GDPR in debt collection

Also known as personal data in debt collection, data processing agreement, danish data protection agency, persondata i inkasso, databehandleraftale, datatilsynet

GDPR sets the boundaries for how a debtor's personal data may be processed during recovery — and who carries the responsibility.

Key facts
Requires
A data processing agreement
Regulator
Datatilsynet (Danish DPA)

In practice

When you hand a case over to debt collection, you also hand over personal data about the debtor. That requires a legal basis and a data processing agreement between you and the collection agency — and as a rule you remain the data controller for your own debtors.

The practical consequence: if you keep debtor records for years “just in case”, you must be able to justify why. And a debtor has the right of access to whatever you have recorded about them.

Where it commonly goes wrong

  • The data processing agreement is missing. It is one of the easiest things for a regulator to find.
  • Data is never deleted because “the case might be reopened.” There has to be a retention limit, closed cases included.
  • The entire customer record is sent along at handover. Only what is necessary for the collection should go.
Read the data processing agreementWhat we process, for how long, and what you can require
  • 30 days free
  • No payment card
  • One day's notice