Have you already concluded data processing agreements?

18 September 2013

Data processing agreements have always raised many doubts and surprises among legal departments, accounting firms, and IT departments. The reason is that it is one of the few agreements in our legal system that is gratuitous, which, however, does not mean that it does not incur costs for one or the other party to the agreement. Why should we sign such agreements? Do we really have to enter into them? If we must, in what situations? Answers below.

No Agreement – Criminal Sanctions!

According to Article 28 of the GDPR, entities have the right to entrust the processing of personal data. What does this mean in practice? Most entities were doing this even before the implementation of the personal data protection system. The most common basis for entering into a data processing agreement is a service contract for a given entity, e.g., IT service, known as IT outsourcing (download the template of the data processing agreement).

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE

Data processing agreements are only seemingly an option or possibility. In practice, their absence can cost us significantly. Firstly, we face criminal liability – Article 51 of the Polish DPA provides that disclosing personal data to an unauthorized person may result, at best, in a fine, and at worst – up to 2 years of imprisonment. In this case, the unauthorized person would be an IT specialist from outsourcing. Secondly, if a data breach occurs due to the fault of an external entity, we lack a contractual legal basis to pursue claims. Thirdly and most importantly, we incur actual losses due to the limited liability of our service provider, e.g., the theft of our clients' contact database and its sale to competitors. On the other hand, due to the potential inspection by the Polish DPA, external companies should also ensure that they have such agreements. It will be difficult to answer the Polish DPA inspector's question about the legal basis for processing personal data belonging to another entity…

More
on how to identify data processing entrustment can be found in the article:
"Data Processing Entrustment - What Exactly Is It and When Do We Use It?".

Must There Be an Agreement?

As a rule, a data processing agreement may be a separate contract, but the service provision agreement may also contain provisions regarding the processing of personal data. However, it should be noted that the conditions specified in the Act must be met – the contractual delegation must specify the purpose and scope of the personal data being processed. In a sample IT outsourcing agreement, the purpose will, of course, be the provision of IT services, that is, what the external IT specialist actually does for us. The scope of processing is somewhat more complicated – we must specify the specific sets of personal data that will be processed during the provision of services. In practice, this means that if we omit any purpose or scope of processing in the agreement, those areas will still not be protected, as if there were no agreement at all.

A sample provision regarding the delegation of processing may look as follows:

The Company undertakes to process Personal Data solely to the extent and for the purpose specified in the agreement (…) and in accordance with its provisions, as well as with the provisions of this Agreement and the Personal Data Protection Act, in particular Articles 36-39a, concerning the security of Personal Data, including securing them against disclosure to unauthorized persons, unlawful acquisition by unauthorized persons, processing in violation of the Act, and alteration, loss, damage, or destruction.

DPO Function - it transfers well

Data Security.

Another condition for the delegation of personal data processing is to ensure at least the same level of data security by the external entity as that provided by the delegating entity. Contractual provisions must specify that the data processor acting on our behalf meets the requirements of the Personal Data Protection Act, meaning that it has documentation for personal data protection, has granted authorizations to employees, etc. Creating a personal data protection system can prove to be a costly process and almost always requires experience or assistance from outside. It is worth taking advantage of free software available online, such as ODO Navigator.

Having documentation for personal data protection is, unfortunately, not everything. Often, it is also necessary to additionally purchase IT equipment, software, or shredders. All this is to match the security measures of the other party to the data processing agreement. Sometimes, there is a temptation to contractually declare the possession of security measures, but in practice, fail to meet this requirement. However, it is better not to do this, as the other party to the agreement has the right to audit us. Most often, the data controller's auditor will be the Data Protection Officer (DPO), who will want to ensure that the data under their supervision is indeed adequately secured.

It is worth emphasizing that in the event of, for example, a data breach, both parties (both sides of the data processing agreement) are jointly liable. The data processing agreement does not exempt the "owner" of personal data from the responsibility for their proper protection.

RODO Support
GDPR.
Support is useful
Determine the scope of support yourself to ensure the organization’s full compliance with GDPR at optimal costs.
ORDER OFFER

Data Processing Agreement or so-called NDA.

With whom must we have signed data processing agreements, and with whom are confidentiality clauses sufficient (download the confidentiality agreement template), i.e., a standard NDA (non-disclosure agreement)?

For example, with a cleaning service, we do not need to have a signed data processing agreement, as the services provided do not involve data processing. Nevertheless, cleaning staff may come into possession of personal data, e.g., documents inadvertently left on a desk, and therefore we should secure ourselves with a so-called confidentiality agreement. If we neglect the confidentiality provisions, it may turn out that despite having data processing agreements with other companies, it is precisely the cleaning staff or security guard who will take our client database.

Personal data for sale.

The market for personal data of potential clients is continuously growing. Entities are willing to pay up to 100 PLN for data concerning an individual who is highly likely to purchase a product in a given industry. For this reason, we should particularly safeguard our clients' data, as the risk of its loss is constantly increasing. Data processing agreements or confidentiality agreements provide us with at least a modicum of control over how personal data flows within our entity and beyond.

Check

Template of a data processing agreement compliant with GDPR

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.