Lesson 8.4 · 4 min
§ 16 The IT provider's data-protection confirmation
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- Who it concerns. Any IT company you engage that comes into contact with personal data of patients or staff.
- What it confirms. With proof, that it complies with the GDPR, also for the staff it deploys.
- Plus the contract. If the company processes data on your behalf, the GDPR also requires a data processing agreement.
In detail
What § 16(5) requires
An IT company you engage that comes into contact with personal data of patients or staff confirms, with proof, that the GDPR is complied with, also with regard to the staff it deploys § 16(5). If you work without such a company, no confirmation is needed.
Who that can be
The QS-VO doesn't list companies. Any company whose work can bring it into contact with such data qualifies, for example:
- the maker of your practice software, if it accesses it by remote maintenance;
- the IT support that maintains computers and servers;
- backup or cloud storage providers.
Confirmation and contract
Separately from § 16(5), the GDPR requires a contract whenever a company processes personal data on your behalf GDPR Art. 28(3). Make sure your paperwork covers both: the contract, and the confirmation that the company's staff comply with the GDPR too.
What works as proof
- a list of the IT companies that come into contact with personal data;
- each company's written, dated confirmation;
- the data processing agreement, where the company processes data on your behalf.
Checklist
- All IT companies that come into contact with personal data are listed.
- Each has confirmed it complies with the GDPR, its staff included.
- Where a company processes data on your behalf, there is a data processing agreement.
- When a new company comes on board, the confirmation is obtained right away.
Quiz
What does § 16(5) require of an IT company that comes into contact with patient data?
- A registered office in Austria
- A confirmation, with proof, that it complies with the GDPR, its staff included
- Nothing, as long as it doesn't store the data
- ISO 27001 certification
Show the answer
The answer is B: A confirmation, with proof, that it complies with the GDPR, its staff included. § 16(5): the company confirms, with proof and also for its staff, that the GDPR is complied with. Coming into contact with the data is enough.
Sources
This lesson's statements rest on:
Not legal advice. What counts is the text of the QS-VO 2024 in the Federal Legal Information System (version of 3 October 2026) and the Austrian Medical Chamber's Hygiene Regulation 2014. Not an offer of ÖQMED, the BIQG or the Medical Chamber.