Controller: Office Club AG, Friedrichstraße 171, 10117 Berlin
As of: 3 June 2025
1. Physical Access Control
Obligation of the Contractor to prevent unauthorised persons from gaining physical access to data processing equipment used to process the contract data (physical access control).
Implemented by: alarm system, engagement of an external security service, transponder locking system, video surveillance of entrances, intercom systems at entrances, motion detectors, role-based authorisation management for employee access, careful selection of cleaning and security staff, a general “no-visitors policy” with visitor badges used for exceptions. For remote workplaces: contractual obligation to separate the work area from the living area, requirement to keep a distance from persons not entrusted with the service.
2. System Access Control
Obligation of the Contractor to prevent data processing systems from being used by unauthorised persons, in particular through the use of encryption methods that reflect the current state of the art (system access control).
Implemented by: secure passwords (to be created in accordance with defined rules) for user accounts; automatic locking mechanisms; two-factor authentication; encryption of databases and data storage media; VPN or TLS connections requiring a user name and password
3. Data Access Control
Obligation of the Contractor to ensure, in particular through the use of authentication and encryption methods that reflect the current state of the art, that persons authorised to use a data processing system can access only the contract data covered by their access authorisation, process such data only on the instructions of the Contractor, and that contract data cannot be read, copied, altered or removed without authorisation during processing (data access control).
Implemented by: role-based authorisation management for employee access; logging of access; authentication and encryption methods; secure passwords; automatic locking mechanisms; “clean desk policy”
4. Transfer Control
Obligation of the Contractor to ensure, in particular through the use of authentication and encryption methods that reflect the current state of the art, that contract data cannot be read, copied, altered or removed without authorisation during electronic transmission or transport, and that it is possible to verify and establish to which bodies contract data are intended to be transmitted by means of data transmission facilities (transfer control).
Implemented by: TLS encryption of web services and notification e-mails; virtual private networks (VPN); engagement of trustworthy courier services for the transport of data storage media
5. Input Control
Obligation of the Contractor to ensure that it is possible to subsequently verify and establish whether and by whom contract data have been entered into, altered in, transmitted from or removed from data processing systems (input control), and that contract data can be attributed to their origin at any time (authenticity control).
Implemented by: logging of data access; document management; documentation of incoming and outgoing data
6. Availability Control
Obligation of the Contractor to ensure that contract data are protected against accidental or deliberate destruction or loss (availability control). This includes in particular ensuring the resilience of systems and services, safekeeping the contract data in accordance with the principles of proper data backup, and regular data safeguarding, including regular backups, to the extent required.
Implemented by: write protection/version control; backup strategy including storage of backup data outside the data centre; uninterruptible power supply (UPS); virus protection; firewall; system maintenance/load tests; updates; reporting channels and emergency plans
7. Separation Control
Obligation of the Contractor to ensure that contract data collected for different purposes can be processed separately (separation control).
Implemented by: separate access rights; multi-client capability; separation of production, test and development systems; limitation of the storage of employees’ private data on company systems
8. Implementation Control
Obligation of the Contractor to ensure that the data protection principles are implemented effectively and that the necessary safeguards are integrated into the processing in order to meet the requirements of data protection law and to protect the rights of data subjects.
Implemented by: instruction and training of employees; checks/spot checks
9. Effectiveness Control
Obligation of the Contractor to implement a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures for ensuring the security of the processing.
Implemented by: complete, up-to-date and transparent documentation of data processing operations; data protection management; incident response management; load tests/spot checks/simulated “external” attacks; adaptation to the state of the art (updates, training)
10. Order Control
Obligation of the Contractor to ensure that personal data are processed only in compliance with the instructions of the Client and that instructions received are implemented without undue delay.
Implemented by: clear contract drafting; instruction of employees; formalised order management; strict selection of the service provider; obligation to verify in advance; follow-up checks
This English version is provided for information purposes only; in the event of any discrepancy, only the German version shall be legally binding.