# AKI (Estonia) - No. 2.1-1/24/397-890-38

- Type: Enforcement
- Source: AKI (Estonia)
- Date: 2026-04-16
- Original: https://gdprhub.eu/index.php?title=AKI_(Estonia)_-_No._2.1-1/24/397-890-38
- Canonical: https://overview.legal/posts/53882
- Topics: Controllers, Processors, Data Controller, Recipient, Personal Data, Processing, Privacy by Design, Data Processor, Joint Controllers, Health Data

## Summary

Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only partially complied after several requests from the DPA. Although the DPA closed the part of the case concerning the access request, it continued investigating the controller’s processing of patients’ personal data when providing Invisalign treatment. The service required the controller to collect and transfer patients’ health data to Align Technology, Inc. However, the contractual documents did not clearly establish whether Align Technology acted as a processor, an independent controller or a joint controller. The controller stated that Align Technology largely determined the conditions of the service, including the consent form and the processing arrangements, and that individual clinics could not unilaterally amend these conditions. The DPA also found that the information provided to patients was incomplete and fragmented. The consent form and privacy information did not clearly explain the legal basis and purposes of processing, the parties involved, data recipients, retention periods, transfers outside the European Union or the safeguards applied to such transfers. Parts of the information were only available in English on external websites. Holding — The DPA held that the controller had failed to demonstrate that the processing carried out in connection with the Invisalign service was lawful and transparent under Articles 5(1)(a) and 5(2) GDPR. First, the DPA found that the parties’ roles had not been properly determined. Under Article 4(7) GDPR, the assessment had to be based on which party actually determined the purposes and means of processing, rather than solely on the contractual description of the relationship. The controller decided whether Invisalign treatment was suitable for a patient and collected the relevant health data. It therefore acted as a controller in relation to the treatment. However, Align Technology exercised significant control over the subsequent processing, including the data collected, the recipients, retention arrangements, the use of other service providers and transfers outside the European Union. The DPA therefore considered that Align Technology could not simply be regarded as a processor acting only on documented instructions under Article 28(3)(a) GDPR. On the available evidence, it was at least a joint controller under Article 26 GDPR. The DPA ordered the controller to review the contractual relationship. If Align Technology acted as a processor, the agreement had to comply with Article 28 GDPR, including the requirements concerning subprocessors under Article 28(2). If the parties were joint controllers, they had to allocate their respective responsibilities under Article 26 GDPR. Second, the DPA found that the consent obtained from patients was invalid. The consent form did not provide sufficient information for patients to understand the processing and therefore did not meet Articles 4(11), 6(1)(a), 7 and 9(2)(a) GDPR. The DPA also noted that healthcare processing may, depending on the operation concerned, rely on Article 6(1)(b) GDPR together with Article 9(2)(h) GDPR. However, the controller had not clearly identified the applicable legal bases for the different processing activities. The privacy information also failed to comply with Articles 12, 13 and 14 GDPR. Patients were required to consult several documents and external websites, some of which contained incomplete or inconsistent information. The controller had therefore not ensured that the information was easily accessible, understandable and available in Estonian. The DPA further referred to Article 25 GDPR when emphasising that the controller had to ensure that the processing arrangements and safeguards complied with the GDPR. Under Article 58(2)(d) GDPR and § 56(1) of the Estonian Personal Data Protection Act, the DPA ordered the controller to clarify the parties’ roles, conclude an Article 26 arrangement or Article 28 agreement, amend the consent form and privacy policy, and publish the required information in Estonian. No administrative fine was imposed. However, failure to comply could result in a penalty payment of €1,000 for each unfulfilled point or subpoint of the order, imposed repeatedly until compliance.

## Sections (29)

### ¶0

35 (1) (2) PRECAUTION-WARNING in personal data protection case no. 2.1-1/24/397-890-38 Precept maker: Kirsika Kuutma, lawyer of the Data Protection Inspectorate Precept making date: 16.04.2026 in Tallinn time and place Recipient of the precept – Fullgevity OÜ (former business name OÜ Dr Mõttus Hambaravi) personal data processor registry code: 12166527 address: Harju County, Tallinn, Nõmme district, Jaama tn 1a, 11615 e-mail address: info@citymed.ee Member of the Management Board responsible person RESOLUTION Based on § 56 (1) of the Personal Data Protection Act and Art. 58 (2) (d) of the General Data Protection Regulation the Data Protection Inspectorate issues a mandatory precept for compliance

> Topics: Controllers, Data Processor, Processors, Personal Data

### ¶1

To review the agreement(s) concluded between Fullgevity OÜ and Align Technology, Inc. within the framework of the provision of the Invisalign service, in the course of which: 1.1. to define the roles arising from the GDPR (controller, processor, joint processors) in accordance with the processing operations performed with personal data; 1.2. in the case of the controller and processor relationship, to ensure that the agreement covers the requirements arising from Art. 28 of the GDPR; 1.3. in the case of the joint processors relationship, to agree on the areas of responsibility for fulfilling the obligations arising from the GDPR (Art. 26 of the GDPR).

> Topics: Personal Data, Processors, Controllers

### ¶2

Ensure that the provision of Invisalign services to clients and the transfer of data within the framework of this is transparent for data subjects and in accordance with Article 5(1)(a) of the GDPR: 2.1. bring the consent form into line with the requirements for consent set out in Article 4(11), Article 6(1)(a), Article 7 and Article 9(2)(a) of the GDPR (see in more detail paragraphs 19-22 of the precept); 2.2. bring the data protection conditions into line with the GDPR so that they contain the information required in Articles 13 and 14 (see in more detail paragraphs 23-26 of the precept); 2.3. present the data protection conditions in Estonian and also publish them on the Fullgevity OÜ website www.citymed.ee, to ensure the availability and comprehensibility of the information. Confirmation of compliance with the precepts together with documents proving compliance with the precept – a (renewed) contract or agreement regarding the processing of personal data, a revised consent form, data protection conditions and a link to the website where they are published – shall be submitted to the Data Protection Inspectorate no later than 07.05.2026 to the e-mail address info@aki.ee. CHALLENGE REFERENCE This precept can be challenged within 30 days by submitting either: - a challenge under the Administrative Procedure Act to the Director General of the Data Protection Inspectorate or - a complaint under the Code of Administrative Court Procedure to an administrative court (in this case, the challenge in the same matter can no longer be reviewed). Challenging the precept does not suspend the obligation to comply with it or the implementation of the measures necessary for compliance. PENALTY WARNING If the precept has not been complied with within the specified deadline, the Data Protection Inspectorate will impose a penalty of 1,000 euros on the addressee of the precept for each unfulfilled point and sub-point of the proposal. A penalty may be imposed repeatedly until the precept is complied with. If the addressee does not pay the penalty, it will be transferred to the bailiff to initiate enforcement proceedings. In this case, the bailiff's fee and other enforcement costs will be added to the penalty. MINORITY PENALTIES WARNING For failure to comply with a precept pursuant to Article 58(1) of the General Data Protection Regulation, misdemeanor proceedings may be initiated on the basis of § 69 of the Personal Data Protection Act. The person may be punished with a fine for such an act. The Data Protection Inspectorate is the extrajudicial authority for the misdemeanor. FACTS On 30.03.2024, the Data Protection Inspectorate (hereinafter the Inspectorate) received a complaint from a data subject (hereinafter the complainant) regarding the fact that OÜ Dr Mõttus Hambaravi (hereinafter the data processor) is not releasing his personal data to him in full. On 10.04.2024, the Inspectorate forwarded the complaint to the data processor to respond, to which the data processor failed to respond. On 23.04.2024, the Inspectorate forwarded a proposal to the data processor to release his personal data to the complainant or to provide a justification on the basis of which the data processor refuses to release it. The data processor failed to respond to the proposal. On 12.05.2024, the Inspectorate forwarded a repeated proposal to the data processor. On 31.05.2024, the data processor responded to the repeated proposal and partially fulfilled the proposal, providing, among other things, an explanation as to why it would not satisfy the proposal in full. On 26.06.2024, the Inspectorate sent an inquiry to the data processor to clarify the data processor's response and the reasons contained therein. As part of the inquiry, the Inspectorate also drew attention to the imposition of a precept and a penalty payment in the event that the Inspectorate's inquiry is not responded to within the deadline. On 18.07.2024, the Inspectorate sent a reminder to the data processor, as the deadline for responding to the inquiry had passed. On 18.07.2024, the data processor responded to the inquiry. 2 (9) On 26.09.2024, the Inspectorate sent an additional inquiry to the data processor regarding the circumstances of the complaint and the responses provided by the data processor and set a deadline for responding on 09.10.2024. As part of the inquiry, the Inspectorate also drew attention to the imposition of a precept and penalty payment in the event that the Inspectorate's inquiry is not responded to within the deadline. On 30.09.2024, the Inspectorate terminated the proceedings regarding the circumstances of the complainant's complaint, but continued the proceedings with the data processor regarding the service provided by them. On 09.10.2024, the data processor sent a request for an extension of the deadline for responding, because their response in turn depends on the response of the third party (the authorized processor). The Inspectorate granted the request. On 13.11.2024, the Inspectorate sent a reminder to the data processor because the extended deadline for responding to the inquiry had passed. The data processor did not respond to the reminder. On 18.12.2024, the Inspectorate issued a precept-warning No. 2.1-1/24/397-890-26 to the data processor with a resolution to respond to the Data Protection Inspectorate's inquiry No. 2.1-1/24/397- 890- 21 of 26.09.2024. The Inspectorate set the deadline for compliance with the precept as 06.01.2025. On 08.01.2025, the Inspectorate sent a reminder to the data processor because the deadline for responding to the precept had passed. The data processor responded to the reminder on 09.01.2025 and explained the reasons for its failure to respond. Among other things, the data processor confirmed that it would forward the responses to the inquiry at the earliest opportunity. On 27.01.2025, the Inspectorate additionally asked the data processor by what time a response could be expected. The data processor did not respond to this letter. On 14.03.2025, the Inspectorate, by precept No. 2.1-1/24/397-890-26 of 18.12.2024, set an additional deadline of 31.03.2025 for responding to the inquiry. The data processor did not respond to this letter. On 11.04.2025, the Inspectorate issued a notice of imposition of a penalty payment to the data processor for failure to comply with the precept No. 2.1-1/24/397-890- 30 According to the notification, the penalty payment will not be paid if the data processor responds to the inquiry no. 2.1-1/24/397-890 on 26.09.2024, submitting all the information and documents requested in the inquiry no later than 25.04.2025. On 25.04.2025, the data processor responded to the Inspectorate's inquiry and thereby complied with the precept. On 07.11.2025, the Inspectorate made a proposal no. 2.1-1/24/397-890-32 to the data processor and set the deadline for compliance as 05.12.2025. On 05.12.2025, the data processor sent a request to extend the deadline for responding to the proposal. The Inspectorate set a new deadline for compliance with the proposal as 19.01.2026. On 19.01.2026, the data processor sent a response to the Inspectorate explaining the possible solutions for fulfilling the proposal. The Inspectorate responded to the data processor on 28.01.2026 with letter no. 2.1-1/24/397- 890-36, in which it presented its position regarding the fulfillment of the data processor's proposal. The Inspectorate also set a new deadline for fulfilling the proposal of 18.02.2026. On 04.03.2026, the Inspectorate sent a reminder to the data processor that the additional deadline for fulfilling the proposal had expired and set a new deadline of 11.03.2026. The data processor has not responded to this. PERSONAL DATA PROCESSOR'S STATEMENT Fullgevity OÜ (Citymed, data processor) provided its own response to the AKI's proposal of 07.11.2025

> Topics: Controllers, Data Processor, Processors, Supervision

### ¶3

(9) 19.01.2026, in which it confirmed, among other things, its readiness to cooperate fully with the Inspectorate. However, the data processor failed to comply with the proposal on time, based in summary on the fact that the data processing related to the Invisalign service is largely predetermined by the service provider i.e. Align technology, Inc. and cannot be changed unilaterally by individual clinics. Align technology, Inc. has expressed its willingness to negotiate the terms of the contract to a certain extent, but since it is a large group, changes may not be possible in the final stage or making changes may be time-consuming. The data processor further emphasized that the Invisalign treatment method is inherently such that a potential restriction would not be proportionate from a public health perspective. We believe that a potential substantive restriction of the Invisalign service or making the provision of the service uncertain solely due to administrative and contractual issues – especially in a situation where the planned significant update of the European Union personal data protection regulation and its proportionality in terms of objectives, subjects and administrative costs and the reduction of the previous apparently unjustifiably excessive requirements are publicly known – would not be in accordance with the health interests of patients or the broader needs of society. Especially considering the current economic situation, where every euro spent is important for people and the availability of affordable treatment solutions is of decisive importance, and the Invisalign treatment system is very suitable for achieving such objectives. Thus, an important criterion in resolving the issue is also the justified proportion of the provision of a treatment system that is very necessary and required for public health versus the reasonableness of the administrative requirements related to its provision. We also proceed from the aforementioned publicly known assumption that a significant change to the IKÜM at the European Union level is reasonably on the agenda and that a final solution can probably only be developed after the relevant regulatory changes come into force, as changing global standards is both time-consuming and costly. We believe that the primary consideration in resolving any medical issues should be the interests of public health, and that administrative solutions and regulations should primarily enable and facilitate the achievement of public health objectives and interests. To ensure the transparency of data processing and in the part that is under the direct control of the data processor, the following measures are being implemented:  prepared a new, more comprehensive Estonian-language personal data processing consent form for Invisalign treatment;  harmonized the information provided to the patient so that it would not be contradictory or fragmented;  started updating the data protection conditions on the clinic's website and ensuring the availability of Estonian-language information which we will complete by obtaining confirmation from the AKI on the suitability of the proposed solution. The data processor requested the AKI's position on the suitability of the measures or the need for changes. The Inspectorate responded on 28.01.2026 and presented its position regarding the implementation of the data processor's proposal. The data processor's positions on 19.01.2026 to the AKI proposal and the AKI's response on 28.01.2026 are attached in their entirety to this administrative act (Appendix 1 and Appendix 2). JUSTIFICATIONS OF THE DATA PROTECTION INSPECTORATE: Processing of personal data 1 Pursuant to Article 4(1) of the General Data Protection Regulation (GDPR), personal data is any information about an identified or identifiable natural person, and health data is, pursuant to Article 15 personal data relating to the physical and mental health of a natural person, including data relating to the provision of healthcare services to him or her, which provide information about his or her health status.

> Topics: Controllers, Special Categories of Data, Identification, Health Data

### ¶4

(9)2. Pursuant to Article 5(1)(a) of the GDPR, the processing of personal data must be lawful, fair and transparent to the data subject, and pursuant to Article 5(1)(f), personal data must be processed in a manner that ensures the reliability and confidentiality of personal data. Processing is lawful if at least one of the legal grounds set out in Article 6(1) of the GDPR is met, and for the processing of special categories of personal data one of the circumstances set out in Article 9(2) of the GDPR is present. 3 The main authorisation for healthcare providers to process special categories of personal data stems from Article 9(2)(h) of the GDPR, which allows the processing of special categories of data if it is necessary for reasons related to preventive medicine or occupational medicine, to assess the employee's ability to work, to make a medical diagnosis, to provide healthcare or social care services or treatment, or to organise the healthcare or social care system and services, based on Union or Member State law or a contract concluded with a healthcare professional and provided that the conditions referred to in paragraph 3 are met (obligation of confidentiality, additional safeguards in national legislation). 4 As a general rule, the data processor providing healthcare services is the controller of the patient's personal data, who processes personal data on the basis of Article 6(1)(b) of the GDPR (contract for the provision of healthcare services) in conjunction with Article 9(2)(h) of the GDPR. If the controller uses processors (e.g. a laboratory, a provider of medical treatment, etc.) in the framework of the provision of healthcare services , the data must be processed either on the basis of a contract between the controller and the processor or on the basis of the patient's consent.

> Topics: Controllers, Special Categories of Data, Integrity and Confidentiality Principle, Data Processor

### ¶5

If data processing is carried out with the consent of a person, then in Article 4(11) of the GDPR, consent is defined as follows: "any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear statement of consent, signifies agreement to the processing of personal data relating to him or her." Therefore, based on the principle of Article 4, consent must always be freely given, specific, informed and unambiguous indication of the data subject's intention, by which he or she, by a statement or by a clear affirmation, signifies agreement to the processing of personal data relating to him or her. Consent must be given in such a way that there is no doubt whether it meets all the conditions at the same time (voluntary, informed, specific and unambiguous).

> Topics: Processing, Consent, Personal Data

### ¶6

The controller of personal data is responsible for the lawfulness of the processing and is able to prove its compliance (Article 5(2) of the GDPR).

> Topics: Controllers, Personal Data

### ¶7

The Inspectorate maintains all of its previous justifications, including 07.11.2025 in proposal no. 2.1-1/24/397-890-32, and highlights the following in this administrative act. Being a controller

> Topics: Controllers

### ¶8

The data processor has not questioned its being a controller of the patient data in the response to the inquiry or proposal, and there is no dispute in this regard. The initial patient reception takes place at the data processor and under its control, among other things, the treating physician decides on the suitability of the service provided to the patient, including the Invisalign service.

> Topics: Data Processor, Processors, Health Data, Processing

### ¶9

During the procedure, the data processor has not provided AKI with an overview of the relationship between the controller and the authorized processor in the further process of using the Invisalign service (collection of patient data based on consent and all other data processing). Based on the information collected during the procedure, AKI estimates that the process of using the Invisalign service is under the actual control of Align technology, Inc. , which assumes rights under the contract that define it to a certain extent as an independent controller or at least a co-controller, not as an authorized processor. Among other things, the following indicates this: a. Upon termination of the contract, Align Technology, Inc. personal data to the controller (dental clinic), except for data that Align Technology, Inc. stores in accordance with applicable law or on a backup server. Different documents give different retention periods: the data protection terms do not specify the retention period, the Invisalign Pricing Terms give a period of 7 years. It is not specified which or which country's applicable law is in mind, where the backup server is located and/or where and for how long the data is stored. b. The controller (dental clinic) ensures that the requirements for the processing of personal data are met, including that the patient has obtained proper consent, whereby the patient agrees that Align Technology, Inc. may transfer his or her personal data to members of the group and other authorized processors (so-called co-processors) and process his or her data outside 3 the European Union. However, the consent form is not in accordance with the requirements of the GDPR. c. Align Technology, Inc. stores personal data on servers that may be located outside the European Union. It is not specified who exactly decides where and which patient data is stored. d. The controller (dental clinic) can object to Align Technology, Inc. within 30 days of the use of a co-processor. The list of co-processors is published on the Align Technology, Inc. website and the controller must keep an eye on it. e. In the event that the patient changes doctor and/or clinic and the patient's data is transferred to the new doctor and/or clinic based on the respective consent, the controller (dental clinic) will no longer have access to the patient's data, including not within the scope of the service it provides. According to Estonian legislation, a healthcare provider must store data related to the provision of a service for 30 years. f. The controller (dental clinic) agrees upon signing the contract that Align Technology, Inc. may use patient data anonymously for advertising, marketing, research and development purposes. 7 In addition, in accordance with the data protection conditions, Align Technology, Inc. may publish the collected data (photos) for marketing purposes in a way that allows for the indirect identification of a person - the name is not published, but the person may be recognizable in the photo. It should be noted that the relevant information is contained in the data protection conditions created for the European Union (https://www.invisalign.eu/privacy-policy), but the patient consent page contains a reference to the general website https://www.aligntech.com, where the content of the data protection conditions can be found different.

> Topics: Processing, Consent, Controllers, Identification

### ¶10

Pursuant to Article 4(7) of the GDPR, the controller is the natural or legal person, public authority, agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data. According to Art 26, where two or more controllers jointly determine the purposes and means of the processing of personal data, they are joint controllers.

> Topics: Public Sector, Public Authority, Data Controller, Personal Data

### ¶11

The European Data Protection Board has clarified that the legal status of the controller is determined by the actual activities of the different parties in a specific situation, i.e. that the only decisive factor is not the formal division of roles agreed upon in a contract. The main purpose of assigning the controller role is to ensure accountability and the effective protection of personal data, and therefore the concept of controller should be interpreted broadly enough to ensure the protection of the rights of data subjects. In this 1 2https://www.aligntech.com/privacy_policy and https://www.invisalign.eu/privacy-policy EMEA Invisalign Pricing Terms (Euros): Data protection, p 1.9. 3EMEA Invisalign Pricing Terms (in Euros): Global Terms and Conditions, p 9. / EMEA Invisalign Pricing Terms (in Euros): Data protection 1.3./ Informed consent and agreement regarding the treatment method Invisalign® (Patient consent form) – privacy statement. 4EMEA Invisalign Pricing Terms (in Euros): Data protection, P 2.2. 5Privacy policy | Invisalign - "Who do we share your personal information with?" Current service providers 9cff2fcd-a686-4940-94a9-59e18c6b9aba 6EMEA Invisalign Pricing Terms (in Euros): Data protection, p 1.9., 1.10. 7EMEA Invisalign Pricing Terms (in Euros): Data protection, p 1.13. 8 Privacy policy | Invisalign - What do we do with the information we collect? We will never display your name in any promotional material we create, but you should be aware that other people may still recognize you from yours photograph. 6 (9) must take into account that if several parties are involved in the same processing, this does not mean that they necessarily act as joint processors. 9

> Topics: Accountability, Personal Data, Controllers, Consent

### ¶12

In the event that the controller involves a processor, the controller must be able to determine unilaterally the conditions of the processing and the purpose of the processing and to implement appropriate technical and organisational measures during the processing of personal data that are necessary to effectively implement data protection principles (such as data minimisation) and to integrate appropriate safeguards into the processing of personal data in order to protect the rights of data subjects (Art. 25 GDPR). The processor must, in accordance with Art. 28(3)(a) GDPR, be guided by the documented instructions of the controller and not vice versa.

> Topics: Controllers, Processors, Retention Period, Personal Data

### ¶13

Align Technology, Inc. cannot be considered a processor based on the information provided to the AKI, but is at least a joint processor within the meaning of Art. 26 GDPR. This is indicated, among other things, by the fact that they seem to have the entire process of providing the Invisalign service under their control, from drafting the consent form, establishing the data sets to be collected, designating data recipients (group), setting retention periods to selecting co-processors. Also, if Align Technology, Inc. were a processor, it would not be able to choose cooperation partners (Article 28(2) of the Data Protection Act) without the written consent of the controller such as courier companies, laboratories, support services (IT services, archiving). Align Technology, Inc. also assumes the right to apply binding rules within the group, including to the processing of personal data (e.g., data transfer within the group, storage), which indicates that the terms of the contract are also likely to be prescribed by Align Technology, Inc.

> Topics: Processors, Personal Data, Processing, Controllers

### ¶14

The ambiguity of roles is also indicated by the fact that the data processor only provided answers to the inquiry submitted by AKI on 26.09.2024 on 25.04.2025, after repeated attempts to contact the Invisalign representative office in Lithuania. The data processor itself did not have the information requested by AKI. In the response of 25.04., the data processor has, among others, stated the following. We are attaching to this response the official Invisalign files, which show the data protection principles of the Invisalign system. If there should be any problems with them (the same principles apply to all Invisalign treatment system providers around the world), then more detailed information or claims can and should be submitted directly to the person who set these conditions. Dr. Mõttus Hambaravi OÜ and other dental clinics using the same system do not have the opportunity to unilaterally change the aforementioned principles. The email also contains the position of the Invisalign representative, according to which legal contracts are concluded directly between Align Technology, Inc. and the healthcare provider. The data processor has not yet submitted to AKI an agreement that would reflect the data processing between the parties and has not been able to provide answers to the questions that they should be able to do as a controller.

> Topics: Health Data, Data Processor, Representatives, Processors

### ¶15

Also in their response to AKI's proposal on 19.01.2026, the data processor points out that unilateral changes to the terms are difficult. We also emphasize that Fullgevity OÜ cannot unilaterally establish or enforce such contractual terms and directly depends on the Invisalign service provider's readiness to make the corresponding changes, and their uniform standards for their service apply practically all over the world where the corresponding service is provided - and according to Invisalign partners, no problems in this area have been presented to them so far, including by the European Union authorities. Thus, the current issue is not the legal relationships related to a single clinic practicing the Invisalign treatment system, but the issue of possible corrections to the Invisalign global uniform standard, in which the positions of the owner-service provider of the Invisalign system are clearly decisive. 9 Guidelines of the European Data Protection Board 07/20 on the concepts of controller and processor in the General Data Protection Regulation, version 2.0, adopted on 07.07.2021, Part I, Chapter 1, paragraphs 12 and 14. 10Citymed 09.01.2025 letter to AKI. Since responding to your information request unfortunately largely requires receiving answers from third parties, unfortunately, a final answer has not yet been put together. We will be able to do this immediately when the information holder, a third party, receives answers to the questions we have sent. More precisely. Most of the information you have requested concerns the flow of information about the Invisalign system. 7 (9)16. The fact that Align Technology, Inc. is a large group that does not allow for flexibility is not a justification for not complying with the requirements of the GDPR. Among other things, many large service providers (e.g. Microsoft cloud, e-mail application, information system, etc.) are generally authorized processors and a written contract must be concluded with them. Large service providers often have standard terms and conditions, which may limit the ability of the controller to influence the processing conditions, but the controller must still ensure that the service provider's standard terms and conditions comply with the requirements of the GDPR and that the service provider itself does not turn out to be the actual controller.

> Topics: Data Processor, Processors, Processing, Controllers

### ¶17

In the event that Align Technology, Inc. (standard) conditions do not meet the requirements of the GDPR or the actual controller is Align Technology, Inc., the controller of the patient's data shall have the final decision on whether to choose the service provider or not and shall be responsible for the choice made to the data subjects and the supervisory authority.

> Topics: Supervisory Authorities, Supervision, Controllers

### ¶18

If the substantive assessment shows that there are joint controllers, the areas of responsibility for fulfilling the obligations arising from the GDPR (Article 26) must be agreed upon, including which activities each party is responsible for, who and in what part shall provide the data subject with the information required in Articles 13 and 14, who shall fulfil the requirements of which data subjects, who shall process breach notifications and notify the data subject/supervisory authority thereof, etc. Ensuring the principle of transparency

> Topics: Data Controller, Transparency, Supervisory Authorities, Supervision

### ¶19

At this time, the Invisalign service consent form provided to patients by the data processor and developed by Align Technology, Inc. is not in accordance with the requirements of the GDPR. For example, the consent page only includes a reference to the general website (not specifically to the data protection terms) https://www.aligntech.com, where the English-language data protection terms can be found. Since the company has separate data protection terms for the European Union, which are located at https://www.invisalign.eu/privacy-policy, this reference is not included on the consent page. As of 16.04.2026, the data protection terms are still missing from the data processor's website. The consent page also lacks an overview of who, where and for how long the data is stored, and it is not specified when and for what purpose the data is transferred to third parties, etc.

> Topics: Data Processor, Processors, Processing, Controllers

### ¶20

On 19.01.2026, the data processor submitted an amended consent page, to which additional aspects were added (e.g. data categories and purpose of processing), but the information resulting from IKÜM- art-test 13 and 14 outlined in the AKI proposal was still incomplete. Among other things, information was missing on: a. who is the authorized processor (or co-authorized, depending on the circumstances) within the framework of Invisalign treatment; b. what is the legal basis for data processing; c. who stores, where and for how long and what data exactly; d. when and for what purpose and what data is transferred to third parties (including within the group); e. what are the safeguards when transferring data to third countries; f. where data protection conditions are available; g. the possibility of contacting a supervisory authority to protect rights, etc.

> Topics: Data Processor, Processors, International Transfer, Supervisory Authorities

### ¶21

According to Article 5 of the GDPR, the requirement of transparency is one of the fundamental principles that is closely linked to the principles of fairness and lawfulness. Providing information to data subjects before consent is essential in order to enable them to make informed decisions, understand what they are agreeing to, and for example, exercise their right to withdraw consent. If the controller does not provide accessible information, user control becomes illusory and consent as a basis for processing is invalid. The controller must ensure that consent is given on the basis of information that allows data subjects to easily identify who the controller is and to understand what they are consenting to. The controller must clearly describe the purpose of the data processing for which consent is sought.

> Topics: Information Provision Modalities and Communication Methods, Transparency, Controllers, Consent

### ¶22

The controller must therefore be satisfied that the person's consent complies with the requirements set out in Article 4(11), Article 6(1)(a), Article 7 and Article 9(2)(a) of the GDPR and ensure that the information provided 8 (9) to data subjects, both in the data protection conditions and on the patient consent form, is relevant for the proper giving of consent.

> Topics: Controllers, Consent

### ¶23

The principle of transparency requires that all information relating to the processing of personal data is easily accessible, understandable and clearly worded to the data subject. This concerns in particular the information of data subjects in order to ensure fair and transparent processing. The information of individuals is regulated in more detail by Articles 12-14 of the GDPR. Articles 13 and 14 of the GDPR set out what the information provided to individuals should contain as a minimum.

> Topics: Fairness & Transparency, Transparency, Personal Data, Processing

### ¶24

On the Align Technology, Inc. website (both with the .com and .eu endings), the data protection terms are presented in English, which is why it cannot be assumed that all people are able to understand them unambiguously. It is also questionable whether accessing the data protection terms of the authorized processor ensures easily accessible information about data processing, since a person should presumably receive all information related to data processing primarily from the data protection terms of the dental clinic as the controller. A person should not have to independently search for whether and which authorized processors the dental clinic uses and what the conditions for processing the data of the authorized processors are.

> Topics: Information Provision Modalities and Communication Methods, Processors, Controllers

### ¶25

This means that in addition to the data protection conditions prepared by the authorized processor (or co-processor), the provision of information must also be ensured by the data processor, i.e. the dental clinic, both through the data protection conditions published on the website and through the patient's consent form. It is important to emphasize that the data processor cannot rely on the assumption or agreement that the authorized processor will make the required data available on its website, but must also actually verify this.

> Topics: Data Processor, Processors, Processing, Controllers

### ¶26

The controller is obliged to ensure that all information provided to the patient complies with the principle of transparency. Fulfilling this obligation requires harmonizing the data protection conditions of the consent form, the clinic itself and the authorized processor so that there is no conflicting information. In the case of the Invisalign service, the patient must consult three different documents, the information in which sometimes does not overlap, in particular regarding the relationship between the controller and the authorized processor, the transfer of data to third countries and the data collected and the storage of the results. Summary

> Topics: Processors, Transparency, International Transfer, Controllers

### ¶27

As a result of the above, the data processor has not been able to prove compliance with the GDPR requirements when using the Invisalign service. The roles between the controller and the authorized processor are unclear and Align Technology, Inc.'s actual control over the purposes and means of processing indicates at least a co-controller relationship within the meaning of Article 26 of the GDPR. There are no corresponding agreements on the distribution of roles, responsibilities and obligations.

> Topics: Data Processor, Joint Controllers, Processors, Processing

### ¶28

Transparency of data processing and valid consent are also not guaranteed: the patient is not provided with the required information on the legal basis for processing, purposes, data recipients, storage conditions, transfer to third countries, or safeguards. The consent obtained on the basis of the consent form does not comply with the requirements of the GDPR (Article 4(11), Article 6(1)(a), Article 7 and Article 9(2)(a). The transparency requirements arising from Articles 12–14 of the GDPR are also not ensured. The data processor's website still lacks the necessary data protection conditions.

> Topics: Data Processor, Processors, Transparency, International Transfer

### ¶29

In summary, the data processor has not ensured that the processing carried out within the framework of the Invisalign service is lawful and transparent in accordance with Article 5(1)(a) of the GDPR, and has not fulfilled its obligation to provide proof in accordance with Article 5(2) of the GDPR. (signed digitally) Kirsika Kuutma, lawyer, authorised by the Director General 9 (9)

> Topics: Data Processor, Processors, Processing, Controllers

## Cited law provisions (1)

### GDPR — gdpr-art-4-par-7-en

‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

---
Generated by overview.legal · https://overview.legal/posts/53882 · 2026-08-22
