Skip to main content

Data protection and DPA fundamentals (GDPR roles and responsibilities )

A Data Processing Agreement (DPA) is a legally binding contract that governs how personal data is processed when one party handles data on behalf of another.

Definition

GDPR Article 28 governs the relationship between a data controller and a data processor that handles personal data on the controller's behalf, and a Data Processing Agreement (DPA) is the standard way to document those terms. Putting Article 28 terms in place is the controller's responsibility, and Debitura makes a DPA available on request rather than requiring one. The DPA defines how personal data must be processed, what security measures apply, and the responsibilities of each party.

In the context of debt collection:

  • Data Controller: The entity that determines the purposes and means of processing personal data. Clients are data controllers for debtor data because they decide to use Debitura for debt recovery.

  • Data Processor: The entity that processes personal data on behalf of the controller, following the controller's instructions. Debitura acts as a data processor for Clients.

  • Data Subject: The individual whose personal data is being processed. In debt collection, this is typically the Debtor.

When a DPA applies

Article 28 terms are the creditor's responsibility to put in place as data controller, and a DPA is the standard way to document them for creditors based in the EU or handling personal data of EU residents. Signing one is not a precondition for using Debitura or for uploading cases. The Standard Debt Collection Agreement (SDCA) already defines the data protection role of each party (SDCA §01.G), and a signed DPA prevails over the SDCA on personal data processing (SDCA §13.2).

Debitura provides a self-service DPA wizard where Clients can generate, review, and digitally sign a DPA online. This process captures an immutable snapshot of your company information at signing time, along with the signature itself, the signer's name and email, the signing timestamp, and a SHA256 hash of the signed PDF so the document's integrity can be verified later.

If your account is later anonymised at your request, the detailed DPA audit history is deleted. The record that a DPA was signed, by whom and when, is retained. If instead a collection partner anonymizes, that partner's DPA audit rows survive, but their IP address, user agent, browser data and event payload are cleared.

Key elements of the Debitura DPA

Element

Description

Parties

The Client (data controller) and Debitura LLC (data processor)

Purpose

Processing debtor personal data for debt collection services

Data categories

Debtor contact information, claim details, payment history, and communications

Processing instructions

Debitura processes data only as instructed by the Client and in accordance with the platform's debt collection workflows

Security measures

Technical and organisational measures to protect personal data, including audit trails and access controls

Sub-processors

Any third parties Debitura engages to assist with processing (disclosed in the DPA)

Data subject rights

Procedures for handling data subject requests (access, rectification, erasure)

Retention and deletion

Rules for how long data is kept and when it must be deleted

Privacy policy requirements

Under GDPR Article 13, Clients must inform debtors about third-party processors handling their data. After signing a DPA, Clients receive a privacy policy snippet to add to their website. The snippet text varies based on whether the Client operates in an EU or non-EU context.

Confidentiality

Beyond the DPA, confidentiality is addressed in multiple agreements within the Debitura platform:

  • Standard Debt Collection Agreement (SDCA): Contains a confidentiality clause stating that all information exchanged under the agreement is confidential and shall not be disclosed to third parties without consent, except as required by law.

  • Partnership Agreement (Collection Partners): Requires Collection Partners to maintain the confidentiality of all information disclosed by Debitura, using such information solely for the purpose of providing services to Clients. This includes protecting sensitive data and not disclosing it to third parties without prior written consent.

Collection Partners and data processing

Collection Partners who receive cases from Debitura also process debtor personal data. The SDCA states that Debitura and the Collector (Collection Partner) will process personal data in accordance with applicable data protection laws (such as GDPR). The Collection Partner acts as an independent data processor on behalf of the Client, not as a sub-processor of Debitura. Separate Data Processing Agreements may be signed upon request, and Clients may request a separate DPA directly with the Collection Partner.

Currently, Debitura's self-service DPA wizard is implemented for Client-Debitura agreements. The system architecture supports future Partner-Debitura and Client-Partner DPAs without requiring code changes.

Impact by actor

Client

  • Acts as data controller for debtor personal data

  • May request a DPA from Debitura at any time; signing one is not required before uploading cases

  • Must update privacy policy to inform debtors about Debitura as a processor

  • Retains ultimate responsibility for lawful data processing

Debitura

  • Debitura LLC (registered in Delaware, United States; EIN: 37-2213530) acts as data processor on behalf of Clients

  • Processes data only according to Client instructions and platform workflows

  • Provides the self-service DPA wizard for Clients

  • Maintains audit trails and security controls for compliance

Collection Partner

  • Processes debtor data as part of debt recovery activities

  • Bound by confidentiality obligations in the Partnership Agreement and SDCA

  • May sign separate DPAs upon request

Referral Partner

Debtor

  • Is the data subject whose personal data is processed

  • Has rights under GDPR including access, rectification, and erasure

  • Should be informed by the Client (via privacy policy) about Debitura's role as processor

Where to find DPA documents

Clients can access and sign their DPA through the self-service DPA wizard in the Debitura platform. After signing, Clients can download a PDF copy of the signed agreement. The signed PDF includes a SHA256 hash for integrity verification.

For broader information about Debitura's compliance practices, see Clients: Compliance and verification.

Did this answer your question?