Guidelines of the EDPB on the concepts of data controller and data processor under the GDPR (part 2/2)

27 October 2020

In accordance with the announcement, we invite you to the second part of the study on the Guidelines adopted by the European Data Protection Board regarding the concepts of data controller and data processor under the GDPR, which are in the public consultation phase until October 19, 2020.

In the first part of the study, we focused on the definitions of the data controller, joint controllers, data processor, third party, and data recipient. In this part, we will present the EROD guidelines regarding the relationship of entrustment and the relationship between joint controllers.

The Relationship Between the Data Controller and the Data Processor

An undeniable novelty introduced by the GDPR was the provisions imposing obligations directly on data processors (for example, Article 28(3), Article 30(2), Article 32, Article 37 or Article 33(2) of the GDPR). At the same time, due to the fact that the data controller is obliged to use only those data processors that provide sufficient guarantees for the implementation of appropriate technical and organizational measures, so that the processing meets the requirements set out in the GDPR, the data controller has the obligation to assess the extent to which the guarantees provided by the data processor are sufficient, and it should be able to demonstrate that it took into account all necessary elements arising from the GDPR during this assessment.

By guarantees provided by the processor, one should obviously understand those that the processor is able to demonstrate, as only these can be taken into account in the compliance assessment conducted by the data controller. For example, providing these guarantees will often require the provision of appropriate documentation (e.g., records of processing activities, reports from external audits, recognized international certifications, such as the ISO 27000 series).

The assessment conducted by the data controller is a form of risk assessment, the outcome of which will largely depend on the type of processing entrusted to the processor and which should be performed individually with respect to each case of entrustment, taking into account the nature, scope, context, and purposes of the processing, as well as the risks to the rights and freedoms of natural persons. The data controller should consider elements such as: the processor's expertise (e.g., specialized technical knowledge regarding security measures and data breaches); the reliability of the processor; and the resources available to the processor.

It is worth noting that the obligation expressed in Article 28(1) of the GDPR to use only processors that provide sufficient guarantees is a continuous obligation, not a one-time requirement. It does not end upon the conclusion of a contract between the data controller and the data processor.

Form and Content of the Data Processing Agreement

The issue of entrusting data processing should be regulated in writing, including in electronic form. This means that unwritten agreements (regardless of how precise and effective they may be) cannot be considered sufficient to meet the requirement set out in Article 28 of the GDPR. To avoid any difficulties in demonstrating that the agreement or other legal instrument is actually binding, the EDPB recommends ensuring that the legal act contains the necessary signatures.

The EDPB emphasizes that both the data controller and the data processor are responsible for ensuring that the data processing agreement (or other legal instrument) has actually been concluded. In order to fulfill the obligation to conclude an agreement, the data controller and the data processor may negotiate their own agreement, encompassing all mandatory elements, or rely, in whole or in part, on the content of standard contractual clauses (SCC) regarding obligations under Article 28 of the GDPR. At the same time, the EDPB notes that entering into a data processing agreement based on SCC is neither a requirement nor is such an agreement in any way preferred over negotiating an individual agreement. Both options are appropriate for the purposes of compliance with data protection law, provided they meet the requirements of Article 28(3) of the GDPR.

The fact that the agreement and its specific commercial terms are prepared by the service provider, rather than by the data controller, is not problematic in itself and does not constitute a sufficient basis for concluding that the service provider should be regarded as a data controller. Similarly, the lack of balance in contractual rights between a small data controller and large service providers should not be considered a justification for the data controller to accept clauses and terms of agreements that are not compliant with data protection law, nor does it exempt the data controller from the obligations imposed on them under the GDPR. The data controller must assess the conditions imposed on them and, to the extent that they freely accept and utilize the service, they also assume full responsibility for compliance with the GDPR.

FREE

Key and Most Challenging Concepts - Practical Examples Only.

Watch the webinar

While the elements specified in Article 28 of the GDPR constitute mandatory content of the agreement between the data controller and the data processor, the concluded agreement should serve as a means for the data controller and the data processor to further clarify (in the form of detailed instructions) how these elements required by the GDPR will be implemented. The EDPB emphasizes that the agreement between the data controller and the data processor should not merely repeat the GDPR, but rather provide a detailed specification along with specific information on how the requirements set forth in the agreement will be fulfilled.

At the same time, the agreement should take into account "the specific tasks and responsibilities of the processor in the context of the processing to be carried out, as well as the risks to the rights and freedoms of the data subjects." In other words, the agreement between the parties should be drafted in light of the specific data processing activity.

In the opinion of the EDPB, the data processing agreement should include the following elements:

  • the subject of processing (e.g., video recordings of individuals entering and exiting a high-security facility),
  • duration of processing: the exact time frame or criteria used to determine it should be specified (for example, reference can be made to the duration of the data processing agreement),
  • nature of processing: the type of operations performed within the processing (e.g., filming, recording, archiving images) and the purpose of processing (e.g., detection of unauthorized access); this description should be as comprehensive as possible,
  • type of personal data: it should be specified in the most detailed manner possible (example: video footage of individuals entering and exiting the premises). It would be deemed insufficient to state that it concerns "special categories of personal data referred to in Article 9 of the GDPR". In the case of special categories of data, the agreement or other legal instrument should at least specify what kind of data it concerns, for example: "information regarding medical documentation" or "information on whether the data subject is a member of a trade union",
  • categories of individuals whose data is being processed (for example: guests, employees, service providers),
  • obligations and rights of the data controller.

Documented instruction of the data controller

Since the instructions under which the processor processes data belonging to the data controller must be documented, it is recommended that the procedure and template for providing further instructions be attached to the data processing agreement (or other legal instrument). Such instruction may be issued in any written form (e.g., via email), provided that there is a possibility to control such instructions (for example, in the form of a record).

Important
EROD recommends that the data controller pays due attention to the obligation to issue instructions regarding processing, particularly when the processor intends to transfer certain processing activities to other data processors and when the processor has branches or units located in third countries.

The processor should take all measures required under Article 32 of the GDPR

The agreement must include or refer to information regarding the security measures to be taken by the data processor and include the data processor's obligation to obtain the data controller's consent before making any changes to them, as well as a regular review of the security measures to ensure their adequacy in relation to threats that may evolve over time.

The specificity of the instructions provided by the data controller to the processor regarding the measures to be applied will vary depending on the circumstances. In some cases, the data controller may provide a clear and detailed description of the security measures to be implemented by the processor. In others, the data controller may specify minimum protection objectives that must be achieved while asking the processor to propose the implementation of specific security measures. In any case, the data controller should provide the processor with a description of the processing activities and security objectives (based on a risk assessment conducted by the data controller), as well as approve the measures proposed by the data processor. According to the EDPB, such information could be included in the data processing agreement.

GDPR. Support is useful!

Assistance to the data controller in fulfilling the obligation to respond to requests from data subjects and to comply with the obligations specified in Articles 32 – 36 of the GDPR;

While assistance in responding to requests from individuals may simply involve promptly forwarding each received request, there may be circumstances in which it is justified for the data processor to receive more detailed, technical obligations in this regard – primarily when it is involved in the collection and management of personal data. However, it should be noted that although the practical aspect of managing requests from individuals may be delegated to the data processor, the data controller remains responsible for fulfilling such requests. Consequently, the assessment of whether the requests from data subjects are admissible and/or whether the requirements set forth by the GDPR are met should be conducted directly by the data controller.

When it comes to assisting the data controller in fulfilling the obligations specified in Articles 32-36 of the GDPR, it is essential that the agreement does not merely repeat the obligations outlined in the GDPR regarding assistance to the data controller: the agreement should include details on how the data processor may be requested to assist the data controller in meeting the specified obligations. For example, procedures and templates may be added as attachments to the agreement, which would facilitate the data processor's provision of all necessary information to the data controller.

Furthermore, the data processor should assist the data controller in fulfilling the obligation to report personal data breaches to the supervisory authority, and if a high risk to the rights and freedoms of natural persons is identified – also to the affected individuals. The data processor must notify the data controller of any instance in which it discovers a breach affecting the data processor's or sub-processor's resources/information systems and is simultaneously obliged to assist the data controller in obtaining the information that must be provided in the breach notification to the supervisory authority. The EDPB recommends that the agreement specify the timeframes for such notification (e.g., by indicating the number of hours) and provide a contact point for such notifications as well as the manner of informing the data controller about the detected breach.

Additionally, the data processor must also assist the data controller in conducting a Data Protection Impact Assessment (DPIA) – when required – and in consulting with the supervisory authority when the DPIA outcome reveals that there is a high risk that cannot be mitigated. The obligation to assist does not entail the transfer of responsibility, as these obligations still rest with the data controller. For example: although the DPIA may, in practice, be conducted by the data processor, the data controller remains responsible for the obligation to carry out this assessment, and the data processor is obliged to assist the data controller "only if necessary and upon request."

Important
If the data processor violates the GDPR by independently deciding on the purposes and means of processing, it should be regarded as a separate data controller, in accordance with Article 28(10) of the GDPR.

Further Data Processors

Although the chain of further data processors may be quite long, the data controller still retains its key role in determining the purposes and means of processing. Article 28(2) of the GDPR states that the processor may not engage another processor without the prior specific or general written consent of the data controller. In the case of general consent, the processor must inform the data controller of any intended changes regarding the addition or replacement of other data processors, which gives the data controller the opportunity to object to such changes.

If the data controller decides to grant specific consent, it should specify in writing which sub-processor and for which processing activity has been appointed. Any subsequent changes prior to their implementation must still be authorized by the data controller. Alternatively, the data controller may grant general consent for the use of sub-processors (in the data processing agreement, including a list of such entities in an annex), which should be supplemented with criteria that the data processors should follow in any further delegation (e.g., guarantees regarding technical and organizational measures, expertise, reliability, and resources). Consequently, the main difference between specific and general consent lies in the significance attributed to the silence of the data controller.

Interesting Fact
The imposition of "the same" obligations should be interpreted functionally rather than formally: it is not necessary for the agreement to contain exactly the same wording as that used in the agreement between the data controller and the data processor. However, the data processor transferring data "further" should ensure that the obligations imposed on the further data processor remain essentially the same.

Consequences of Joint Administration

Determining Appropriate Scope of Responsibilities

According to Article 26 of the GDPR, through mutual agreements, joint controllers transparently define the respective scopes of their responsibilities regarding the fulfillment of obligations arising from the GDPR. Joint controllers must therefore determine "who does what," deciding among themselves who will be responsible for which tasks, to ensure that the processing is compliant with the regulations.

Free GDPR advice
There are no stupid GDPR questions.
There are free answers
Take advantage of free legal or IT advice.
I HAVE A QUESTION
The purpose of this obligation is to ensure that in the case of the involvement of multiple entities, especially in complex data processing environments, the responsibility for compliance with data protection principles is clearly assigned, to prevent situations where the protection of personal data would be limited or where a conflict of competence could lead to legal gaps, resulting in none of the parties involved in the data processing fulfilling certain obligations.

The provision clearly indicates that joint controllers must specify, in particular, which of them will be responsible for exercising the rights of data subjects granted to them under the GDPR, as well as for fulfilling the obligations regarding the provision of information referred to in Articles 13 and 14 of the GDPR. However, the use of the phrase "in particular" clearly indicates that this is not an exhaustive list.

In practice, joint controllers must ensure that all joint data processing is fully compliant with the GDPR. In this regard, as part of the measures to ensure compliance and the related obligations – in addition to those specifically defined in the article – joint controllers should also consider the following when dividing responsibilities:

  • the implementation of general data protection principles (Article 5 of the GDPR)
  • legal basis for processing (art. 6 GDPR)
  • security measures (art. 32 GDPR)
  • notification of a personal data breach to the supervisory authority and the data subject (art. 33 and 34 GDPR)
  • Data Protection Impact Assessment (art. 35 and 36 GDPR)
  • use of services of a data processor (art. 28 GDPR)
  • transfer of data to third countries (Chapter V GDPR)
  • organization of contacts with data subjects and supervisory authorities.

Other issues that may be considered depending on the specific process and the intentions of the parties include, for example, restrictions on the use of personal data by individual joint controllers for purposes other than those jointly established. In such a situation, each joint controller is always obliged to ensure that they have a legal basis for processing. Sometimes co-administered data is shared with another data controller. In light of the accountability principle, each controller is obliged to ensure that the data is not further processed in a manner inconsistent with the purposes for which it was originally collected by the data controller that shared the data.

Joint controllers have a certain degree of flexibility in dividing responsibilities among themselves, provided they ensure full compliance with the GDPR; responsibilities do not also have to be evenly distributed among joint controllers. Furthermore, there may be cases where not all responsibilities can be divided, and each joint controller will be required to comply with the same requirements arising from the GDPR, taking into account the nature and context of the joint processing.

An example
is the obligation for each joint controller to maintain records of processing activities or appoint a Data Protection Officer, if the conditions from art. 37(1) GDPR are met. Such requirements are not related to joint processing but apply to them as joint controllers.

Form of Arrangements

The GDPR does not specify the legal form in which arrangements between joint controllers should be made. This means that joint controllers have the freedom to determine their form. However, in the interest of legal certainty, the EDPB recommends that such arrangements be made in the form of a binding document, such as a contract or another binding legal act under EU law or the law of the member state to which the data controllers are subject. This would provide certainty and could be used as evidence of the implementation of the principles of transparency and accountability in the context of processing. To better define the division of responsibilities between the parties, the EDPB recommends that the agreement also includes general information about the joint processing, particularly by specifying the subject matter and purposes of the processing, the types of personal data, and the categories of data subjects.

Obligations towards Data Subjects and Supervisory Authorities

It is crucial for joint controllers to clarify in the agreement the role they perform, particularly regarding the exercise of data subject rights and their obligations concerning the provision of information referred to in Articles 13 and 14 of the GDPR. The manner in which these obligations are divided should accurately reflect the reality underlying the joint processing. For example, if only one of the joint controllers communicates with data subjects, that joint controller is likely to be in a better position to inform data subjects and potentially respond to requests for the exercise of their rights.

The obligation to provide the essential part of the arrangements is key for the data subject, so that they know which of the controllers is responsible for what. What should be understood as the essential part of the arrangements is not defined by the GDPR. The EDPB recommends that the essence includes at least all elements of information referred to in Articles 13 and 14, and for each of these elements, the arrangements should specify which of the joint data controllers is responsible for ensuring compliance with that specific element. The essence of the agreement must also include the indication of a contact point, if one has been designated.

The GDPR does not specify how to provide the essential part of the arrangements to the data subjects. Therefore, it is up to the joint controllers to decide on the most effective way to share the arrangements (e.g., along with the information contained in Article 13 or 14 of the GDPR, in the privacy policy, or upon request submitted to the Data Protection Officer, if one exists, or to the contact point – if designated).

Article 26(1) of the GDPR provides for the possibility for joint controllers to designate a contact point for data subjects, which is not mandatory. However, indicating a single contact method with the joint controllers allows data subjects to obtain information about whom they can contact regarding all matters related to the processing of their personal data. Furthermore, it enables multiple data controllers to coordinate their relationships and communication with data subjects more effectively. For these reasons, in order to facilitate the exercise of the rights of data subjects, the EDPB recommends that joint controllers designate such a contact point. The contact point may be a Data Protection Officer, if one exists, a representative in the Union, or any other contact point where necessary information can be obtained.

Even if joint controllers have designated a contact point, this does not mean that data subjects must comply with it. The requirement for individuals to contact the designated contact point or the responsible data controller would impose an excessive burden on them, which would be contrary to the objective of facilitating the exercise of their rights under the GDPR.

Regardless of the above, data controllers should organize in their agreements the manner in which they will communicate with the relevant supervisory authorities. Such communication could include possible consultations under Article 36 of the GDPR, reporting a personal data breach, or appointing a Data Protection Officer (DPO). However, it should be noted that data protection supervisory authorities are not bound by the terms of these agreements - neither regarding the qualification of the parties as joint data controllers nor the designated point of contact. Consequently, the authorities may contact any of the joint data controllers to exercise their powers under Article 58 in relation to the joint processing of data.

Summary

Opinions on the Guidelines and their usefulness are divided, and it is hard not to get the impression that they will not revolutionize our perception of the institution of data administration, joint data administration, or data entrustment. We await the final shape of the Guidelines that will emerge after public consultations; however, experience indicates that the EDPB generally does not take to heart the amendments proposed during the consultations, thus the current draft can be considered almost final.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.