External service providers in social institutions: Why the DPA does not regulate everything

Cindy Stefanet
by Cindy Stefanet · 09.09.2026
Data Protection

When in addition to the GDPR, § 203 StGB and special requirements of social data protection must also be observed

Cloud services, specialized software, external IT service providers, or AI applications are long part of everyday work, even in many social institutions. If personal data is processed in the process, one of the first questions often arises: Have we concluded a contract with the provider for contract processing? This is important. However, it can be too general.

Because information can be processed in institutions providing basic social services and by social service providers that is not only protected by the GDPR. Depending on the activity and the people involved, special confidentiality obligations may also apply under § 203 StGB or regulations on social data protection. This also generally applies to professional secret keepers. Therefore, a signed AVV does not automatically mean that an external service provider is fully legally protected.

Data protection and privacy protection are not the same thing

The GDPR protects personal data and regulates under what conditions it may be processed. § 203 StGB, on the other hand, protects the confidential information entrusted to certain professional and personal groups in the course of their activities.

In the social sector, this can include, for example, state-recognised social workers and social educators. Certain counselling professions and public officials are also covered by Section 203 of the StGB.

An example: A social worker documents information about a young person's mental illness, their family situation, and the content of personal conversations in an electronic client file.

This information is personal and is at the core of the development from child to adult. At the same time, this information can constitute secrets within the meaning of Section 203 of the StGB. Health information, such as mental illness, is also considered a special category under data protection law according to Article 9 of the GDPR, for which increased requirements already apply.

Not every social institution falls under § 203 StGB automatically

However, it is important to note that § 203 of the StGB does not apply in a general way to every social institution and every person employed there.

What matters is rather which individuals and functions are actually involved. § 203 of the StGB lists certain professional and personal groups for this purpose. These include, in the social sector, for example, state-recognized social workers and social educators, as well as, under certain conditions, marriage, family, educational, youth, and addiction counselors. Officials and persons particularly obligated to perform public duties may also be included.

For the practice, this means that in the first step it is necessary to determine whether professional secrecy investigations within the meaning of Section 203 of the StGB are involved in the data processing process, which is supported by the external service provider.

Only then does the next question arise: Can the external service provider access secrets that this person has entrusted or learned about in the course of their work?

Why the DPA alone is not always enough

An AVV under Article 28 of the GDPR and the requirements of Section 203 of the StGB serve different functions.

The AVV regulates the processing of personal data on behalf of its clients. This includes, for example, requirements regarding instructions, confidentiality, technical and organizational measures, and the use of other contract processors.

Section 203 of the Criminal Code, on the other hand, places the protection of other people's secrets at the forefront.

This does not mean, however, that protected persons are not allowed to employ external service providers. The law explicitly recognizes that additional persons can contribute to their professional or service activities (§ 203, paragraph 3, StGB).

External service providers may therefore be involved. However, they may only be given access to protected secrets to the extent necessary for their specific involvement.

This can become relevant, for example, in the case of:

  • Professional and case management software,
  • Cloud and hosting services,
  • Document management systems,
  • IT support and remote maintenance or
  • externally operated AI systems.

Confidentiality must also be regulated.

If § 203 StGB is applied, another point becomes important: the obligation of the participating service provider to maintain secrecy. The professional secret keeper must ensure that any other participating person is also required to maintain secrecy (§ 203, paragraph 4, sentence 2 StGB).


In addition, the person involved themselves – for example, the service provider or their employees – can be held criminally liable if they disclose such a secret without authorization (§ 203, paragraph 4, sentence 1, StGB). The duty of secrecy thus applies not only to the person originally protected under § 203 StGB, but also to other persons who are involved in the processing operations with regard to the protected secret.


This does not necessarily require an additional document with the title „Agreement pursuant to § 203 StGB“. What is crucial, however, is whether the necessary regulations are already effectively included in the existing contract. This may be the case, for example, in the service contract or AVV. If no corresponding regulations are in place, an addition may be necessary and should be agreed upon. For companies and institutions, it is therefore worthwhile taking a closer look at the existing contracts.

And what about the social secret?

In certain institutions, special social data protection may also be relevant. § 35 of the Social Security Act I protects so-called social confidentiality. For the processing of social data on behalf of the institution, § 80 of the Social Security Act X contains further requirements. These may include, for example, that the assignment must be indicated in advance to the competent legal or professional supervisory authority (§ 80, paragraph 1, of the Social Security Act X).


Here too, it is important to note that not all social institutions automatically fall under the same social data protection regulations; these regulations are based on the provisions mentioned in § 35, paragraph 1, of the Social Security Act (specifically, social welfare providers and the providers of services for them). Depending on the specific circumstances, the GDPR, § 203 of the StGB, and social data protection may therefore be considered in parallel.

A service provider, three possible testing grounds: GDPR: Is data processing involved? Privacy protection: Are confidential data affected? Social data protection: Do special regulations apply to social data?

What does this have to do with AI?

The topic is not new. However, it is becoming particularly visible due to the increasing use of generative AI. For example, if a state-recognized social worker enters information from a specific client case into an externally operated AI system, the secrets of the AI system provider and, if applicable, any other service providers involved may become accessible. State-recognized social workers are expressly included among the professions covered by Section 203 of the StGB.

Then the question is: „Does the AI provider have an AVV?“ It often isn’t possible to exclude this. It must be checked which information is being processed, which other providers are involved, and whether the requirements of data protection are being met. The same applies to other external systems.

Six questions before hiring a service provider

Instead of concluding additional agreements with each service provider in a general manner, it is advisable to conduct a structured review:

  • Are there any individuals involved who are subject to § 203 of the Criminal Code?
  • What information does the service provider receive or process?
  • Can protected secrets be made available to him in the process?
  • Is this access necessary for his/her specific activity?
  • Is the necessary confidentiality also ensured for other involved persons?
  • 6. Do the requirements of the GDPR or of social data protection apply in addition?

Conclusion

Having a completed AVV is often an important component when integrating external service providers. However, it does not automatically answer all legal questions.

An AVV can only be part of the examination


Especially in social institutions, it should be further examined whether protected secrets are affected by § 203 StGB or whether special requirements of social data protection apply.


This applies not only to AI; professional software, cloud providers, hosting, document management systems, or IT support can also be relevant.
An additional question in service provider management can therefore make a big difference: „Can the protected secrets of this service provider be accessed – and if so, have we taken these requirements into account?“

Check the mandatory fields –
Step-by-step in the webinar

FAQ

Does every social institution have to comply with § 203 of the StGB?


Is an AVV sufficient for an external service provider?


Does a separate agreement under § 203 StGB always have to be concluded?

Does this also apply to AI providers?


What additional requirements may apply regarding social data protection?


What should social institutions consider before hiring a service provider?