GDPR questions and answers

GDPR: QUESTIONS AND ANSWERS

Category:
DPO Challenges

Should a data processing agreement be concluded with a training company when real personal data processed by the controller is made available to the trainer for employee training?

ANSWER

In the described situation, a data processing agreement should be concluded, because the trainer will have access to personal data processed by the controller, and the concept of processing includes viewing, organising, using, and similar activities.

Who the agreement should be concluded with will depend on whether the person delivering the training is an employee of the training company. If so, a data processing agreement should be concluded with the training company. The processing agreement should include, on the processor's side, an obligation to obtain from its employee a commitment to keep confidential the personal data disclosed to them under that agreement.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.
DPA with training company when using real personal data? | ODO 24 | ODO 24