Order Processing in the Security Industry: Rights and Obligations Towards Clients

post thumb
Law
by Your Security Team/ on 15 Mar 2026

Order Processing in the Security Industry: Rights and Obligations Towards Clients

Open and transparent communication

Security service providers process sensitive data every day: shift schedules, access authorizations, video recordings, customer employee personal data. Yet many underestimate their role as data processors under the GDPR. We clarify rights, obligations and typical pitfalls.


Why Order Processing is Particularly Relevant in the Security Industry

Security service providers typically have access to particularly sensitive data:

Data Type Examples
Personal data Names, addresses, dates of birth of clients, visitors or employees
Access data Who opened which door when (including timestamps)
Video recordings Moving images of people, often with facial recognition
Incident reports Detailed descriptions of incidents (also with personal reference)
Shift schedules Working hours and deployment locations of own security personnel
Security concepts Confidential documents about client vulnerabilities

The catch: The security service provider acts on behalf of its client. This makes it legally a data processor – with far-reaching obligations.


The General Data Protection Regulation (GDPR) clearly distinguishes between:

Role Definition Example
Controller Decides on the purpose and means of processing The client (e.g. a company having its building monitored)
Processor Processes data on behalf of the controller The security service provider

Key statement: The security service provider may only do what the client has contractually permitted – and must implement strict technical and organizational measures (TOM).


The 7 Most Important Obligations as a Processor

1. Conclude a Data Processing Agreement (DPA)

This is mandatory before you begin processing. The DPA must regulate:

  • Subject matter and duration of the processing
  • Nature and purpose of the processing
  • Type of personal data and categories of data subjects
  • Obligations of the processor (instructions, TOM, support obligations)

Practical tip: Many clients have their own DPA templates. Review them carefully – especially liability and audit rights.

2. Instruction-Bound Processing

You may only act according to the client’s instructions. Unauthorized processing (e.g. storing longer than agreed, passing data to third parties) is prohibited.

Exception: Legally mandated instructions (e.g. handing over video recordings to the police) are permitted but must be documented.

3. Technical and Organizational Measures (TOM)

You must demonstrate that your systems and processes are secure. These include:

  • Encryption of video and access data
  • Access controls (only authorized employees have access)
  • Logging of all access
  • Regular backups and recovery options
  • Security updates and patch management
  • Emergency plan for data breaches

Practical tip: Document your TOM in writing – this is your best defense in case of disputes.

4. Support Obligations Towards the Client

You must support the client with:

  • Fulfilling data subject access requests (“What data about me is stored?”)
  • Correction or deletion of data
  • Restriction of processing
  • Reporting data breaches to supervisory authorities

5. Obligation to Report Data Breaches

If you discover a data breach (e.g. hacked video system, lost company laptop with sensitive data), you must:

  • Immediately inform the client (no fixed deadline, but “without undue delay”)
  • Provide all known information about the breach (scope, affected data, countermeasures)
  • Support the client in notifying the supervisory authority

Important: Concealment can be expensive – fines of up to €20 million or 4% of global annual turnover.

6. Use of Subcontractors Only with Approval

May your security personnel independently use external service providers (e.g. cloud storage, maintenance technicians, cleaning staff with access to sensitive areas)?

  • Only with prior written approval from the client
  • Same contractual obligations for the subcontractor (DPA required)
  • Liability remains with you (you are liable to the client for subcontractors)

7. Deletion or Return of All Data After Contract End

After contract termination, you must either:

  • Delete all personal data (including backups, logs, emails) or
  • Hand over to the client (e.g. on a hard drive)

Storage “just in case” is not permitted. Exceptions apply only if statutory retention obligations exist (e.g. commercial retention of invoices for 10 years – but without personal content).


Typical Pitfalls in the Security Industry

Pitfall 1: Verbal Agreements Are Not Enough

Many security service providers have been working with a client for years – but there is no written DPA. This is unlawful and can lead to high fines in the event of an inspection by the supervisory authority.

Pitfall 2: Video Surveillance Without Deletion Concept

“Continuous recording for 30 days – better safe than sorry.” Not really. The GDPR only permits storage for as long as is necessary for the purpose. In case of doubt, you must agree on shorter periods or event-based recording (only in the event of an alarm).

Pitfall 3: No Documentation of Access

Who accessed which video recording when? If you don’t log this, you cannot prove in case of dispute that no unauthorized access took place.

Pitfall 4: Private Phones of Security Personnel

An employee photographs a suspicious object with their private smartphone and shares the image via WhatsApp. Data breach! Private devices have no place in order processing.

Pitfall 5: Unclear Instruction Situation

The client requests “just quickly” a deletion of all recordings from a specific day. Are they allowed to do that? Yes, but only if the DPA provides for it. And you must document the instruction.


Your Rights as a Processor

Not only obligations – you also have important rights:

Right Meaning
Remuneration for instructions You can charge separately for additional effort (e.g. complex information requests) if not otherwise agreed.
Limitation of liability You are only liable for damages caused by your breach of duty – not for the client’s general risks.
Termination in case of instruction violation If the client gives unlawful instructions (e.g. “Monitor the toilets too”), you can refuse the instruction and, in extreme cases, terminate the contract.
Proof of TOM You may demonstrate to the client that your security measures are adequate (e.g. through certifications such as ISO 27001).

Contract Design: What Must Be Included in the DPA

A professional data processing agreement for security service providers should include at least:

  • Precise description of the data processed (e.g. “Video recordings from cameras 1-10, access data from the main entrance”)
  • Storage periods for each data category
  • Instruction rights of the client (including procedures for instructions)
  • TOM catalog (technical and organizational) as an annex
  • Audit rights of the client (e.g. annual audit right)
  • Regulations on subcontractors (approval requirement, DPA for subcontractors)
  • Reporting obligations for data breaches
  • Deletion and return obligations after contract end
  • Liability provisions (who is liable for what)
  • Contractual penalty for breach of duty (optional, but recommended)

Checklist for Security Service Providers

Regularly check whether you meet the following points:

  • Is there a written DPA with each client?
  • Is the DPA up to date (especially the TOM)?
  • Have you documented your TOM and can you prove them?
  • Are accesses to personal data logged?
  • Is there a procedure for data breaches (internal reporting channel, templates for client notifications)?
  • Are your employees regularly trained on data protection?
  • Do your employees use company devices (no private smartphones)?
  • Are data really deleted after contract end (not just “forgotten”)?
  • Have you appointed a data protection officer (if legally required)?

Conclusion: Order Processing as a Competitive Advantage

Many security service providers see GDPR obligations as annoying bureaucracy. However, legally compliant order processing is a real quality feature:

  • Clients feel secure when you handle their data professionally
  • A clean DPA avoids later disputes
  • Good TOM reduce the risk of data breaches (and thus liability risks)

Invest in legal advice, documentation and employee training. The costs are low compared to a fine or loss of trust.

Do you have questions about order processing or need support with contract design? We advise you discreetly, practically and with many years of experience in the security industry.


Note: This article does not replace legal advice. The legal situation may change, and individual contracts should be reviewed by a lawyer specializing in data protection law.