A data processing agreement is concluded for every data room. It covers all the points of Article 28(3) GDPR; the details are set out in the following section. It may be concluded in electronic form under Article 28(9) GDPR. We provide a template before the contract is concluded so that your legal department can review it in advance.
The technical and organisational measures pursuant to Article 32 GDPR are documented as an annex to the agreement, with a date and version status. We maintain a record of processing activities pursuant to Article 30(2) GDPR. We review the effectiveness of the measures at defined intervals and document the outcome. Tobias Streckel, Managing Director, is responsible for this.
Real estate data rooms regularly contain personal data: tenant names in leases, tenancy schedules and arrears lists, contact details and bank details, surety bonds and credit reports, evidence of deposits, extracts from the Grundbuch (land register) showing owners, rights holders and holders of land charges, Erbbaurecht agreements, the Teilungserklärung (declaration of division) with the list of owners and the minutes of the owners' meetings, extracts from the register of Baulasten (public-law building encumbrances), documents on site personnel including the particulars under Section 613a BGB, and anti-money-laundering documents on the beneficial owner. Occasionally special categories of personal data under Article 9 GDPR occur. We draw attention to such documents separately before any release is granted.
We therefore work with redaction and pseudonymisation. In the first phase of a bidding process, personal data are as a rule made illegible or replaced by identifiers; the complete version is only released once the field of bidders has been narrowed. Redaction is destructive: the content concerned is removed from the document, not covered over. The redacted version is newly generated, and the search index is built exclusively from that version. The unredacted original file remains separate and is not released. Before every release to a bidder group we check on a sample basis that the text layer and the search index no longer contain any redacted content. You take the decision on scope and timing; we prepare it and point out the document classes concerned.
Release to a bidder is a transfer: the bidder becomes a controller in its own right for the data received. The legal basis and the balancing of interests lie with you; you govern the bidder's confidentiality and deletion obligations in the confidentiality agreement. We provide the basis for this: an overview of the document classes released per phase and bidder group, together with evidence of what was actually available.
We support you in the case of requests from data subjects under Articles 15 to 22 GDPR – you fulfil the rights as controller, not us. If we become aware of a personal data breach, we notify you without undue delay in accordance with Article 33(2) GDPR; notification of the supervisory authority is a matter for you.
Once the project has been completed, you decide how the documents are to be dealt with: complete deletion, return as a structured export, or handover of a closed data room archive including the index, Q&A trail, log extract and the release and visibility history. The periods for deletion and for the run-off of the backups are quantified in the contract. Statutory retention obligations remain unaffected (Article 28(3)(g) GDPR); we identify the affected data before deletion. On request, you receive a complete data export in open file formats before deletion.