GDPR and DPA in e-invoice conversion: data protection, EU hosting, deletion
Anyone who converts invoices processes personal data – and must therefore take data protection into account. When selecting a conversion solution, it is worth taking a close look at hosting, storage, and contracts.
> Quick answer: Invoice data is usually personal and subject to the GDPR. Look for EU hosting, make sure invoice content is not stored permanently, and check for clear deletion periods and an available DPA. At TaxLayer: processing in Frankfurt, no storage of invoice content, metadata deleted after 90 days, DPA on request.
Why this is relevant
Invoices contain names, addresses, and often contact details – in other words, personal data. As soon as a service provider processes these on your behalf, it becomes your processor in the sense of the GDPR. This gives rise to requirements regarding the place, scope, and duration of processing.
What to look for
| Criterion | What matters |
|---|---|
| Hosting | processing and storage within the EU |
| Server location | specifically named (e.g. Frankfurt am Main) |
| Storage | ideally no permanent storage of invoice content |
| Deletion | clear, automatic deletion periods |
| DPA | data processing agreement available |
How TaxLayer handles it
- Processing in Frankfurt am Main; all data remains in the EU.
- The invoice file is not stored permanently but processed and returned.
- Only minimal usage metadata is kept, and it is automatically deleted after 90 days.
- A DPA is available on request.
How this interacts with retention
Separately from data protection, the tax retention obligation applies: you must archive the e-invoice itself in an audit-proof way. How this fits together with the GoBD is explained in Archiving e-invoices.
Conclusion
Data protection is not a side issue in e-invoice conversion. Look for EU hosting, sparing storage, clear deletion periods, and a DPA – then processing stays GDPR compliant.
---
TaxLayer: processing in Frankfurt, no storage of invoice content, DPA on request. Questions to info@landauer.de.
Frequently asked questions
Is invoice data personal data?
Yes, as a rule. Names, addresses, and sometimes the contact details of individual contacts are personal. Processing therefore falls under the GDPR.
Where is the data processed?
At TaxLayer, processing takes place exclusively in German data centres (Frankfurt am Main). All data remains within the EU.
Is invoice content stored?
No. The invoice file (PDF/XML) is processed and returned but not stored permanently. Only minimal usage metadata is kept, and it is automatically deleted after 90 days.
Is there a DPA?
Yes. A data processing agreement (DPA) is available on request. Write to info@landauer.de.
Free tools
Related articles
Convert PDF invoices now
Try TaxLayer for free – 2 conversions per month, no credit card required.
Get started