Skip to content
Call, 0511 – 47 55 58 11

Professional secrecy and IT providers

Professionals bound to secrecy may outsource as far as the service requires it. The processing agreement governs the processing and not the confidentiality, and that is what decides which provider comes into question.

A medical practice has its software maintained remotely, a tax adviser moves client files to the cloud, a counselling centre has its records destroyed by an outside firm. In each case the provider presents a processing agreement, and with the signature the matter appears settled. The question whether it really is arises, as a rule, before anything has gone wrong.

Behind it often sits the worry that outsourcing as such is forbidden. It is not. The question is narrower and more practical, because it concerns the conditions and in the end the choice of provider.

Outsourcing is permitted as far as it is necessary

Section 203(1) StGB makes it an offence to disclose a secret entrusted to a member of the listed professions. Anyone giving a provider access to patient records, client files or counselling records discloses them within the meaning of the provision. Section 203(3) sentence 2 StGB carves out what is necessary in order to make use of the service, and expressly extends that to the further persons the provider engages.

Covered by the exemption

  • Maintenance and operation of the specialist application where access is unavoidable
  • Hosting and backup where the data has to sit with the provider for that
  • File destruction and archiving to the extent agreed
  • Sub-processors, as far as the chain is reflected in the contracts

Not covered

  • Access going beyond the purpose of the service commissioned
  • Analysis of the holdings for the provider’s own purposes
  • Passing on to third parties who do not contribute to the service
  • Permanent access where access in the event of a fault would do

The measure is necessity for the service commissioned and not the convenience of operations. A remote maintenance connection standing permanently open, although it is needed only when something breaks, goes beyond that.

The processing agreement governs the processing, not the confidentiality

Whether the contract put forward suffices is decided by which duty it actually concerns. Article 28(3) GDPR requires several undertakings, among them instructions, security of processing and confidentiality of the persons authorised to process. That is data protection law and it addresses the controller as an organisation.

The duty of secrecy under section 203 StGB is a different duty with a different addressee. It attaches to the person, it is criminally sanctioned, and under section 203(4) sentence 2 no. 1 StGB it requires its own undertaking from the contributing person. The two provisions stand alongside each other and neither replaces the other.

Criteria for choosing the provider

Which provider comes into question is decided by the reach of the undertaking. It has to be contractually possible, and it has to reach through to the sub-processors, because section 203(4) sentence 2 no. 2 StGB imposes the same duty there. Standard terms of large providers frequently do not allow for it.

  1. Level 1: The professional binds the provider

    They have to ensure that the contributing person was bound to secrecy, section 203(4) sentence 2 no. 1 StGB.

  2. Level 2: The provider binds its staff and its sub-processors

    Where it engages further contributing persons, the same duty falls on it, section 203(4) sentence 2 no. 2 StGB.

  3. Level 3: Each level answers for its own care

    Whoever discloses is liable under section 203(4) sentence 1 StGB. Being bound by the level above does not relieve them.

Section 203 StGB prescribes no particular form. What is required is to ensure the undertaking, and that has to be demonstrable in a dispute. A written or electronic record is therefore the practical route, whatever individual professional codes require on top.

A provider failing these points is not a formality to be fixed but a refusal. Where the cooperation begins regardless, the risk of criminal liability stays with the professional.

How we help

Not covered here are the further requirements of individual professional codes, the social secrecy provisions, and secrecy in the public sector under section 203(2) StGB.

Cloud or remote maintenance planned?

We go through the provider terms before you sign. Little can be renegotiated afterwards.

Have the contract checked

Frequently asked questions

Who does this apply to?

To the professions listed in section 203(1) StGB, among them healthcare professions with state-regulated training, professional psychologists, notaries, auditors, tax advisers as well as recognised counselling centres and private billing agencies. The criminal provision applies to all of them alike. Individual professional codes impose further requirements on the contract.

Is a processing agreement enough?

No. Article 28(3) GDPR governs the processing, that is instructions, security and sub-processors, and requires confidentiality of the persons authorised to process. The criminally sanctioned duty of secrecy under section 203 StGB is something else. It attaches to the person rather than the organisation and requires its own undertaking under section 203(4) sentence 2 no. 1 StGB.

What must the undertaking look like?

Section 203 StGB prescribes no particular form. What is required is to ensure that the contributing person has been bound to secrecy. In a dispute that has to be shown, which is why a written or electronic record is the practical route. It is also sensible to limit access expressly to what the service requires, because section 203(3) sentence 2 StGB draws the line there.

What applies to the provider's sub-processors?

The same duty, one step further along. Under section 203(4) sentence 2 no. 2 StGB the contributing person commits an offence by engaging a further contributing person without ensuring that they are bound. The contract therefore has to reflect the chain, and a provider unable to bind its sub-processors does not come into question.

When is no separate undertaking needed?

Where the contributing person is itself bound to professional secrecy. Section 203(4) sentence 2 no. 1 StGB expressly excludes that case, because the duty already exists by statute. Also outside the rule are one's own professional assistants, since disclosure to them is not disclosure at all under section 203(3) sentence 1 StGB.

Related