GDPR & Compliance at Planerio: Data Protection as the Standard
- Software Hosting in Germany
- DPA & TOM included by default
- BSI C5, ISO/IEC 27001, 27017, and 27018-certified infrastructure
- AES-256 Encryption & Audit-Proof Logging
Planerio is GDPR-compliant software for shift planning and workforce management. Your personal shift planning data is processed and stored on AWS’s infrastructure in Germany, which is certified to BSI C5, ISO/IEC 27001, 27017, and 27018 standards. Other personal data, such as that used for direct communication between Planerio and you, is stored within the EU/EEA. A data processing agreement (DPA) in accordance with Article 28 of the GDPR is included by default in your Planerio contract. In short: Data protection and compliance are central to Planerio’s software architecture decisions, they are not merely “nice-to-haves.” The data processed includes employee information from the digital personnel file and the HR master data. The legally required documentation of working hours is also subject to the same protection requirements.
GDPR Compliance
What GDPR compliance specifically means for Planerio
Three pillars – from the server location to the DPA to EU/EEA transparency regarding all subprocessors.
AWS Server Infrastructure Certified to BSI C5 and ISO/IEC Standards
Planerio operates its entire software infrastructure on AWS, with its data center located exclusively in Germany (Frankfurt am Main). There is no transfer of data to a third country as defined by the European Court of Justice ruling C-311/18 (Schrems II). The relevant documentation is available upon request.
AWS is the first company to receive C5 certification (Cloud Computing Compliance Controls Catalog) from the Federal Office for Information Security (BSI). In addition, the AWS Frankfurt region is certified to ISO/IEC 27017 (Data Security in the Cloud) and ISO/IEC 27018 (Protection of Personal Data in the Cloud).
DPA pursuant to Art. 28 of the GDPR – included by default
By accepting our quote, you agree to our data processing agreement (DPA) pursuant to Article 28 of the GDPR as an integral part of every Planerio contract—including Technical and Organizational Measures (TOM).
No separate application process, no additional workload for your data protection officers.
Upon request, we can provide a separate DPA; please contact your Planerio sales representative directly regarding this matter.
Data Protection Transparency in the EU/EEA
In addition to the Planerio core software, Planerio relies on specialized third-party providers for internal business processes, such as project management and customer communication.
The processing of personal data by these services takes place exclusively within the EU/EEA.
A complete list of the sub-processors used, as well as all technical documentation, is available upon request.
Security Plan
Overview of Technical Protective Measures
Planerio protects logins, personal shift planning data, and processes for all users through a multi-layered security approach.
Secure Access & Authentication
- Single Sign-On (SSO): Centralized identity management that reduces the attack surface
- Multi-factor authentication (MFA): available by default; recommended for regulated areas
- Role-based access rights: configurable at the department and company levels
Data Security & Availability
- Encryption: AES-256 for stored data, TLS 1.3 for data transmission (TLS 1.2 supported as a fallback)
- Backup & Disaster Recovery: documented emergency plan; RTO ≤ 24 hours, RPO ≤ 24 hours
- Audit-proof logging: every change is recorded in an unalterable manner and is auditable
- Incident Response under Article 33 of the GDPR: Notification to customers within a maximum of 72 hours
Healthcare & Public Sector
Compliance for the Healthcare Industry & Public Sector
For hospitals, long-term care facilities, and public institutions, GDPR compliance alone is not enough. Planerio natively maps sector-specific requirements—automatically, in an audit-proof manner, and with alerts if applicable collective bargaining agreements are not adhered to.
Arbeitszeitgesetz (ArbZG) – Automated and Audit-Proof
Maximum working hours, rest times, and break deduction logic are automatically and audit-proof recorded in accordance with the ArbZG. No manual Excel reconciliation, no corrections required after a tax audit.
PPBV, PpUGV, PPP-RL, and others – documentation ready for review
Planerio documents the legally required minimum staffing levels for regulated areas in the healthcare sector in a way that is audit-ready and traceable. Audit reports can be retrieved at any time with a single click.
TVöD, TV-L, TV-Ärzte, Company-Specific Collective Bargaining Agreements & Works Agreements
Municipal and university collective bargaining agreements can also be mapped in Planerio, as can individual company agreements. When setting up Planerio, these are directly integrated into the planning and time management logic—the Planerio onboarding team will explain how during the software setup process.
GDPR Compliance
Planerio Compared to Generic Workforce Management Solutions
IT decision-makers in regulated industries always ask us the same question when comparing software: “Is our employee data really secure with Planerio?” The table below shows what matters when choosing a shift schedule or workforce management solution—and how Planerio meets these important criteria:
| Criterion | Planerio | Generic WFM Tools |
|---|---|---|
| Server location (personal schedule data) | Exclusively in Germany (AWS Frankfurt) | Not always DE; sometimes EU and/or difficult to identify |
| GDPR-compliant & DPA available | Included as standard in our contract; alternatively: a separate contract | In some cases, only upon request |
| Technical and Organizational Measures (TOM) | Included by default as an attachment to the DPA | In some cases, only upon request |
| ArbZG natively supported | Various warnings for noncompliance | Compliance is up to the users |
| PPBV, PpUGV, and PPP-RL Documentation | Available by default | Partially possible, partially not |
| TVöD, TV-L, TV-Ärzte, and municipal pay scales | Can be mapped, including, as a rule, individual in-house rates | Compliance is up to the users |
| Audit-Traceable Logs | Ensured by the system | Variable |
| Software Specialization | Designed specifically for industries with complex requirements | Often generic or cross-industry |
At a Glance
Planerio Privacy Policy at a Glance
Which documents you can obtain and where—and which ones are included in your contract by default.
Document
Availability
Data Processing Agreement (DPA) pursuant to Article 28 of the GDPR
Included in the contract
Technical and Organizational Measures (TOM)
Appendix to the DPA
Publicly accessible
AWS Certifications (BSI C5, ISO/IEC 27001, 27017, 27018)
Publicly accessible
Proof of Server Location (AWS Frankfurt)
Upon request
Incident Response Policy (Art. 33 of the GDPR)
Upon request
FAQ
Frequently Asked Questions About Data Protection & Compliance at Planerio
Yes. All personal data related to shift planning is processed and stored exclusively in Germany. There is no transfer to a third country as defined by the ECJ ruling in Case C-311/18. A DPA pursuant to Article 28 of the GDPR is included by default or can be entered into separately on a company-specific basis.
Yes. Planerio operates its software infrastructure on AWS, with its data center located exclusively in Germany (Frankfurt am Main). The relevant documentation is available upon request.
Planerio operates its infrastructure on AWS’s cloud infrastructure, which is certified to BSI C5, ISO/IEC 27001, 27017, and 27018. The AWS certifications are publicly available. Technical documentation from Planerio is available to data protection officers, auditors, and works council members upon request.
Yes, Planerio is GDPR-compliant and suitable for businesses of all sizes—from medical practices to hospital networks, and from small trade businesses to industrial companies with multiple sites. Regardless of company size, the same data protection standards apply: the DPA and TOM are included by default in every Planerio contract.
Planerio documents legally required minimum staffing levels for regulated areas—including operating rooms, intensive care units, and psychiatric wards—in a way that is ready for audit and traceable. If staffing levels are at risk of falling below the minimum, Planerio automatically issues a real-time warning. Audit reports can be accessed at any time without any additional effort on the part of the planning team.
Maximum working hours, rest times, and break deduction logic are automatically mapped in accordance with the ArbZG in an audit-proof manner. The TVöD, TV-L, TV-Ärzte, and individual in-house collective bargaining agreements are integrated directly into the scheduling logic upon account setup—without the need for manual reconciliation.
Planerio has a documented incident response policy. In the event of a security incident, customers will be notified as soon as possible, but no later than 72 hours, in accordance with Article 33 of the GDPR.
Yes, because a printed notice allows uncontrolled access, provides no audit trail, and lacks access restrictions that comply with data protection regulations. Personal data in the shift schedule is subject to Article 88 of the GDPR in conjunction with Section 26 of the BDSG.
Sending shift plans via email is also problematic from a data protection perspective: An unencrypted email is legally comparable to a postcard – personal data such as work hours and names are potentially visible to third parties. With Planerio, neither of these issues arises: Employees view their schedule exclusively through the role-based, encrypted employee scheduling app.
No notice, no email, no privacy risk.
Proven: Over 4000 sites
Talk through your data protection questions one-to-one – in 30 minutes.
Do you have specific questions about Planerio’s server location, DPA, certifications, or industry-specific compliance? During a personalized product demo, Planerio will answer all your questions about data security—transparently, directly, and without any sales pressure.
This content is provided for general informational purposes only and does not constitute individual legal or data protection advice. Information regarding legal requirements (GDPR, ArbZG, TVöD, PpUGV, etc.) has been compiled to the best of our knowledge and based on publicly available sources. For a binding legal assessment, please consult a qualified legal advisor or your data protection officer.