Externe/en: Unterschied zwischen den Versionen
Weitere Optionen
Isan (Diskussion | Beiträge) Keine Bearbeitungszusammenfassung |
KoKl (Diskussion | Beiträge) Keine Bearbeitungszusammenfassung |
||
| (8 dazwischenliegende Versionen von 3 Benutzern werden nicht angezeigt) | |||
| Zeile 2: | Zeile 2: | ||
Externals in the context of data protection are external legal or natural entities, meaning companies or people, who receive personal data from your company or transmit them to you. The management of those externals is fundamental for GDPR compliance. As a company, you must be able to give information about which externals you have received personal data from and which externals you transmit them to. In a processing activity, there's a record of which externals give and receive which data, respectively, which allows you to fulfill the duty to disclose. | Externals in the context of data protection are external legal or natural entities, meaning companies or people, who receive personal data from your company or transmit them to you. The management of those externals is fundamental for GDPR compliance. As a company, you must be able to give information about which externals you have received personal data from and which externals you transmit them to. In a processing activity, there's a record of which externals give and receive which data, respectively, which allows you to fulfill the duty to disclose. | ||
As a data protection | As a data protection Expert or Professional, you will see all external companies and persons created in the data protection management system under "Data protection → Externals". Here you can record new externals or edit those already created. | ||
Experts who additionally have a Supply Chain Risk Management license see a link button next to the plus button above. With this, you can link external parties with [[Special:MyLanguage/Lieferanten|suppliers]]. Accordingly, there is also a "Linked supplier" column that provides an overview of these links. You can find out more on the dedicated page on [[Special:MyLanguage/Lieferanten_und_Externe_verknüpfen|Linking]]. | |||
[[Datei:Externe Übersicht.png|left|thumb|900px|Overview of externals]] | [[Datei:Externe Übersicht.png|left|thumb|900px|Overview of externals]] | ||
| Zeile 17: | Zeile 16: | ||
To edit an external, double-click on the name in the overview. | To edit an external, double-click on the name in the overview. | ||
[[Datei:Externe bearbeiten.png|left|thumb| | [[Datei:Externe bearbeiten.png|left|thumb|901px|Create/edit external]] | ||
<br clear=all> | <br clear=all> | ||
<b>Caution:</b> Once created, externals can no longer be deleted. They can only be changed from active to deactivated. | <b>Caution:</b> Once created, externals can no longer be deleted. They can only be changed from active to deactivated. | ||
<u>X links:</u> If the external is used in one or more processing activities, this is shown here. X shows the number of links of the external. Clicking the linktext opens a window that lists all the PAs. | |||
<u>Abbreviation and designation:</u> | <u>Abbreviation and designation:</u> | ||
| Zeile 35: | Zeile 35: | ||
<u>Recipient not in EU:</u> If the recipient is not located in the EU, this must be marked. In addition, appropriate safeguards must also be specified for this case, so that these externals may receive personal data compliant with the General Data Protection Regulation. | <u>Recipient not in EU:</u> If the recipient is not located in the EU, this must be marked. In addition, appropriate safeguards must also be specified for this case, so that these externals may receive personal data compliant with the General Data Protection Regulation. | ||
<u>Recipient is a processor:</u> "Processor" can be a natural or legal person, a government agency, institution, or other entity that processes personal data on behalf of your company. In the course of this, you must provide information about the scope of this processing and upload documents such as contracts and agreements with the processor. | <u>Recipient is a processor:</u> "Processor" can be a natural or legal person, a government agency, institution, or other entity that processes personal data on behalf of your company. In the course of this, you must provide information about the scope of this processing and upload documents such as contracts and agreements with the processor. Whether there are documents with an external can be optionally shown in the overview. | ||
<u>Purpose and legal basis:</u> The transmission to certain categories of recipients are often based on a previously determinable purpose and legal basis for the transmission to this category of recipients. Record standardized purpose and legal basis here, in order to automatically take over this information in processing activities. They can afterwards be manually modified in individual processing activities. | |||
<u>Address:</u> The address of the external. | <u>Address:</u> The address of the external. | ||
Aktuelle Version vom 7. August 2026, 09:02 Uhr
Externals in the context of data protection are external legal or natural entities, meaning companies or people, who receive personal data from your company or transmit them to you. The management of those externals is fundamental for GDPR compliance. As a company, you must be able to give information about which externals you have received personal data from and which externals you transmit them to. In a processing activity, there's a record of which externals give and receive which data, respectively, which allows you to fulfill the duty to disclose.
As a data protection Expert or Professional, you will see all external companies and persons created in the data protection management system under "Data protection → Externals". Here you can record new externals or edit those already created.
Experts who additionally have a Supply Chain Risk Management license see a link button next to the plus button above. With this, you can link external parties with suppliers. Accordingly, there is also a "Linked supplier" column that provides an overview of these links. You can find out more on the dedicated page on Linking.

Create/edit externals
To create an external, click the "Plus" button in the overview.
To edit an external, double-click on the name in the overview.

Caution: Once created, externals can no longer be deleted. They can only be changed from active to deactivated.
X links: If the external is used in one or more processing activities, this is shown here. X shows the number of links of the external. Clicking the linktext opens a window that lists all the PAs.
Abbreviation and designation:
- Abbreviation: internal abbreviation of the external party.
- Designation: e.g. name of the company or person that receives personal data.
Description: Here, you explain what function the external performs.
Industry: The industry in which the external is active.
Is responsible for processing activity: Must be enabled for the external to be displayed in the selection for Responsible in a processing activity.
Recipient not in EU: If the recipient is not located in the EU, this must be marked. In addition, appropriate safeguards must also be specified for this case, so that these externals may receive personal data compliant with the General Data Protection Regulation.
Recipient is a processor: "Processor" can be a natural or legal person, a government agency, institution, or other entity that processes personal data on behalf of your company. In the course of this, you must provide information about the scope of this processing and upload documents such as contracts and agreements with the processor. Whether there are documents with an external can be optionally shown in the overview.
Purpose and legal basis: The transmission to certain categories of recipients are often based on a previously determinable purpose and legal basis for the transmission to this category of recipients. Record standardized purpose and legal basis here, in order to automatically take over this information in processing activities. They can afterwards be manually modified in individual processing activities.
Address: The address of the external.
Contact: Contact details of the external.
Contact person: The contact person with the external.