
First, we must recognize the purpose for which the data controller enters into a data processing agreement with the data processor, and then indicate the grounds on which the processor gains access to this data. Importantly, according to Article 4(8) and Article 28(3)(a) of the GDPR, processing may only take place on the documented instruction of the data controller through the conclusion of a data processing agreement (under Article 28(3) of the GDPR, it is also permissible to entrust data processing in the form of another legal instrument subject to EU law or the law of a Member State).
This means that the processing of data belonging to a specific catalog indicated by the data controller, for a clearly defined purpose, is possible only after fulfilling the conditions specified in the GDPR, such as defining the subject and duration of processing, its nature and purpose, as well as the type of personal data and categories of individuals whose data is being collected. After these conditions are met and the agreement is signed by both parties (the processor and the data controller), the data is entrusted – and at that point, the processor processes it according to the terms specified in the agreement. In practice, the data controller most often enters into a data processing agreement when utilizing the services of an external entity (outsourcing).
The Need for Reuse of Data – Position of the Supervisory Authority
At this point, we arrive at the key issue of what to do when, after the termination of the data processing agreement, the processor approaches the data controller with a request to continue processing the data received under the same data processing agreement. The necessity for further processing of data by the entity acting as the former processor may be justified by a business need, based for example on the necessity to use the data for market needs analysis to improve the quality of services provided or to create new products based on previously obtained data.
Regarding the permissibility of the processor's reuse of data, the French supervisory authority (CNIL) has expressed its opinion. It emphasized that the processor may use the collected personal data in its own name, provided that such reuse is consistent with the original purpose of processing (as defined in the data processing agreement) and that the data controller grants written consent to this entity.
The data processor that wishes to reuse the data must report this need to the data controller, as it cannot independently process the data again (unless such an obligation is imposed by EU law or the law of the member state to which it is subject, or if it has the explicit consent of the data subject). This action is necessary, as otherwise the processor would not only violate the provisions of the GDPR but would also be subject to the sanctions provided for in the original data processing agreement.
Necessary Compliance Test
As indicated by CNIL, when the purpose of processing differs from the purpose originally specified in the agreement with the data controller, it is necessary to conduct a compatibility test. Such a test allows for the assessment of whether the entity can continue to use the collected data, even though the original purpose for which the data was collected was different. The compatibility test is conducted based on criteria such as:
- the existence of a connection between the purposes for which the data was collected and the purposes for which the data is now to be processed,
- the assessment of the context in which the data was collected - this concerns the evaluation of the difference in purpose for which the data was originally collected and the purpose of the controller regarding its reuse,
- the assessment of the nature of the personal data – special attention should be paid to special categories of data (whether the processing concerns sensitive data),
- the analysis of foreseeable consequences of further processing for the data subjects,
- the analysis of the safeguards applied (such as encryption and pseudonymization).
If the controller and processor determine that there is compatibility allowing for the conclusion that the purpose of the new processing will at least remain consistent with the original purpose of the controller, then the reuse of the data will be permissible. It should be noted that the controller's consent must be in written or electronic form.
As an example of the reuse of personal data (preceded by a compatibility test), CNIL pointed to the enhancement of cloud data processing services. In its view, this situation can be considered processing that is consistent with the original purpose of processing.
And what should be done if the test does not demonstrate the required compatibility? The answer to this question is unequivocal. In such a situation, the controller will not be able to grant the entity consent for the reuse of the data.
Fulfillment of Information Obligations Arising from the GDPR
If the processor remains compliant with the original purpose of processing and has obtained the data controller's consent for the reuse of the data, can it proceed with the intended purposes? Unfortunately, no. It is necessary to remember the obligations set forth in the GDPR, including the requirement to fulfill the information obligation. We arrive at a very interesting situation where the previous processor becomes a new data controller (as the data will be processed for a new purpose). Therefore, the "new controller" must fulfill all obligations towards the data subjects (Article 12 – 23 GDPR).
It is worth emphasizing that the previous data controller will also be obliged to fulfill the information obligation towards the data subjects regarding the transfer of data to the new controller for the new purpose. In particular, the CNIL indicated that these individuals should be informed of their right to object (Article 21 GDPR).
According to the current legal status, the new data controller will additionally have to carry out a number of activities related to ensuring compliance of the processing for the selected process. This primarily involves ensuring all security measures, conducting a risk analysis, identifying potential threats to data security, as well as identifying and verifying the circle of recipients of personal data. This means that it will be necessary to fulfill the obligations from Article 24 GDPR, such as implementing appropriate technical
and organizational measures to ensure compliance of data processing, implementing appropriate data protection policies, or applying approved codes of conduct, if an approved code of conduct is applicable to the given process.
Compliance of data processing with the interests of the controller
We already know what conditions must be met by the entity to be able to reuse data entrusted by the controller for its own purposes – assuming that such processing will be legally permissible due to the application of appropriate technical and organizational measures. However, it is also important to consider one more extremely significant issue, which is the compliance of processing with the interests of the controller.
If we do not receive consent for processing ordinary personal data directly from the data subject, the legal basis for their processing will typically be Article 6(1)(f) of the GDPR, which refers to the legitimate interest of the data controller. It is widely accepted that the application of this basis is quite broad, and the doctrine allows for a flexible interpretation of its scope. However, it should be noted that a data controller wishing to process data based on Article 6(1)(f) of the GDPR must verify their legal interest, for instance, by conducting a so-called legitimate interest assessment (LIA). In practice, this means that the legal interest of the data controller must, in every case, comply with generally applicable legal provisions. It is worth emphasizing that the legitimate interest of the data controller does not have to arise from a specific legal provision. It will be sufficient for the data controller to demonstrate that their legal interest is related, for example, to an economic interest.
In relation to the case we are discussing, the data processor, after conducting a compliance assessment and ensuring that it can implement appropriate technical and organizational measures, should focus on the key issue – the legal basis for data processing. This can be determined, for instance, using the aforementioned legitimate interest assessment (LIA). A positive outcome of the LIA will help exclude situations where this basis for processing is abused. In other words, conducting the LIA will allow a potential data controller to verify whether the processing of personal data is truly necessary to achieve their legitimate interests.
Summary
The reuse of data by a data processor is a sufficiently complex issue that requires thorough analysis in light of the regulations provided by the GDPR. A processor notifying the data controller of the need to use the received personal data for a purpose other than that for which the data was originally collected will have to undertake numerous actions to identify the grounds for the permissibility of such reuse of data. It is necessary not only to confirm a positive outcome of the compliance test and obtain the data controller's consent for the use of the data but also to implement appropriate technical and organizational measures and – if the data will be processed based on Article 6(1)(f) of the GDPR – to conduct a legitimate interest assessment (LIA). Importantly, the previous processor will then become a separate data controller. It should be noted that data administration is associated with the fulfillment of a number of obligations provided by the GDPR. In situations where data is reused, it is also necessary to fulfill the information obligation towards the individuals whose data is being processed.



