Redact insured-party files.
Archive decisions.
Social data protection by design.
Docuflair for social insurance agencies: insured-party files with PII redaction for inter-agency cooperation, audit-proof decision archiving under section 304 SGB III, multi-tenant operation across regional agencies. 100% on-premises, compliant with BDSG sections 45 to 84.
Social data is especially protected — and especially voluminous.
Social data protection (section 35 SGB I)
Social data is subject to social secrecy — stricter purpose binding than the GDPR, disclosure only within narrow limits. Breaches carry criminal liability under section 203 of the German Criminal Code.
Insured-party files for 30+ years
Pension files must be kept for at least 30 years, accident/occupational-disease files sometimes for life. Paper archives on that timescale are both an operational and a data-protection risk.
Inter-agency cooperation
Cooperation between pension, health and accident agencies requires extracts of insured-party files — but only the purpose-relevant content, without third-party data. Manual redaction is a source of errors.
Decisions with third-party data
Decisions often contain information about employers, physicians and relatives — before file inspection by the insured or authorised representatives, third-party data must be redacted. High effort, tight deadlines.
How Docuflair supports social insurance agencies
PII redaction at data transfer
Automatic detection and redaction of third-party personal data in 9 PII categories — before inter-agency cooperation, file inspection, appeal or litigation proceedings. Reusable profiles per file type.
More about RedactArchive under section 304 SGB III
Audit-proof long-term archiving with SHA-256 hash, retention rules per file type and tamper-resistant storage — section 304 SGB III (employment agency), section 147 SGB VI (pension), SGB V/VII/XI (health/accident/care).
More about ArchiveWorkflow for appeal procedures
Appeal, deadline monitoring (three months under the Social Court Act), assignment to appeals office, decision and handover to the social court — fully modelled with audit trail and electronic file transfer.
More about WorkflowTenant separation for regional agencies
Multi-tenant architecture for regional agencies (federal vs. regional DRV) or nationwide funds with branch offices. One platform, separated data rooms, central reporting.
More about Access ControlInsured-party case in 5 steps
Create insured-party case
A new case with insured-party number is created in the specialist system — Docuflair references the case number. Role-based access for caseworkers, medical service and appeals office.
Scan files
Medical reports, certificates, findings and applications are scanned, OCR-recognised and stored audit-proof. TR-RESISCAN enables legally compliant destruction of paper originals.
Redact
Before transfer to inter-agency partners, insured parties or the social court, third-party data is automatically masked across 9 PII categories. Reusable redaction profiles.
Issue decision
Decision from a template, electronically signed, dispatch via De-Mail, E-POST or paper. The audit trail documents creation, signature and dispatch with timestamps.
Archive for 30 years
SHA-256-secured storage with retention rules per file type — pension files 30 years, employers'-liability files partially for life. On-schedule deletion is technically guaranteed.
Typical social insurance scenarios
Regional pension insurance agency
A regional DRV agency with several state sites and a central headquarters. Docuflair standardises the insured-party files, cooperation with federal DRV and other regional agencies runs with automatic redaction.
- Nationally consolidatable
- Automatic inter-agency redaction
- 30-year archive
Health fund with nationwide branches
A statutory health insurance fund with branches in every federal state. Docuflair operates as a multi-tenant platform across all locations, central archive, separated work areas, consolidated reporting for the medical service.
- Multi-location tenants
- Medical-service access controls
- SGB V-compliant deletion deadlines
Federal Employment Agency / local agency
A local employment agency with a high volume of applications — unemployment benefit decisions, training applications, integration agreements. Docuflair digitises the application-to-decision cycle and archives under section 304 SGB III.
- Volume under control
- Section 304 SGB III-compliant
- Appeal workflow
The key modules for social insurance
Top 3 core products plus complementary modules for insured-party operations
Docuflair Archive
Audit-proof long-term archiving up to 30+ years — SHA-256, retention under section 304 SGB III, tamper protection.
Learn moreDocuflair Redact
Automatic PII redaction in 9 categories for inter-agency cooperation, file inspection and litigation.
Learn moreDocuflair Workflow
Appeal procedures, deadline monitoring, decision creation with audit trail.
Learn moreLegal frameworks Docuflair supports
Section 35 SGB I (social data protection)
Social secrecy, purpose binding, disclosure within narrow limits — implemented through role-based access and automatic redaction.
Section 304 SGB III (archiving)
Retention obligations of the Federal Employment Agency — retention rules per file type, tamper-resistant SHA-256 storage.
BDSG sections 45 to 84
Special provisions for social data in the German Federal Data Protection Act — logging, deletion deadlines and transfer restrictions implemented technically.
GDPR
General Data Protection Regulation as a framework — on-premises architecture meets Schrems II requirements for third-country transfers.
Note on cloud services: Social data under section 35 SGB I must not be outsourced to US cloud providers (CLOUD Act, Schrems II). Docuflair runs exclusively on-premises at the agency or in a GKV/DRV data centre — no cloud components, no external telemetry.
Frequently Asked Questions
Answers to the most important questions for social insurance agencies
How is social data protection under section 35 SGB I implemented in Docuflair?
Docuflair implements the requirements of social data protection under section 35 SGB I and sections 67ff. SGB X technically: purpose binding through role-based access, logging of every access in the SHA-256 audit trail, deletion deadlines through retention rules, PII redaction before any data transfer. The on-premises architecture ensures social data does not leave the agency.
Does Docuflair fulfil the retention obligation under section 304 SGB III?
Yes. Docuflair Archive provides audit-proof long-term archiving with SHA-256 hash, tamper-resistant storage and retention rules per file type — Federal Employment Agency decisions under section 304 SGB III, pension files under section 147 SGB VI, health/care files under SGB V/XI, each with statutory deadlines.
Does Docuflair support appeal procedures with a workflow?
Yes. Docuflair Workflow maps the appeal path — filing, assignment to the appeals office, deadline monitoring (three months under the Social Court Act) through to the decision. Before handover to the social court, files are automatically redacted.
Can Docuflair integrate with DRV-Service or GKV-Spitzenverband IT landscapes?
Docuflair provides open interfaces (REST API, file exchange, SFTP) and can connect to specialist systems — DRV systems, AOK base systems, BITMARCK or ITSG landscapes. The specific integration is agreed in a preparatory call.
Why can social data not be stored in the cloud?
Social data is subject to social secrecy (section 35 SGB I) and the BDSG special provisions in sections 45 to 84. Outsourcing to US cloud providers is legally highly problematic due to the CLOUD Act and Schrems II. Docuflair runs exclusively on-premises — at the agency or in a data centre of a GKV/DRV IT service provider.
Does Docuflair meet Austrian data-protection requirements for sensitive records?
Yes. Docuflair captures, redacts and archives sensitive records audit-proof and GDPR- and DSG-compliant, and integrates with electronic file management (ELAK). Personal data is reliably pseudonymised or redacted – on-premises or dedicated private cloud, so all data stays in-house.
Is Docuflair suitable for Swiss bodies handling sensitive personal data?
Yes. Docuflair complies with the revised Swiss Federal Act on Data Protection (revDSG/nFADP, in force since 1 September 2023) and archives sensitive records audit-proof and unalterable. On-premises or dedicated private-cloud operation ensures personal data never leaves Switzerland.
More public-sector solutions
Public sector (hub)
Overview of all public-sector solutions: police, justice, ministries, municipalities, social insurance.
Learn moreCourts
Electronic court file (eAkte) under section 298a ZPO, PII redaction for file inspection, SHA-256 tamper protection.
Learn moreReady for compliant social-insurance file processing?
15-minute demo — we show you how Docuflair redacts insured-party files, archives decisions and maps the appeal workflow. No marketing noise, real software against real social-insurance scenarios.
Compliance across the DACH region and the EU
Docuflair supports the retention and data-protection requirements of Germany, Austria and Switzerland, plus GDPR across the European Union.
Germany
GDPR and sector-specific data protection: audit-proof capture, reliable pseudonymisation and redaction of sensitive personal data.
Austria
DSG and electronic file management (ELAK): pseudonymisation or redaction of sensitive personal data, audit-proof PDF/A archiving.
Switzerland
revDSG (in force since 1 September 2023): audit-proof, unalterable archiving of sensitive records; personal data never leaves Switzerland.