Receive a package of free GDPR guides and micro-trainings
Before making a decision regarding the necessity of entering into a data processing agreement, the factual situation in which both entities operate, between which data will flow, should be assessed. In practice, it may often turn out that entering into a data processing agreement will not be necessary, as the roles of the two entities involved in the data transfer must be assessed as independent data controllers. It should be noted at this point that the data processing agreement referred to in Article 28(3) of the GDPR does not have a constitutive character for the data processing delegation process.
This means that the agreement itself cannot be considered as a condition or a creator of the delegation relationship. It is necessary to agree with the thesis that the data processing delegation relationship can exist independently of the conclusion of a data processing agreement. Its absence should be regarded as a formal deficiency resulting in a violation of the provisions of the EU regulation. Therefore, the characterization of the analyzed factual situation as a delegation of personal data processing has an objective nature. However, there are certain criteria that will help us conduct the appropriate assessment in this regard.
Important:
The data processing agreement regulates the relationship between the data controller and the data processor.
It will not be required in the case of data transfers between two independent data controllers. If you have doubts about how to distinguish co-administration from data processing delegation, we write about it here.
Data Processing Delegation
vs. Provision of Personal Data
Legal regulations concerning the protection of personal data do not precisely define what data processing by a data processor actually entails. However, there are provisions that allow for the identification of certain characteristics of this institution. Article 4(8) of the GDPR contains the definition of a data processor, which is understood as a natural or legal person, a public authority, or another entity that processes personal data on behalf of the data controller. From the cited provision, it follows that the most significant characteristic allowing a given entity to be referred to as a data processor is that it acts on the instructions of the data controller (in its name and on its behalf). Therefore, it seems reasonable to adopt the view that a more accurate term for such an entity would be "data processor on behalf of." This approach would allow for a clear distinction between an external entity (not belonging to the structure of the data controller) processing data on behalf of and for the data controller, and, for example, employees who, as part of their duties, may also process personal data on behalf of the data controller.
Cezary Lutyński – our data protection advisor will advise you on when to apply data processing on behalf of the data controller in your company. Contact him to schedule a meeting.
Processing personal data on behalf of the data controller will occur when an external entity provides certain services for the data controller; however, this does not have to be the primary task assigned to the external entity. Activities involving the processing of personal data may be an integral part of or may be directly related to the performance of other services provided by the external entity for the data controller. It follows from the above that the essence of data processing on behalf of the data controller is closely linked to the concept of outsourcing. The term outsourcing refers to the delegation to external entities, specialized in a specific area, of processes necessary for the functioning of the delegating entity. The idea behind such actions is to carry out a specific process in a more efficient manner than would be possible using only the resources of the delegating entity itself. In other words, the concept of outsourcing should be understood as a type of agreement in a business context whereby activities that could be performed by the entity itself or its employees are entrusted to a third party for execution. The aim of outsourcing is thus the delegation of certain responsibilities from one entrepreneur to another entity in a formalized manner, i.e., based on an agreement concluded between these entities.
At this point, it also seems important to compare the definitions of data controller and data processor, which will allow for the identification of another significant characteristic of the data processor. Art. 4 point 9 of the GDPR explicitly states that it is the data controller who determines the purposes and means of processing personal data. From this, it follows that the fundamental characteristic of delegating the processing of personal data is that the data processor does not have full discretion regarding the actions taken on the personal data received from the data controller. One could posit that the role of the processor is secondary, as it only takes actions on the personal data after the data controller has defined the purpose and means of processing.
In light of the above, we can define the delegation of personal data processing as a situation where the data controller, wishing to utilize the services of an external entity, transfers personal data for which it is responsible. At the same time, the actions of this external entity related to the processing of personal data are closely tied to the decision of the data controller, who is solely entitled to specify the purposes and means of processing that data. All actions taken by the external entity are performed on behalf of and for the benefit of the data controller, at whose direction it operates. All significant issues regarding the delegation of personal data processing should be regulated in a data processing agreement concluded between the data processor and the data controller (in accordance with art. 28 of the GDPR).
Important:
The most significant characteristic of the data processor is that it acts on the instruction of the data controller (in its name and for its benefit). The data processor undertakes its actions only after the data controller has defined the purposes and means of processing the data.
As mentioned at the outset of this article, the transfer of data between two entities may also be classified as the sharing of that data. Similar to the concept of data processing delegation, the regulations do not provide a definition for the sharing of personal data. Regardless of the above, this concept is commonly used in practice. By sharing data, one should understand nothing other than one of the forms of processing personal data, as stated in Article 4(2) of the GDPR, which indicates that processing means operations or a set of operations on personal data such as, among others, dissemination or other forms of sharing. According to the accepted views of representatives of the doctrine, a characteristic feature of this form of processing is that it occurs when data is transferred between two entities that independently decide on the purposes and means of processing personal data. In connection with the above, in this case, the recipient of the data will only be a separate data controller. It should be noted that in the case of data sharing, the GDPR does not provide specific rules for its execution, e.g., the necessity to conclude an appropriate agreement. Therefore, the nature of the act of sharing data should be assessed as a factual act, which means that it can occur in any manner resulting in the recipient gaining access to personal data, enabling them to make actual independent decisions regarding the purposes and means of processing that data. Thus, we cannot speak of data sharing in the relationship between the data controller and the data processor in the sense of Article 4(8) of the GDPR, as has been demonstrated earlier, the latter acts solely within the scope of the purposes and means defined by the data controller itself.
Important:
If it turns out that our contractor to whom we transfer data is a separate data controller, then this constitutes the sharing of personal data. This means that a data processing agreement does not need to be concluded.
Who is our contractor: a separate data controller
or a data processor?
Analysis of the necessity to conclude a data processing agreement
Qualifying entities into one of two categories, namely data controller or data processor, is objective in nature and occurs in connection with specific circumstances, economic decisions made, and the assessment of who makes decisions regarding the purpose of processing personal data and the means by which it is carried out.[8] Correctly identifying the entities involved in the analyzed data processing process will allow for the determination of whether personal data processing is entrusted and, consequently, whether it is necessary to conclude the agreement required by Article 28 of the GDPR.
For the proper qualification of individual entities within the aforementioned categories, it is necessary to analyze them in terms of the characteristics specific to a separate data controller. In this regard, the Opinion 1/2010 on the concepts of “data controller” and “processor” 00264/10/PL WP 169 issued on February 16, 2010, by the Article 29 Working Party will be helpful. Although it was issued under the old Data Protection Directive 95/46/EC, it remains relevant in clarifying the concepts discussed therein.
Indicating in the relationship between two entities which one determines the purposes and means of data processing should be based on both legal and factual circumstances. From these, the dependency of one entity on the other or the independence of both entities may arise. The aforementioned opinion of the Article 29 Working Party lists elements that may be crucial for identifying the data controller and the data processor:
- Control over processed data resulting from explicit legal competencies
This pertains to situations where the data controller or specific criteria necessary for its identification arise directly from applicable legal provisions. A direct specification in the legal provision that a specific entity is the data controller should leave no doubt. It should be noted that the GDPR indicates that provisions in Union law or the law of a Member State may directly designate the data controller or may specify particular criteria for designating the controller (see Article 4(7) of the GDPR).
At this point, it is also possible to indicate a situation where legal provisions impose on a specific entity only the obligation to process personal data. Entities that have been imposed the obligation to collect a specific scope of personal data should be regarded as separate data controllers. - Control over processed data resulting from implied competencies
This premise can be encountered in situations where the legal provision does not explicitly define the role of the entity as a data controller nor indicates the obligation for a specific entity to collect personal data. However, the role of the entity as a data controller may then arise from certain established practices. Key to identifying the controller in such cases may be traditional roles shaped within accepted practices, e.g.: an employer in relation to data concerning its employees, a publisher in relation to data concerning subscribers, an association in relation to data concerning its members or supporters. - Control over data processing resulting from actual influence
The last of the criteria directly relates to the assessment of the circumstances of a given case. This arises from the fact that there are no specific provisions regulating the administration of data or their collection, and no practice has developed in this regard. In most such cases, our analysis will begin with an assessment of the contractual relationships occurring between the entities involved in the processing of personal data. It should be emphasized that the assignment of the appropriate status (data controller or data processor) to the individual parties to the agreement should always be verified against the actual level of control over the processing of data exercised by these entities. According to the author, this last criterion should be binding when determining the data controller. An entity that does not have legal or factual control over determining the purpose and means of processing personal data cannot be considered a data controller.
Determining the purposes and means of data processing –
what does it really mean?
Free knowledge about GDPR.
Feel free to use it!
It should be emphasized that the determination of the means of data processing should not be associated solely with the decision regarding the technical measures used in the processing process. The determination of the means of data processing includes, in addition to technical issues, also organizational aspects and essential elements of the processing itself. The latter group includes the following issues: what type of data is being processed?, how long will the data be processed?, what third parties have access to this data?, when is the data deleted?, who has access to the data?. It is agreed with the thesis presented in the referenced opinion of the Article 29 Working Party that the determination of the aforementioned essential elements regarding the means of data processing is the exclusive right of the data controller. In other respects, i.e., the decision regarding the specific technical and organizational measures used, it may be delegated to the data processor (e.g., regarding the computer equipment or software used). However, it should be emphasized that the adopted technical and organizational measures should be adequate to achieve the purposes of processing, which are determined solely by the data controller.
The purpose of processing refers to the intended result or effect of a specific action (processing of personal data). According to Article 5(1)(b) of the GDPR, this purpose should be defined in a specific, clear, legally justified manner and should not be subject to arbitrary changes during the processing activities.[12] Whoever makes this decision is (in fact) the data controller. Therefore, if the data processor has an influence on determining the purposes or uses personal data to achieve its own purposes, it should generally be considered a separate data controller.
In summary, it should be noted that in a situation where none of the characteristic elements mentioned in this article apply when assessing a specific entity, there will be no basis for designating it as a data controller. This means that it will be a data processor acting on behalf of the data controller, which will necessitate the conclusion of a data processing agreement in accordance with Article 28 of the GDPR.
Download: template of a data processing agreement compliant with the GDPR


