QS-VO 2024 course All courses

Lesson 8.4 · 4 min

§ 16 The IT provider's data-protection confirmation

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

What § 16(5) requires

An IT company you engage that comes into contact with personal data of patients or staff confirms, with proof, that the GDPR is complied with, also with regard to the staff it deploys § 16(5). If you work without such a company, no confirmation is needed.

Who that can be

The QS-VO doesn't list companies. Any company whose work can bring it into contact with such data qualifies, for example:

Confirmation and contract

Separately from § 16(5), the GDPR requires a contract whenever a company processes personal data on your behalf GDPR Art. 28(3). Make sure your paperwork covers both: the contract, and the confirmation that the company's staff comply with the GDPR too.

What works as proof

Checklist

Quiz

What does § 16(5) require of an IT company that comes into contact with patient data?

  1. A registered office in Austria
  2. A confirmation, with proof, that it complies with the GDPR, its staff included
  3. Nothing, as long as it doesn't store the data
  4. ISO 27001 certification
Show the answer

The answer is B: A confirmation, with proof, that it complies with the GDPR, its staff included. § 16(5): the company confirms, with proof and also for its staff, that the GDPR is complied with. Coming into contact with the data is enough.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the text of the QS-VO 2024 in the Federal Legal Information System (version of 3 October 2026) and the Austrian Medical Chamber's Hygiene Regulation 2014. Not an offer of ÖQMED, the BIQG or the Medical Chamber.