Due Diligence when Appointing a Data Processor

If you are a controller considering engaging a data processor, you can’t choose the one that suits you best based only on functionality, even if that data processor is selling the perfect product or is offering the perfect deal. If they don’t provide sufficient guarantees to keep the personal data safe and sound, don’t appoint them. 

Why? As a controller, you bear the responsibility not only for your compliance with the GDPR, but also for choosing the processor that will process data on your behalf in a secure and compliant way. For this reason, before you start collaborating with any processor, you need to do thorough due diligence. This article aims to clarify what the due diligence part implicates and what you should look for when you engage a new processor.

First Steps

Before anything else, you need to do a self-assessment and figure out what the nature of the processing will be and what level of risk this processing implicates for data subjects’ rights and freedoms. For example, will vulnerable data subjects data be processed? Vulnerable data subjects refer to people who may be unable to consent or oppose the processing of their data or to exercise their rights.

Good examples of vulnerable data subjects are children, employees, mentally ill individuals and asylum seekers. So, will the processor process special categories of personal data on your behalf? If the answer is yes, you need to be even more careful when choosing the processor and make sure that they have appropriate technical and organisational security measures in place. 

The Process of Appointing a Data Processor

Once this first step is completed, you can start the due diligence process, which is the first stage of processor management. Here is a checklist with the things you need to look out for when engaging a new processor.

The first thing to do is to check the processor’s website. You should read their privacy notice. You may find some positive or some negative indicators. An informative and updated privacy notice can be a positive sign that the processor takes data protection seriously. On the other hand, reading a privacy notice that is mentioning, for example, Privacy Shield as the transfer mechanism, could be a negative indicator. This shows that this processor has not bothered to update its privacy notice for more than a year.

However, that is not all. A GDPR Questionnaire should be sent and you must establish whether the processor is actually complying with the regulation. If you cannot satisfy yourself that they are then you can ask us to carry out a Data Protection Audit. We can then report back as to the potential processor’s status. We will confirm the following:

Does this Data Processor have technical security measures in place?

The processor must provide sufficient guarantees that they have technical measures in place. These measures must ensure the security of the personal data. For example, are they using encryption or pseudonymisation for the protection of the data? Do they run regular full back-ups? Do they update software regularly?

Does this processor have organisational security measures in place, including relevant data protection documentation?

A processor needs to have a Record of Processing Activities. This can never be a template and must be refer to the processing activities of the processor. It is a legal requirement. Despite that, the processor shall apply appropriate organisational measures. These will include internal data protection and information security policies and data breach and incident planning. Data Protection Impact Assessments must be in place to ensure the security of the personal data they will process on your behalf. 

The provision of such documentation will enable you to make a more informed decision. Most processors have all the relevant documentation ready for the prospective controllers to examine. However, you should check they are not templates which are of no use to them or to you. You should read all of them to ensure they are fair and don’t unfairly benefit them commercially. You may be asked to sign a non-disclosure agreement (NDA) with the processor before they disclose such documentation to you.

Has this processor appointed a Data Protection Officer or another data protection contact person?

A Data Protection Officer (DPO) is an independent data protection professional who helps an organisation to manage its privacy issues. According to the GDPR, in some cases, the appointment of a DPO is obligatory. In this case, your processor is legally required to appoint a DPO. They may have not yet fulfilled this obligation yet. It is a very good indicator that it is not taking compliance with the GDPR seriously. Any appointed DPO cannot be a director or shareholder of the processor’s company. If the processor has appointed a DPO voluntarily, despite not having such an obligation, it can be a very positive sign for its respect for data protection. 

If there is no legal obligation to appoint a DPO for this specific processor, a responsible person should be appointed. You should check whether they have an individual responsible for data protection matters. This person should be contactable and their details available to all.

Are relevant staff of the processor subject to confidentiality obligations?

You will require the processor to ensure that anyone it authorises to process the personal data is subject to a strict duty of confidentiality. They must confirm that they can only process the data in accordance with the permitted purpose agreed. Therefore, before engaging a new processor you could check if there is a confidentiality clause in the employment contract.

Does the processor hold any information security certifications?

Information security certifications are important. ISO 27001 is the holy grail of ISMS. Cyber Essentials and Cyber Essential Plus are also very good. Keep an eye out for the IAMSE Gold Standard also.

Has this processor suffered any data breaches in the last year? 

This is very important. If the processor is compliant, you can simply ask for their data breach register. The recording of data breaches is part of the accountability principle that came in with the Data Protection Act 2018. Be wary of businesses that have not had any sort of data breach. A data breach is not necessarily a bad thing. It is the response to it and the remediation that matters. Proof should be provided and you should be satisfied that these measures were appropriate and effective.

Will the processor allow the controller to conduct audits?

You have to monitor the activities of the processor throughout the whole lifecycle of your cooperation. For this reason, it is important to choose processors willing to go through regular audits to ensure compliance with contractual obligations.

Some processors offer as part of the deal to hire an external auditor to conduct audits at specific intervals and then provide the controller with a written report of the results. Others may allow the controller to conduct onsite audits on its own. Therefore, you need to examine what this processor suggests and see if it is convenient for you.

Will the processor be transferring the data to countries outside of the European Economic Area (EEA)?

You need to examine whether by choosing this processor, you will be transferring the data outside of the EEA. If yes, you must consider whether or not you can find a legal transfer mechanism for the data processing activities that will be undertaken outside of the EEA. As a controller, it is up to you to ensure that you put in place an appropriate transfer mechanism to ensure the rights and freedoms of data subjects remain protected. Often this will be through an EU standard contractual clause agreement.

On the same note, you have to check whether the processor will be transferring the data outside of the EEA by using any sub-processors. In the first instance, you need to ask the prospect processor to provide you with a list of any sub-processors they will use for the processing of the data that you will provide them with. Second, if this list contains sub-processors established outside of the EEA, you also have to look for an appropriate transfer mechanism.

Need some help?

Does this all sound a bit much? If you think it is, you are not alone. We help many businesses who are unsure of what technical measures are and how to implement them. Don’t forget that this is not just an IT problem.

We can carry out a technical measures audit to help you understand your current status. In the first instance, you can book your audit. Alternatively you call us on 03333 22 1011 or contact us.

Why Education Establishments Need Data Protection Officers

The ICO announced this week that a former headteacher has been fined over £1000 by a magistrate’s court for unlawfully obtaining children’s personal data from previous schools where he had been employed.

Darren Harrison took the information from two primary schools where he had been employed and then transferred it to the computer system at his new school. As he had no lawful reason to do such data processing, he was found to be in breach of the data protection legislation.

Six months into his role as Deputy Head at Isleworth Town Primary School, Harrison was suspended. A subsequent IT audit showed large volumes of sensitive personal data present on the Isleworth server from his previous schools, Spelthorne Primary and The Russell School in Richmond.

During the course of the investigation, Harrison provided no valid explanation as to how the information had appeared on his system, which was via an upload from his USB stick, stating he had deleted the personal data from it.

In a subsequent interview with the Information Commissioner’s Office (ICO), Harrison read from a prepared statement advising that the information had been taken for professional purposes.

Appearing before Ealing Magistrates’ Court, Harrison admitted two offences of unlawfully obtaining personal data in breach of s55 of the Data Protection Act 1998.

He was fined, and with additional costs including a victim surcharge and court costs, this totalled over £1000 

In another incident, The University of Greenwich was fined £120,000 by the Information Commissioner following a “serious” security breach involving the personal data of nearly 20,000 people.

The personal data included contact details of 19,500 people including students, staff and alumni such as names, addresses and telephone numbers. However, around 3,500 of these included sensitive data such as information on extenuating circumstances, details of learning difficulties and staff sickness records. This was subsequently posted online.

This was caused by a microsite created on the University infrastructure, created by an academic with the University’s consent to facilitate a training conference as long ago as 2004. The site had an anonymous upload function to allow delegates to upload conference papers. Following the conference, this was not removed or disabled and it didn’t receive regular security updates. In 2013, it became apparent that the site had been compromised.

In mid January 2016, hackers exploited this microsite using SQL injection to gain access to an account with sufficient permissions to upload PHP exploits. These exploits in turn allowed the attackers to gain access to other databases hosted on the web server. The attacker then extracted the data.

The case of Harrison is symptomatic of careless IT and lack of care with regards to personal data. We have always recommended not using portable storage devices for reasons like the Harrison case but also for cyber hygiene. He took large amounts of data and admitted taking it for ‘professional reasons’ and that he had no right to process the data. For the latter, he was in breach of the DPA. Not only did he face a fine and costs, he also lost his job!

A representative of the ICO said that: “they (the ICO) will continue to take action against those who they find have abused their position of trust.”

What could the three schools have done to prevent this happening?

  • Ban and block the use of USB storage devices to prevent anything being saved to them.
  • Cloud services where documents are accessed and worked on ‘in the cloud’ with download functions turned off.
  • Carry out data discovery to understand where data is being stored and by whom.
  • Put in place an ‘Acceptable Use Policy’ to make the use of USB storage a disciplinary matter.
  • Create a security culture to encourage staff to discourage bad practices and behaviours.

How could the University have prevented their incident?

  • Conducting an exercise to understand exactly what was on their network. This would have revealed the presence of more than one microsite that were simply not needed.
  • An audit to show risk of where student and other personal data was stored would have revealed how easily a theft could take place.
  • Understanding the age of the data and why it was stored might have reduced the impact. If this data, or some of it, was historic and not required, then surely it would have been worth deleting and therefore reducing the size and impact of the breach.

So, why do educational establishments need a Data Protection Officer?

  • A good DPO is truly independent. An external DPO is even better
  • To data map and discover data silos
  • Understand the flow of data around the establishment
  • Audit systems, users and their behaviours
  • Record data breaches and report where appropriate
  • Handle DSARs in a compliant manner and record all requests and outcomes
  • Ensure that the supply chain is compliant and monitor this
  • Help create a GDPR culture and train all the people in the school

If you would like to know more about our DPO as a Service for schools and colleges, please get in touch on 03333 22 1011 or email [email protected].

GDPR Data protection