Zum Hauptinhalt springen

Overview of text module categories

When creating a new text module under "Settings > Text modules", you first select a category and the language. Text module categories are document-specific and cover areas such as processing activities, technical and organizational measures, contracts, privacy policies, data protection impact assessments, deletion concepts, audits, data transfer impact assessments and AI compliance. Each category contains specific content and fields tailored to the respective requirements.

When you want to create a new text module in the settings area under "Settings > Text modules", you first select a text module category and then the language.

Below you will find an overview of the text module categories used in the respective documents:

Processing activities

Purpose of data processing, persons/groups of persons authorized to access, legal basis, data sources, data categories, affected persons, internal recipient categories, external recipient categories within the EU, external recipient categories outside the EU, standard deadlines for deletion, legitimate interests, intention to transfer to a third country or international organization, adequacy decision of the EU Commission, safeguards and obtaining the safeguards, right to information, right to rectification, right to erasure, right to restriction of processing, right to object to processing, right to data portability, automated decision-making and profiling, right to lodge a complaint with a supervisory authority, reasons for carrying out a DPIA, risk-increasing aspects, risk-reducing aspects, possible damages (physical, material, immaterial), attackers or relevant risk sources, measures, additional information for data processing pursuant to Art. 26 (2) sentence 2 GDPR, type of publication, requirement, consequences of non-provision, right of withdrawal


Technical and organizational measures

Access control (premises), access control (systems), access control (data), separation control, transfer control, input control, pseudonymization, encryption, availability (of data), recoverability (of data / systems), order control, data protection management, incident response management, privacy-friendly default settings, resilience (of systems)

Contracts for order processing

Data processing agreement


Privacy policies

Privacy policy


Data protection impact assessments

Reasons for carrying out a DPIA, risk-increasing aspects, risk-reducing aspects, possible damages (physical, material, immaterial), attackers or relevant risk sources, measures, necessity and proportionality: assessment, necessity and proportionality: consequences / notes


Contracts for joint controllership

Joint controllership


Consent forms

Consent form


Policies

Policies


Deletion concepts

Data categories, standard deadlines for deletion, statutory provisions on the deletion obligation and possible exceptions


Audits

Notes on implementation


Data transfer impact assessments

Circumstances of the transfer, legal provisions, applicable restrictions and safeguards, format of the data, economic sector, transmission channels, intention to transfer to a third country or international organization, data categories, legal basis, purpose of data processing


Processing activities on behalf

Legal basis


AI compliance: technical and organizational measures

AI: access control, AI: permission management, AI: encryption and protection of sensitive data, AI: logging, AI: security monitoring, AI: security audits and tests, AI: emergency preparedness, AI: recovery management, AI: ensuring data quality, AI: validation and control of data sources, AI: documentation of AI models, AI: explanations for users, AI: professional qualification, AI: awareness of risks and responsibility


Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.