Whether it's an insurance application, patient questionnaire or event registration – almost every business form contains personal data. And as soon as those forms are sent to an external provider for digitization, a question arises: what GDPR requirements apply?
The good news: the requirements are clearly defined and manageable in practice. The key framework is Article 28 GDPR, which governs data processing on behalf of a controller.
What is data processing on behalf of a controller?
When formalogix processes your form data, we act as a data processor – we process data on your behalf, according to your instructions, exclusively for the agreed purpose. We do not use the data for our own purposes, do not share it, and delete it after project completion.
This requires a Data Processing Agreement (DPA), which we provide for every project. It covers, among other things:
- Technical and organisational measures (TOMs) for data protection
- Which sub-processors may be used
- Deletion periods for original documents and intermediate data
- Your rights to audit and inspect
EU hosting: Why server location matters
formalogix processes and stores all data exclusively on servers in Germany. There is no transfer to third countries. This is especially relevant if your documents contain special categories of personal data – such as health data (Art. 9 GDPR) or biometric information.
Providers using US infrastructure or cloud services outside the EU face stricter requirements (Standard Contractual Clauses, Transfer Impact Assessment). This significantly increases compliance overhead.
Comparing providers by hosting location
Your choice of service provider has a direct impact on your GDPR workload. The table below shows what additional steps are required depending on where data is hosted:
| Criterion | Provider in Germany | EU provider (non-DE) | US / global provider |
|---|---|---|---|
| Core GDPR requirements | ✓ met | ✓ met | ⚠️ extra effort |
| Standard Contractual Clauses needed | No | No | Yes |
| Transfer Impact Assessment | Not required | Rarely required | Required |
| Data sovereignty | High | Medium | Low |
| Recommended for health data | ✓ | ⚠️ review | ✗ |
Deletion periods and data minimisation
After project completion, all original documents and intermediate data are securely deleted within a contractually defined period (default: 30 days). You receive only the structured output data in the format you need – CSV, JSON, XML or directly via API.
How the onboarding process works
From initial enquiry to compliant delivery of your structured data, we follow a clearly defined process:
Initial meeting & form analysis
We discuss your forms, volume and any special requirements. You receive an assessment of the GDPR relevance of the data involved.
DPA & TOMs
We provide the Data Processing Agreement including TOMs for review. On request, we can walk through individual clauses together with your Data Protection Officer.
Secure handover
Documents are transferred via encrypted channels – no email, no unencrypted FTP.
Processing & deletion
After project completion you receive the structured data. Original documents are securely deleted within the agreed period and deletion is logged.
Checklist before commissioning
- 1 Sign a Data Processing Agreement with formalogix
- 2 Review and document TOMs internally
- 3 Define deletion periods for original documents
- 4 Update your Record of Processing Activities (RoPA)
- 5 Inform your Data Protection Officer (if applicable)
What happens when a GDPR violation occurs?
Data protection authorities can impose fines of up to 4% of global annual turnover or €20 million – whichever is higher. On top of that, violations can lead to reputational damage, cease-and-desist letters from competitors and civil claims from affected individuals. Controllers who choose unreliable processors share the liability.
Our recommendation: for every external provider handling personal data, check not just the DPA on paper, but also the actual technical implementation. Our processing log provides a complete audit trail of which documents were handled, when, and by whom – available for data protection audits at any time.
We provide all necessary documentation and support you with your RoPA records. If you have specific requirements from your sector – healthcare, financial services or others – contact us directly.
Next step
Have specific forms to digitize?
Send us a sample – we'll have a quote ready within 24 hours.