RGPD

What the GDPR brings to drafting data processing agreements

The adoption of the General Data Protection Regulation (GDPR) has created additional obligations for processors and controllers, to which data processing agreements must adapt.

Contents
Schedule a discussion

Reading time:

3 min

The adoption of the General Data Protection Regulation (GDPR) has created additional obligations for processors and controllers, to which data processing agreements must adapt.

These new rules have prompted a growing awareness of the responsibilities and obligations relating to data processing, illustrated in particular by the development of standard contractual clauses by processors.

Understanding your role as a GDPR processor

Where one entity handles personal data on behalf of another, it is regarded as a processor under the GDPR. The same applies to "turnkey" solutions that process personal data.

Here, in carrying out its assignments, the web development agency has access to the personal data of the clients of its business clients.

As a result, this IT provider must ensure that it complies with the instructions set by the controller (the business that owns the website or application) and must set out the various obligations incumbent on each of them on the basis of the applicable rules (Articles 4.7, 4.8 and 28.10 of the GDPR).

However, if the processor uses the data from this processing for its own purposes (e.g. customer management, accounting), it is regarded as a controller for that specific processing.

Why is it crucial to have a clear GDPR contract?

The controller and the processor must draw up a contract that includes several mandatory provisions under Article 28 of the GDPR.

The role of a qualified lawyer in this process is to organise the respective obligations of the two parties, to incorporate all the mandatory provisions according to the situation, and to give effect to these obligations.

How to define and frame the data processing?

Your GDPR contract must clearly define the subject matter, duration, nature and purpose of the processing, as well as the categories of data and of data subjects.

Any processing operation not provided for in the contract requires written instructions from the controller or a renegotiation of the contract.

This contract also makes it possible to set out the conditions under which the IT provider may engage other processors.

Ensuring GDPR-compliant processing with the help of a lawyer

Indeed, procedures may be put in place in order to document, make available to the controller at any time documents evidencing compliance with the GDPR, or to ensure that:

  • the processor uses GDPR-compliant tools;
  • technical security is maintained;
  • the processor assists the controller in responding to requests from data subjects to exercise their rights in connection with the collection;
  • the controller's instructions are given in writing;
  • the processor maintains and draws up a record of processing activities on behalf of the controller.

The obligations are numerous and must be complied with by the processor in the course of its activities.

In short, navigating the sometimes murky waters of the GDPR can be complex.

Whether you are a controller or a processor, working with a GDPR lawyer to draft your data processing agreement will secure your operations by enabling you to comply with the rules and protect the personal data you process.

If you have any further questions or need assistance drafting your GDPR data processing agreement, please do not hesitate to contact me.

To learn more

What is a processor within the meaning of the GDPR?

The GDPR defines a processor as any entity that processes personal data on behalf of a controller. A web agency that accesses the data of its clients' customers is a processor. Turnkey solutions that process personal data are too. This status carries its own obligations.

Is a web agency a processor or a controller?

It depends on how the data is used. Where it processes the data according to its client's instructions, the agency is a processor. But if it uses that data for its own purposes (customer management, accounting), it becomes a controller for that specific processing. The classification can therefore vary depending on the operations.

Is a GDPR data processing agreement mandatory?

Yes. Article 28 of the GDPR requires a contract between the controller and the processor, containing mandatory provisions. This contract frames each party's obligations and conditions the compliance of the processing arrangement. Its absence constitutes a breach, exposing both parties to liability in the event of a CNIL audit.

What must a GDPR data processing agreement define?

The contract must define the subject matter, duration, nature and purpose of the processing, as well as the categories of data and of data subjects. Any operation not provided for requires written instructions from the controller or a renegotiation. It also frames the possible engagement of other processors.

What obligations rest on the processor under Article 28?

The processor must act on written instructions, ensure technical security, assist the controller in responding to requests to exercise data subjects' rights, document its compliance, maintain a record on behalf of the controller and use only compliant tools. It must also notify breaches and allow audits.

Can the processor engage another processor?

Yes, but in a controlled manner. The contract must set out the conditions for engaging a sub-processor, which in principle requires the controller's authorisation and the transfer of the same data protection obligations. This processing chain must remain under control in order to preserve overall compliance.

What happens if an operation is not provided for in the contract?

Any processing operation not provided for in the contract requires written instructions from the controller or a renegotiation of the contract. The processor cannot decide alone on new purposes or new uses of the data. This framework protects the controller and strictly delimits the processor's role.

Why have your data processing agreement drafted by a lawyer?

Because Article 28 of the GDPR requires specific provisions and a rigorous organisation of obligations. A lawyer tailors the contract to the actual situation, incorporates all the mandatory provisions and sets up the procedures for evidencing compliance. This secures operations and protects the data processed in the event of an audit.

Still have questions?

Our team is available!

Have a question?

Your information will remain strictly confidential.
Thank you! We will get back to you shortly. If you'd like to speed things up, schedule a time with me directly here:
Schedule a 15-minute call
Oops! Something went wrong while submitting the form.
Homme en costume bleu foncé avec cravate et pochette blanche, bras croisés, regardant vers l'avant.

Ressources

Aller plus loin

00
article(s) affiché(s) sur
00

9 min

Doxing, revenge porn and online harassment: the justice system facing new digital crimes
Doxing, revenge porn and online harassment now constitute serious violations of individuals' privacy and dignity.

7 min

Cloud Computing for SMEs: Benefits and Legal Risks to Know
In an economic environment that demands ever more agility and efficiency, cloud computing has established itself as an essential solution for SMEs. By providing on-demand access to IT resources, this technology profoundly transforms the way companies manage

5 min

How to notify a concentration to the Competition Authority?
Notifying a concentration is a legal obligation that allows the Competition Authority to review the impact of a merger or acquisition on a given market. In France, this procedure aims to prevent abuses of dominant position and to ensure a competitive balance in

11 min

Franchisor vs. Franchisee: how to resolve disputes without going to court?
Franchisor vs. franchisee: moments of harmony and periods of tension. Explore alternative dispute resolution methods.

6 min

Penalty clause: how can the court reduce an excessive amount?
Within contracts, the penalty clause stands out as a key tool for defining the consequences of non-performance. Indeed, this contractual stipulation is essential, as it sets in advance the amount of damages owed in the event of a breach of obligations. However, its implementation

3 min

Source code obsolescence does not justify non-performance of the contract: a key ruling from the Paris Court of Appeal
IT outsourcing (infogérance) is a contract whereby a company entrusts the management of its information system to a specialised service provider.
Book an appointment
Book an appointment📆 15-Min Meeting