.
According to Art. 28 GDPR, processing by a processor may only be carried out on the basis of a contract that binds the processor in relation to the controller. This contract must be in writing or set out in another legally binding act.
Order processing for IT maintenance: definition and delimitation
When does order processing exist?
The classification of IT maintenance services as order processing depends crucially on whether the service provider has access to personal data. Even the theoretical possibility of data access is sufficient to justify commissioned processing.
Typical scenarios that are to be classified as order processing:
Remote maintenance with system accessIf maintenance service providers remotely access servers, databases or other IT systems that contain personal data, there is no doubt that this constitutes commissioned processing. This also applies if the service provider assures that it does not access the data.
On-site maintenance with potential data contactPhysical maintenance work on site may also constitute commissioned processing if, for example, backup systems are maintained or there is access to servers on which personal data is stored.
Cloud-based maintenance scenariosSpecial care must be taken when maintaining cloud systems, as personal data is regularly processed here and the distinction between different processing purposes can be complex.
Delimitation of joint responsibility
Not every external IT service automatically results in commissioned processing. In some cases, joint controllership may also exist if the service provider makes its own decisions about the purposes and means of processing.
The distinction is often difficult in practice and requires a precise analysis of the contract design and the actual performance of the service. Blanket classifications are not expedient.
Mandatory contents of a data protection agreement in accordance with Art. 28 GDPR
Basic contract components
Object and duration of processingThe agreement must precisely describe the specific maintenance work to be carried out and the time period in which it will be performed. Vague formulations such as „IT services“ are not sufficient.
Nature and purpose of processingThe purpose for which personal data may be processed as part of maintenance must be clearly defined. This is particularly relevant if the maintenance service provider analyzes log files or creates system backups, for example.
Categories of personal dataThe agreement must specify which types of personal data may be affected by the maintenance. This ranges from master data to sensitive health data, depending on the type of IT system.
Categories of data subjectsA list of the groups of persons whose data could be processed is required. These may be customers, employees, business partners or other persons.
In order to ensure GDPR-compliant data processing, Art. 32 GDPR regulates technical and organizational measures (TOM), compliance with which is required.
Technical and organizational measures (TOM)
Technical and organizational measures (TOMs) form the core of all GDPR-compliant data processing and are mandatory for all data controllers in accordance with Art. 32 GDPR. These protective measures include both technical precautions such as encryption and access controls as well as organizational processes such as employee training and data protection guidelines in order to effectively protect personal data from unauthorized access, loss or misuse.
| Measure | Technical | Organizational |
| 1. access control | Chip card locking system, security doors, light barriers, video surveillance, code lock | Visitor logging, key chip list, role-based server room authorizations |
| 2. access control | User/password authentication, anti-virus software, smartphone encryption, USB locking | User profile management, password rules, verified cleaning staff |
| 3. access control | Role-based authorization concept, data carrier encryption, access logs | Minimum number of administrators, regulated assignment/withdrawal of rights, certified data destruction |
| 4. transfer control | VPN, firewall, e-mail encryption | Documentation of recipients and deletion periods |
| 5. input control | Logging of all data entries/changes/deletions | Individual user names, documented instructions, authorization concept |
| 6. order control | – | Careful selection of contractors, ongoing review, DP contracts in accordance with Art. 28 GDPR, monitoring rights, employee obligations |
| 7. availability control | Outsourced data backup (STRATO AG data center) | Backup & recovery concept, tested data recovery |
| 8. separation requirement | Separate production/test systems, logical client separation | Authorization concept, defined database rights |
| 9. system load capacity | Load distribution across parallel systems, regular updates/patches | Incident response process, documented data breach procedure |
| 10. regular review | Defined test routine, data protection-friendly default settings | Revision of audit reports, data protection management, commissioned processing based on instructions |
Special challenges in various IT maintenance scenarios
Cloud-based IT systems
The maintenance of cloud infrastructures entails additional data protection complexities. Here, several data processing agreements often have to be intertwined: one between the company and the cloud provider and another between the cloud provider and the maintenance service provider.
Regulating subcontracted processingIf the primary maintenance service provider in turn uses subcontractors, appropriate approval procedures and control mechanisms must be established.
Medical IT systems
Particularly strict data protection requirements apply in the healthcare sector, as health data is regularly processed here:
Duty of confidentiality and protection of professional secrecy: Maintenance service providers must submit to corresponding confidentiality obligations that go beyond the standard data protection provisions.
Sector-specific regulationsDepending on the medical field, additional laws such as the Patient Data Protection Act or specific national laws may become relevant.
Practical tips for legally compliant contract drafting
A structured approach to contract negotiations
Risk analysis as a starting pointBefore contract negotiations begin, a detailed analysis of the data protection risks should be carried out. Which data is affected? Which accesses are actually required? What alternatives are there?
Precise service descriptionVague wording is the main reason for later legal disputes. The data protection agreement should describe exactly what maintenance work will be carried out and what data processing is unavoidable.
Don't forget the technical detailsLegal clauses alone are not enough. The agreement must also contain technical implementation details in order to be functional in practice.
Establish control mechanisms
Reporting structuresThe processor should be obliged to report regularly on its activities. This includes both routine status reports and reports in the event of special incidents.
Liability and insurance
Clearly regulate the distribution of liabilityArticle 82 of the GDPR provides for joint and several liability of the controller and processor. Internal recourse claims should therefore be contractually regulated in detail.
Check insurance coverBoth the client and the processor should have appropriate cyber insurance. The amounts and areas of cover should be specified in the data protection agreement.
Checklist for legally compliant data protection agreements
Before signing the contract
- Risk analysis carried out: All data types and categories affected by the maintenance identified
- Legal basis examinedLegitimation for data processing in the context of maintenance clarified
- Alternatives evaluated: Options for minimizing or avoiding data processing examined
- Service provider assessmentQualification and reliability of the processor assessed
- Insurance coverSufficient cover available for both parties
Contract content
- Mandatory information according to Art. 28 GDPR: All content required in Art. 28 GDPR included in full
- Technical and organizational measures: Detailed and verifiable description
- Right to issue instructions: Scope and exercise of the right to issue instructions clearly defined
- Subcontracted processingApproval procedures and control mechanisms defined
- Rights of data subjects: Procedures regulated to support the fulfillment of data subject rights
- Deletion conceptClear guidelines for the deletion or return of data after the end of the contract
After conclusion of the contract
- Implementation monitored: Practical implementation of contractual requirements controlled
- Training courses heldAll employees involved informed of any new procedures
- Audit plan created: Regular reviews of order processing planned
- Documentation createdComplete documentation of order processing in the register of processing activities
Ongoing monitoring
- Regular reviewsAt least annual review of the agreement to ensure it is up to date
- Tracking legal developments: New legal requirements promptly incorporated into contracts
Legal certainty through professional contract drafting
The legally compliant drafting of data protection agreements for the maintenance and servicing of IT systems requires a deep understanding of both the technical circumstances and the legal requirements. The GDPR has significantly increased complexity, but has also improved legal certainty for all parties involved if the requirements are implemented consistently.
Companies that outsource their IT maintenance should be aware that data protection-compliant agreements are not only a legal necessity, but also an important component of company-wide risk management. Well-drafted contracts not only protect against fines, but also create trust among customers and business partners.
Investing in professional legal advice when drafting data protection agreements quickly pays for itself by avoiding costly legal disputes and fines. At the same time, a solid legal basis creates the conditions for trusting and efficient cooperation with IT service providers.
Frequently asked questions
Yes, the technical possibility of accessing personal data already constitutes commissioned processing. The actual use of this possibility is irrelevant for the legal assessment. Pure hardware maintenance can also constitute order processing if, for example, hard disks with personal data need to be replaced.
Standard clauses can serve as a starting point, but must always be adapted to the specific circumstances of the respective maintenance service. Art. 28 GDPR explicitly requires a description of the specific subject matter and type of processing. Blanket formulations do not meet these requirements.
According to Art. 82 GDPR, the controller and the processor are jointly and severally liable to the data subjects. In the internal relationship, the distribution of liability is determined by the degree of fault.
Yes, even one-off or short-term maintenance work requires a data protection agreement if personal data could be processed in the process. In such cases, framework agreements with specific individual contracts can be useful.
A regular review should be carried out at least once a year. In addition, adjustments are required in the event of Changes to maintenance services, new legal requirements, technological advancements or following security incidents.
Art. 28 GDPR requires a clear regulation for the return or deletion of data after the end of the service. This regulation must also include technical aspects such as the secure deletion of backup copies and temporary files.
International data transfers are only permitted under the conditions of Chapter V GDPR. Appropriate protective measures must be implemented for maintenance services with cross-border components.
Certifications can provide an indication of the trustworthiness of a service provider, but are no substitute for individual checks and the specific design of the data protection agreement.
Yes, Art. 28 GDPR explicitly requires that all persons who have access to personal data are obliged to maintain confidentiality. This applies regardless of whether statutory confidentiality obligations already exist.
There is no simplification of the legal requirements for SMEs either. However, industry-specific model contracts can serve as a starting point. Legal advice at an early stage helps to develop cost-efficient solutions and avoid expensive corrections later on.