External service providers in social institutions: Why the DPA does not regulate everything


When in addition to the GDPR, § 203 StGB and special requirements of social data protection must also be observed
Cloud services, specialized software, external IT service providers, or AI applications are long part of everyday work, even in many social institutions. If personal data is processed in the process, one of the first questions often arises: Have we concluded a contract with the provider for contract processing? This is important. However, it can be too general.
Because information can be processed in institutions providing basic social services and by social service providers that is not only protected by the GDPR. Depending on the activity and the people involved, special confidentiality obligations may also apply under § 203 StGB or regulations on social data protection. This also generally applies to professional secret keepers. Therefore, a signed AVV does not automatically mean that an external service provider is fully legally protected.
Data protection and privacy protection are not the same thing
The GDPR protects personal data and regulates under what conditions it may be processed. § 203 StGB, on the other hand, protects the confidential information entrusted to certain professional and personal groups in the course of their activities.
In the social sector, this can include, for example, state-recognised social workers and social educators. Certain counselling professions and public officials are also covered by Section 203 of the StGB.
An example: A social worker documents information about a young person's mental illness, their family situation, and the content of personal conversations in an electronic client file.
This information is personal and is at the core of the development from child to adult. At the same time, this information can constitute secrets within the meaning of Section 203 of the StGB. Health information, such as mental illness, is also considered a special category under data protection law according to Article 9 of the GDPR, for which increased requirements already apply.
Not every social institution falls under § 203 StGB automatically
However, it is important to note that § 203 of the StGB does not apply in a general way to every social institution and every person employed there.
What matters is rather which individuals and functions are actually involved. § 203 of the StGB lists certain professional and personal groups for this purpose. These include, in the social sector, for example, state-recognized social workers and social educators, as well as, under certain conditions, marriage, family, educational, youth, and addiction counselors. Officials and persons particularly obligated to perform public duties may also be included.
For the practice, this means that in the first step it is necessary to determine whether professional secrecy investigations within the meaning of Section 203 of the StGB are involved in the data processing process, which is supported by the external service provider.
Only then does the next question arise: Can the external service provider access secrets that this person has entrusted or learned about in the course of their work?
Why the DPA alone is not always enough
An AVV under Article 28 of the GDPR and the requirements of Section 203 of the StGB serve different functions.
The AVV regulates the processing of personal data on behalf of its clients. This includes, for example, requirements regarding instructions, confidentiality, technical and organizational measures, and the use of other contract processors.
Section 203 of the Criminal Code, on the other hand, places the protection of other people's secrets at the forefront.
This does not mean, however, that protected persons are not allowed to employ external service providers. The law explicitly recognizes that additional persons can contribute to their professional or service activities (§ 203, paragraph 3, StGB).
External service providers may therefore be involved. However, they may only be given access to protected secrets to the extent necessary for their specific involvement.
This can become relevant, for example, in the case of:
Therefore, it is not only important whether a service provider actively reads data; technical access and support options can also be relevant in the assessment.
Confidentiality must also be regulated.
If § 203 StGB is applied, another point becomes important: the obligation of the participating service provider to maintain secrecy. The professional secret keeper must ensure that any other participating person is also required to maintain secrecy (§ 203, paragraph 4, sentence 2 StGB).
In addition, the person involved themselves – for example, the service provider or their employees – can be held criminally liable if they disclose such a secret without authorization (§ 203, paragraph 4, sentence 1, StGB). The duty of secrecy thus applies not only to the person originally protected under § 203 StGB, but also to other persons who are involved in the processing operations with regard to the protected secret.
This does not necessarily require an additional document with the title „Agreement pursuant to § 203 StGB“. What is crucial, however, is whether the necessary regulations are already effectively included in the existing contract. This may be the case, for example, in the service contract or AVV. If no corresponding regulations are in place, an addition may be necessary and should be agreed upon. For companies and institutions, it is therefore worthwhile taking a closer look at the existing contracts.
And what about the social secret?
In certain institutions, special social data protection may also be relevant. § 35 of the Social Security Act I protects so-called social confidentiality. For the processing of social data on behalf of the institution, § 80 of the Social Security Act X contains further requirements. These may include, for example, that the assignment must be indicated in advance to the competent legal or professional supervisory authority (§ 80, paragraph 1, of the Social Security Act X).
Here too, it is important to note that not all social institutions automatically fall under the same social data protection regulations; these regulations are based on the provisions mentioned in § 35, paragraph 1, of the Social Security Act (specifically, social welfare providers and the providers of services for them). Depending on the specific circumstances, the GDPR, § 203 of the StGB, and social data protection may therefore be considered in parallel.

What does this have to do with AI?
The topic is not new. However, it is becoming particularly visible due to the increasing use of generative AI. For example, if a state-recognized social worker enters information from a specific client case into an externally operated AI system, the secrets of the AI system provider and, if applicable, any other service providers involved may become accessible. State-recognized social workers are expressly included among the professions covered by Section 203 of the StGB.
Then the question is: „Does the AI provider have an AVV?“ It often isn’t possible to exclude this. It must be checked which information is being processed, which other providers are involved, and whether the requirements of data protection are being met. The same applies to other external systems.
Six questions before hiring a service provider
Instead of concluding additional agreements with each service provider in a general manner, it is advisable to conduct a structured review:
Conclusion
Having a completed AVV is often an important component when integrating external service providers. However, it does not automatically answer all legal questions.
An AVV can only be part of the examination
Especially in social institutions, it should be further examined whether protected secrets are affected by § 203 StGB or whether special requirements of social data protection apply.
This applies not only to AI; professional software, cloud providers, hosting, document management systems, or IT support can also be relevant.
An additional question in service provider management can therefore make a big difference: „Can the protected secrets of this service provider be accessed – and if so, have we taken these requirements into account?“
FAQ
Does every social institution have to comply with § 203 of the StGB?
No. What is crucial is whether persons belonging to the categories of persons mentioned in § 203, paragraph 1 or 2 of the StGB are involved, and whether they have entrusted corresponding secret information to others or have otherwise become aware of it.
Is an AVV sufficient for an external service provider?
Not necessarily. The AVV regulates the data protection requirements for commissioned processing in accordance with Article 28 of the GDPR. If additional secrets are involved within the meaning of Section 203 of the StGB, the requirements therein must also be taken into account.
Does a separate agreement under § 203 StGB always have to be concluded?
No. What is crucial is that the required confidentiality obligation is effectively ensured. Whether this is done in a separate document or already in the existing contract depends on the specific contract structure.
Does this also apply to AI providers?
That may be the case. If confidential information protected by § 203 StGB is made available to an external AI provider in the context of the activities of a person covered by § 203 StGB, § 203 StGB must also be taken into account in the examination.
What additional requirements may apply regarding social data protection?
In certain instances, in addition to the GDPR, the social secrecy under § 35 SGB I may also be relevant. For the processing of social data on behalf of the social security institution, § 80 SGB X contains additional requirements, which, depending on the specific circumstances, may also include a prior notification to the competent supervisory authority.
What should social institutions consider before hiring a service provider?
In particular, you should clarify whether professional secret keepers are involved, what information the service provider processes, whether protected secrets can be accessed by him/her, and whether such access is necessary. Additionally, it should be examined whether the requirements of the GDPR, § 203 StGB, and, if applicable, social data protection have been fully taken into account.
- When in addition to the GDPR, § 203 StGB and special requirements of social data protection must also be observed
- Data protection and privacy protection are not the same thing
- Not every social institution falls under § 203 StGB automatically
- Why the DPA alone is not always enough
- Confidentiality must also be regulated.
- And what about the social secret?
- What does this have to do with AI?
- Six questions before hiring a service provider
- Conclusion
- Check the mandatory fields – step by step in the webinar
- FAQ
- Does every social institution have to comply with § 203 of the StGB?
- Is an AVV sufficient for an external service provider?
- Does a separate agreement under § 203 StGB always have to be concluded?
- Does this also apply to AI providers?
- What additional requirements may apply regarding social data protection?
- What should social institutions consider before hiring a service provider?
- FAQ



