FAQ - HubBroker and GDPR

Here you will find answers to the most commonly asked questions about General Data Protection Regulation (GDPR).
1. What is GDPR?
The General Data Protection Regulation (GDPR) is the European Union's data-protection regulation governing the processing of personal data.
It establishes requirements for organisations that collect, use, store, transmit or otherwise process personal data and provides individuals with rights regarding the use of their personal data.
The GDPR has applied since 25 May 2018.
2. Why was GDPR introduced?
The GDPR was introduced to strengthen and harmonise the protection of individuals' personal data across the European Union and European Economic Area.
It aims to provide individuals with greater transparency and control over how their personal data is used while establishing consistent data-protection requirements for organisations.
3. Who does GDPR apply to?
The GDPR applies to controllers and processors established in the EU/EEA that process personal data in connection with their activities.
It may also apply to organisations established outside the EU/EEA where they:
- offer goods or services to individuals in the EU; or
- monitor the behaviour of individuals within the EU.
The applicability of GDPR therefore depends on the organisation's activities and the circumstances of the processing, rather than simply the physical location of its systems.
4. What is personal data?
Personal data is information relating to an identified or identifiable living individual.
Examples may include:
- name;
- business or personal email address;
- postal address;
- telephone number;
- identification number;
- IP address;
- location information; and
- other information that can directly or indirectly identify an individual.
Information that has been pseudonymised may still constitute personal data if an individual can be re-identified.
5. What does processing personal data mean?
Processing includes almost any operation performed on personal data.
Examples include:
- collecting;
- recording;
- storing;
- accessing;
- organising;
- modifying;
- transmitting;
- sharing;
- retrieving;
- restricting; and
- deleting personal data.
Processing may be performed manually or through automated systems.
6. What is the difference between a Data Controller and a Data Processor?
A Data Controller determines the purposes and essential means of processing personal data.
A Data Processor processes personal data on behalf of a Data Controller and according to the Controller's documented instructions.
For customer data processed through HubBroker's integration services, the customer generally acts as the Data Controller and HubBroker generally acts as the Data Processor.
HubBroker may separately act as a Data Controller for personal data it processes for its own business purposes, such as customer contacts, administration, billing and security records.
7. What are the main GDPR principles?
Organisations processing personal data must follow the fundamental GDPR principles, including:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality; and
- accountability.
Organisations should collect only the personal data necessary for a defined purpose and protect that information using appropriate technical and organisational measures.
8. What rights do individuals have under GDPR?
Depending on the circumstances, individuals may have rights including:
- the right to be informed;
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to data portability;
- the right to object; and
- rights relating to certain automated decision-making and profiling.
Not every right applies in every situation, and some rights are subject to legal conditions and exceptions.
9. Does GDPR require consent for all processing?
No.
Consent is one possible lawful basis for processing personal data, but it is not the only lawful basis.
Depending on the circumstances, processing may also be based on grounds such as:
- performance of a contract;
- compliance with a legal obligation;
- protection of vital interests;
- performance of a task in the public interest; or
- legitimate interests.
The Data Controller is responsible for determining the appropriate lawful basis for its processing activities.
10. What is a personal data breach?
A personal data breach is a security incident involving the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Examples may include:
- unauthorised access to customer information;
- personal data sent to the wrong recipient;
- loss of a device containing personal data;
- ransomware affecting personal data; or
- unauthorised disclosure or exfiltration of personal information.
11. When must a personal data breach be reported?
Where HubBroker acts as a Data Processor and becomes aware of a personal data breach involving customer data, HubBroker will notify the relevant Data Controller without undue delay in accordance with applicable GDPR and contractual requirements.
Where an organisation acts as a Data Controller and a breach is reportable under GDPR, the competent supervisory authority must generally be notified without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
Where a breach is likely to result in a high risk to individuals' rights and freedoms, communication to affected individuals may also be required without undue delay.
12. What is HubBroker's role under GDPR?
For personal data processed through HubBroker's EDI, e-invoicing, API and integration services, HubBroker generally acts as a Data Processor and processes data according to the customer's documented instructions.
Customers generally act as Data Controllers for the personal data included in their business transactions and integrations.
HubBroker may also act as an independent Data Controller for certain information processed for its own legitimate business purposes.
More detailed responsibilities should be defined in the applicable Data Processing Agreement and related privacy documentation.
Category: GDPR
Last date of update: 25.08.2026