Skip to main content

Clients: Compliance and verification - how Debitura protects your data and follows regulations

Debitura is designed to handle debt collection in compliance with GDPR and applicable data protection laws.

What it is

Compliance at Debitura covers three areas: data processing governance under GDPR, contractual agreements that define rights and obligations, and verification mechanisms that ensure only authorised users can sign legally binding documents.

Together, these safeguards ensure that personal data is processed lawfully, contracts are signed by verified individuals, and a complete audit trail exists for every action on the platform.

Why it matters

If your business is based in the EU or processes personal data of EU residents, GDPR Article 28 governs the relationship between you (the data controller) and any service provider processing data on your behalf (the data processor). A Data Processing Agreement is the standard way to document those terms, and putting them in place is your responsibility as controller. Debitura provides the tools and documentation needed to meet these obligations.

GDPR roles: data controller and data processor

When you use Debitura for debt collection, you act as the data controller and Debitura acts as the data processor under GDPR Article 28. This means you determine the purpose of the data processing (collecting outstanding debts), and Debitura processes debtor personal data on your behalf and under your instructions. Debitura does not use debtor data for its own purposes.

The data Debitura processes on your behalf includes debtor names, contact details, address information, financial claim details, and supporting documents you upload. For a deeper look at GDPR roles and obligations, see Data protection and DPA fundamentals.

Data Processing Agreement (DPA)

A Data Processing Agreement is available to you on request. It is the standard way to document GDPR Article 28 terms if you are based in the EU or handle personal data of EU residents, but signing one is not a precondition for using Debitura's services. The Standard Debt Collection Agreement (SDCA) already sets out each party's data protection role, and a signed DPA takes precedence over it on personal data processing.

Debitura provides a self-service DPA wizard with five steps: review your company data, review and attest your signing authority, sign digitally, add a privacy policy snippet to your website, and confirm completion. Only Admin users can access and complete the DPA wizard. For step-by-step instructions, see How to request a Data Processing Agreement (DPA).

After signing, you receive a context-aware privacy policy snippet to add to your website. This is required under GDPR Article 13 to inform debtors that Debitura processes their data on your behalf. The snippet text adapts depending on whether your context is EU or non-EU.

Required contracts: SDCA and Power of Attorney

Separately from the optional DPA, you must sign two documents before cases can be processed:

You can view and download all signed contracts from the Contracts page in the platform. For details on accessing your documents, see Where to view and download signed agreements.

Audit trails

Debitura maintains comprehensive audit trails of all data processing activities on the platform. Audit records capture what happened, who performed the action, when it occurred, and from where (IP address).

Audit records cannot be edited after they are created. They are not, however, retained unconditionally: when an account is anonymized, the IP address recorded on that account's audit events is erased ahead of the retention period, while the other fields on those events survive. The DPA audit history is treated more strictly: when the client's account is anonymized, those rows are deleted outright. The accountability record of what happened, who did it and when is what the 7-year retention protects; the IP address attached to it is not. The DPA process has its own audit log covering every step from initialisation to completion, including the signer's identity, the signing timestamp and a SHA256 hash of the signed PDF.

Data retention

Data type

Retention period

Active account and case data

While your account is active

Data after account closure

Three stages: personal data is anonymised 30 days after closure; the anonymised records are then retained for 7 years (accounting compliance); at the end of that period they are soft-deleted, and permanently removed from the database a further 6 months later

Audit logs

7 years (legal requirement), then archived for up to 10 years total

Audit log retention is based on legal requirements for accounting records and statute of limitations for legal claims. After the 7-year period, personal data within audit logs is pseudonymised while preserving the audit trail structure.

Your rights under GDPR

As the data controller, your obligations and rights under GDPR apply to the debtor data you process through Debitura. The platform supports you in fulfilling these obligations by maintaining audit trails, providing access to case and document data, and supporting data portability through case exports and document downloads.

Handling debtor GDPR requests

If a debtor submits a GDPR request to you, you are responsible as the data controller for responding. Debitura can support you:

  • Data Subject Access Requests (DSAR): Contact [email protected] to request an export of data Debitura holds on a specific debtor.

  • Erasure Requests (Article 17): Contact [email protected]. Data tied to legal obligations (audit logs, financial records) may be exempt under GDPR Article 17(3).

GDPR requests must be acknowledged within 30 days.

What to expect

With your SDCA and PoA in place, you are set up to use Debitura. A signed DPA and a published privacy policy snippet further document your GDPR position. If your company data changes or a new DPA template version is released, you can delete your existing DPA and complete the wizard again with updated information. Contract version updates are prompted automatically when a new version is available.

For questions about data privacy and what information is visible to different parties, see Data privacy and document visibility. If you experience issues with email verification during contract signing, see Email verification troubleshooting.

Compliance contacts

Topic

Contact

DPA requests and GDPR compliance questions

Legal questions, formal complaints, erasure requests

Did this answer your question?