Data Processing Agreements and Why You Need Them

Whenever a data controller uses a data processor, there must be a written contract in place. The contract is important so that both parties understand their responsibilities and liabilities. Such a contract is better known as a Data Processing Agreement.

Data processing Agreement

The UK GDPR sets out what needs to be included in a Data Processing Agreement.

If a processor uses another organisation (i.e. a sub-processor) to assist in its processing of personal data for a controller, it needs to have a written contract in place with that sub-processor also. However, permission is needed from the Controller for such an appointment. Any appointment of a sub-processor without permission would be a breach of contract.

So, what does a Data Processing Agreement deliver?

A correct and well-written agreement will state how and what data is to be processed. It will state for how long and much more. Here is a useful checklist:

  • The subject matter of the processing
  • The duration of the processing
  • The nature and purpose of the processing
  • The type of personal data involved
  • The categories of data subject
  • The controller’s obligations and rights

The Data Processing Agreement, which is a contract, will include terms stating that:

  • the processor must only act on the controller’s documented instructions, unless required by law to act without such instructions;
  • processors must ensure that people processing the data are subject to a duty of confidence;
  • the processor must take appropriate measures to ensure the security of processing;
  • a processor must only engage a sub-processor with the controller’s prior authorisation and under a written contract;
  • the processor must take appropriate measures to help the controller respond to requests from individuals to exercise their rights;
  • taking into account the nature of processing and the information available, the processor must assist the controller in meeting its UK GDPR obligations. This is in relation to the security of processing as well as the notification of personal data breaches and data protection impact assessments;
  • a processor must delete or return all personal data to the controller (at the controller’s choice) at the end of the contract. The processor must also delete existing personal data unless the law requires its storage; and
  • the processor must submit to audits and inspections. The processor must also give the controller whatever information it needs. This is to ensure they are both meeting their Article 28 obligations.

What responsibilities and liabilities do processors have in their own right?

In addition to its contractual obligations to the controller, a processor has some direct responsibilities under the UK GDPR. Should a processor fails to meet its obligations, it may be liable to pay damages. This might be in legal proceedings or perhaps subject to fines or other penalties or corrective measures. This also applies if the processor acts outside or against the controller’s instructions.

A processor may not engage a sub-processor’s services without the controller’s prior specific or general written authorisation. Once authorised, the processor must put in place a contract with the sub-processor. The terms of the contract that relate to Article 28(3) must offer an equivalent level of protection for the personal data as those in the contract between the controller and processor. Processors remain liable to the controller for the compliance of any sub-processors they engage.

The Bottom Line

We hear too many tales of a relationship with a processor ending badly and the processor deleting your data. This is quite common, sadly. However, your Data Processing Agreement MUST dictate what happens to your data at the end of the agreement, or contract. The agreement will ensure that data is returned or deleted. This action will be recorded in line with the regulation.

However, be careful; a contract must end amicably with all invoices paid so that the processor cannot use your data as a lever to gain payment. The rules of the contract will protect the data primarily as well as the controller. Therefore, processors are not be allowed to simply delete data because a commercial agreement has ended. This is also the case in the event of a dispute.

Do you have this part of your GDPR covered? 

If you are a Data Controller and use Data Processors you must provide processors with a Data Processing Agreement. Have you established whether you are a Data Controller or a Processor? However, you might be a Joint Controller. In which case you will need a different type of agreement. If you are using processors you do need a Data Processing Agreement.

It is important that you establish your situation in relation to the data you process.

Why not book a free call today?

We can then guide you as to your next steps. There is no obligation or fees for our initial advice.