GDPR & Compliance at Planerio: Data Protection as the Standard

  • Software Hosting in Germany
  • DPA & TOM included by default
  • BSI C5, ISO/IEC 27001, 27017, and 27018-certified infrastructure
  • AES-256 Encryption & Audit-Proof Logging
Hosting in Germany
ACTIVE
AWS Frankfurt · eu-central-1
Germany as a Data Center Location

BSI C5
Cloud Computing Compliance Controls Catalog
✓ MET
ISO/IEC 27001
Information Security Management
✓ MET
ISO/IEC 27017
Data Privacy in the Cloud
✓ MET
ISO/IEC 27018
Protection of Personal Data
✓ MET
AES-256
Data in a dormant state
TLS 1.2+
Transmission
📄
DPA pursuant to Article 28 of the GDPR
Included in the contract by default · includes TOM

Planerio is GDPR-compliant software for shift planning and workforce management. Your personal shift planning data is processed and stored on AWS’s infrastructure in Germany, which is certified to BSI C5, ISO/IEC 27001, 27017, and 27018 standards. Other personal data, such as that used for direct communication between Planerio and you, is stored within the EU/EEA. A data processing agreement (DPA) in accordance with Article 28 of the GDPR is included by default in your Planerio contract. In short: Data protection and compliance are central to Planerio’s software architecture decisions, they are not merely “nice-to-haves.” The data processed includes employee information from the digital personnel file and the HR master data. The legally required documentation of working hours is also subject to the same protection requirements.

GDPR Compliance

What GDPR compliance specifically means for Planerio

Three pillars – from the server location to the DPA to EU/EEA transparency regarding all subprocessors.

AWS Server Infrastructure Certified to BSI C5 and ISO/IEC Standards

Planerio operates its entire software infrastructure on AWS, with its data center located exclusively in Germany (Frankfurt am Main). There is no transfer of data to a third country as defined by the European Court of Justice ruling C-311/18 (Schrems II). The relevant documentation is available upon request.

AWS is the first company to receive C5 certification (Cloud Computing Compliance Controls Catalog) from the Federal Office for Information Security (BSI). In addition, the AWS Frankfurt region is certified to ISO/IEC 27017 (Data Security in the Cloud) and ISO/IEC 27018 (Protection of Personal Data in the Cloud).

DPA pursuant to Art. 28 of the GDPR – included by default

By accepting our quote, you agree to our data processing agreement (DPA) pursuant to Article 28 of the GDPR as an integral part of every Planerio contract—including Technical and Organizational Measures (TOM).

No separate application process, no additional workload for your data protection officers.

Upon request, we can provide a separate DPA; please contact your Planerio sales representative directly regarding this matter.

Data Protection Transparency in the EU/EEA

In addition to the Planerio core software, Planerio relies on specialized third-party providers for internal business processes, such as project management and customer communication.

The processing of personal data by these services takes place exclusively within the EU/EEA.

A complete list of the sub-processors used, as well as all technical documentation, is available upon request.

Security Plan

Overview of Technical Protective Measures

Planerio protects logins, personal shift planning data, and processes for all users through a multi-layered security approach.

Secure Access & Authentication

  • Single Sign-On (SSO): Centralized identity management that reduces the attack surface
  • Multi-factor authentication (MFA): available by default; recommended for regulated areas
  • Role-based access rights: configurable at the department and company levels

Data Security & Availability

  • Encryption: AES-256 for stored data, TLS 1.3 for data transmission (TLS 1.2 supported as a fallback)
  • Backup & Disaster Recovery: documented emergency plan; RTO ≤ 24 hours, RPO ≤ 24 hours
  • Audit-proof logging: every change is recorded in an unalterable manner and is auditable
  • Incident Response under Article 33 of the GDPR: Notification to customers within a maximum of 72 hours

Healthcare & Public Sector

Compliance for the Healthcare Industry & Public Sector

For hospitals, long-term care facilities, and public institutions, GDPR compliance alone is not enough. Planerio natively maps sector-specific requirements—automatically, in an audit-proof manner, and with alerts if applicable collective bargaining agreements are not adhered to.

Arbeitszeitgesetz (ArbZG) – Automated and Audit-Proof

Maximum working hours, rest times, and break deduction logic are automatically and audit-proof recorded in accordance with the ArbZG. No manual Excel reconciliation, no corrections required after a tax audit.

PPBV, PpUGV, PPP-RL, and others – documentation ready for review

Planerio documents the legally required minimum staffing levels for regulated areas in the healthcare sector in a way that is audit-ready and traceable. Audit reports can be retrieved at any time with a single click.

TVöD, TV-L, TV-Ärzte, Company-Specific Collective Bargaining Agreements & Works Agreements

Municipal and university collective bargaining agreements can also be mapped in Planerio, as can individual company agreements. When setting up Planerio, these are directly integrated into the planning and time management logic—the Planerio onboarding team will explain how during the software setup process.

GDPR Compliance

Planerio Compared to Generic Workforce Management Solutions

IT decision-makers in regulated industries always ask us the same question when comparing software: “Is our employee data really secure with Planerio?” The table below shows what matters when choosing a shift schedule or workforce management solution—and how Planerio meets these important criteria:

CriterionPlanerioGeneric WFM Tools
Server location (personal schedule data) Exclusively in Germany (AWS Frankfurt)Not always DE; sometimes EU and/or difficult to identify
GDPR-compliant & DPA available Included as standard in our contract; alternatively: a separate contractIn some cases, only upon request
Technical and Organizational Measures (TOM) Included by default as an attachment to the DPAIn some cases, only upon request
ArbZG natively supported Various warnings for noncompliance Compliance is up to the users
PPBV, PpUGV, and PPP-RL Documentation Available by defaultPartially possible, partially not
TVöD, TV-L, TV-Ärzte, and municipal pay scales Can be mapped, including, as a rule, individual in-house rates Compliance is up to the users
Audit-Traceable Logs Ensured by the systemVariable
Software Specialization Designed specifically for industries with complex requirementsOften generic or cross-industry

At a Glance

Planerio Privacy Policy at a Glance

Which documents you can obtain and where—and which ones are included in your contract by default.

Document

Availability

Data Processing Agreement (DPA) pursuant to Article 28 of the GDPR

Included in the contract

Technical and Organizational Measures (TOM)

Appendix to the DPA

Publicly accessible

AWS Certifications (BSI C5, ISO/IEC 27001, 27017, 27018)

Publicly accessible

Proof of Server Location (AWS Frankfurt)

Upon request

Incident Response Policy (Art. 33 of the GDPR)

Upon request

FAQ

Frequently Asked Questions About Data Protection & Compliance at Planerio

Is Planerio GDPR-compliant following the ECJ ruling (Schrems II)?

Yes. All personal data related to shift planning is processed and stored exclusively in Germany. There is no transfer to a third country as defined by the ECJ ruling in Case C-311/18. A DPA pursuant to Article 28 of the GDPR is included by default or can be entered into separately on a company-specific basis.

Does Planerio guarantee that the software’s personal shift schedule data is hosted in Germany?

Yes. Planerio operates its software infrastructure on AWS, with its data center located exclusively in Germany (Frankfurt am Main). The relevant documentation is available upon request.

Is Planerio ISO 27001-certified?

Planerio operates its infrastructure on AWS’s cloud infrastructure, which is certified to BSI C5, ISO/IEC 27001, 27017, and 27018. The AWS certifications are publicly available. Technical documentation from Planerio is available to data protection officers, auditors, and works council members upon request.

Is Planerio GDPR-compliant and suitable for small to medium-sized businesses?

Yes, Planerio is GDPR-compliant and suitable for businesses of all sizes—from medical practices to hospital networks, and from small trade businesses to industrial companies with multiple sites. Regardless of company size, the same data protection standards apply: the DPA and TOM are included by default in every Planerio contract.

How does Planerio help ensure compliance with PpUGV, PPR 2.0, and the PPP-RL?

Planerio documents legally required minimum staffing levels for regulated areas—including operating rooms, intensive care units, and psychiatric wards—in a way that is ready for audit and traceable. If staffing levels are at risk of falling below the minimum, Planerio automatically issues a real-time warning. Audit reports can be accessed at any time without any additional effort on the part of the planning team.

To what extent does Planerio take the Arbeitszeitgesetz and collective agreements into account when creating shift schedules?

Maximum working hours, rest times, and break deduction logic are automatically mapped in accordance with the ArbZG in an audit-proof manner. The TVöD, TV-L, TV-Ärzte, and individual in-house collective bargaining agreements are integrated directly into the scheduling logic upon account setup—without the need for manual reconciliation.

How does Planerio handle data breaches?

Planerio has a documented incident response policy. In the event of a security incident, customers will be notified as soon as possible, but no later than 72 hours, in accordance with Article 33 of the GDPR.

Is a digital shift schedule more secure than a paper one posted on a bulletin board?

Yes, because a printed notice allows uncontrolled access, provides no audit trail, and lacks access restrictions that comply with data protection regulations. Personal data in the shift schedule is subject to Article 88 of the GDPR in conjunction with Section 26 of the BDSG.
Sending shift plans via email is also problematic from a data protection perspective: An unencrypted email is legally comparable to a postcard – personal data such as work hours and names are potentially visible to third parties. With Planerio, neither of these issues arises: Employees view their schedule exclusively through the role-based, encrypted employee scheduling app.
No notice, no email, no privacy risk.

Proven: Over 4000 sites

Talk through your data protection questions one-to-one – in 30 minutes.

Do you have specific questions about Planerio’s server location, DPA, certifications, or industry-specific compliance? During a personalized product demo, Planerio will answer all your questions about data security—transparently, directly, and without any sales pressure.