Knowledgedocuments

Document Management and GDPR: what you need to know

DMS and data protection: hosting location, data processing agreements, access controls, and the tension between deletion obligations and retention periods.

A document management system almost inevitably processes personal data – names on invoices, addresses in contracts, salary data in personnel files. This means GDPR obligations apply: you need secure processing, regulated access, a contract with the provider, and a concept that clearly separates retention obligations from deletion obligations.

Why DMS is automatically a data protection issue

GDPR does not distinguish between “database” and “document storage”. A scanned letter with a sender’s name is just as personal data as a CRM entry. Whoever stores documents centrally, makes them searchable, and shares them with the team processes this data – and must do so responsibly. This is not a reason against a DMS; quite the opposite: a central, regulated filing system is much easier to operate in compliance with GDPR than scattered folders, local copies, and private email inboxes.

The five most important evaluation points when choosing

  • Hosting location and applicable law: Where do the data physically reside, which law applies to the provider? Hosting in Germany or the EU saves you the review of third-country transfers.
  • Data Processing Agreement (DPA): The provider stores documents on your behalf and is therefore usually a data processor. Without a DPA, the contractual foundation is missing.
  • Access control: Not everyone on the team needs to see everything. Pay attention to roles and visibility rules – personnel files belong in different hands than incoming invoices.
  • Encryption and secure login: Transmission encrypted, access protected – for example via one-time codes instead of shared passwords.
  • Traceability: It should be clear what happened to documents. This also helps with access requests from data subjects.

The tension: delete vs. retain

GDPR requires you to delete personal data once the purpose is no longer applicable. At the same time, tax and commercial law require you to retain documents for years. The resolution: legal retention obligations are a separate legal basis – tax-relevant documents remain in the archive until their period expires. Then the deletion obligation applies. A good DMS supports exactly this lifecycle: defined retention instead of “just sitting there”. How immutable archiving works is explained in the article Audit-Proof Archiving.

How webRichtung documents implements this

webRichtung documents combines filing, email import, batch processing, and archive search in one documents area. This lets you implement and audit your organizational rules for intake, retention, and access in one central place instead of distributing documents across local folders. Details on how to use it can be found in the documentation.

Practical getting started

Start with a brief inventory: what types of documents with personal reference do you have (receipts, contracts, personnel files)? Who needs access to what? What retention periods apply to each type? With these three answers, you can evaluate a DMS in a structured way – and document the implementation clearly in case the supervisory authority asks. Also define how access ends when someone leaves the team. These central guardrails make a case for a shared operating system rather than locally copied folders whose whereabouts no one can track anymore.

This article provides general information and is not a substitute for legal or tax advice.

Frequently asked questions

Why is a DMS a GDPR issue?

Invoices, contracts and correspondence contain personal data of customers, suppliers and employees. Once a DMS stores and processes such documents, GDPR obligations apply.

What should I pay attention to when selecting a DMS?

The hosting location and applicable law, a data processing agreement (DPA), role-based access control, encrypted transmission and traceable logging of access.

How do deletion obligations and retention periods fit together?

Legal retention obligations take precedence over deletion: tax-relevant documents must be retained even if they contain personal data. After the period expires, the deletion obligation then applies.

Do I need a DPA with my DMS provider?

As a rule, yes: if the provider stores documents with personal data on your behalf, they are a data processor – then GDPR requires a data processing agreement.

Is a German data center mandatory?

No, GDPR does not prescribe a location. However, hosting in Germany or the EU significantly simplifies the legal assessment because no third-country transfer needs to be reviewed.

webRichtung Documents

Find information in your documents

Search receipts and documents by content. Find the information you need even when you do not know the file name.