GDPR in debt collection
Also known as personal data in debt collection, data processing agreement, danish data protection agency, persondata i inkasso, databehandleraftale, datatilsynet
GDPR sets the boundaries for how a debtor's personal data may be processed during recovery — and who carries the responsibility.
In practice
When you hand a case over to debt collection, you also hand over personal data about the debtor. That requires a legal basis and a data processing agreement between you and the collection agency — and as a rule you remain the data controller for your own debtors.
The practical consequence: if you keep debtor records for years “just in case”, you must be able to justify why. And a debtor has the right of access to whatever you have recorded about them.
Where it commonly goes wrong
- The data processing agreement is missing. It is one of the easiest things for a regulator to find.