Data Processing Agreement · Art. 28 GDPR · Version 1.0
Verifento and B2B clients are INDEPENDENT CONTROLLERS (Art. 4(7) GDPR) – not a controller and processor. Therefore, the relationship is not governed by a standard DPA under Art. 28 GDPR, but by a Controller-to-Controller Data Sharing Agreement (DSA) under Art. 26 GDPR.
Why Not a DPA?
A traditional DPA (Art. 28 GDPR) is concluded when one entity processes data ON BEHALF OF another (e.g., a cloud provider for a company). In the case of Verifento:
- Each B2B client (rental company) independently determines the purpose of processing its customers' data → it is an independent controller
- Verifento manages the network and determines its technical parameters → also an independent controller
- Both parties share data as equal partners → Art. 26 GDPR (Independent Controllers)
Legal reference: EDPB Opinion 07/2020 (Fashion ID case); CJEU C-634/21 (SCHUFA) – confirmation of independent controller status for scoring platforms.
What Document Applies?
The relationship between Verifento ↔ B2B client is governed by:
→ Controller-to-Controller Data Sharing Agreement (DSA v1.1)
View DSA Agreement →When Does a DPA Apply to Verifento?
Verifento enters into DPAs under Art. 28 GDPR with its own subprocessors – technical processors:
These DPAs are internal agreements between Verifento and its providers – they are not relevant to B2B clients of the platform.
Questions about legal classification: privacy@verifento.com