Why businesses need Data Processing Agreement (DPA)? It’s practically not possible to run a business without processing personal data and exchanging it with other businesses. It may be website analytics software, cloud storage, CRM or marketing platform, and whether you are controller, processor, sub-processor or joint controller, you have to construct a lawful Data Processing Arrangement with the party you exchange personal information.
GDPR does not have legal restrictions on the form of the Data Processing Agreement, however, if processor is located outside EU and international data transfer happens, there are some specific requiremens to the format of documentation, for example standard contractual clauses, coprorate binding rules., etc.
Considering the complexity of the task, it’s advisable to have a data processing agreement as a separate document.
Do I need to have a Data Processing Agreement?
If you exchange personal data with other parties, you should have a Data Processing Agreement in place. Articles 28 through 36 of the GDPR cover the requirements for data processing and data processing agreements. Let’s have a look at a bit more specific responsibilities of different roles.
The data processor should handle the data exclusively in the manner demanded by the controller. Processor must have adequate information security in place, shouldn’t use sub-processors without the knowledge and consent of the controller, must cooperate with the authorities in the event of an enquiry, must report data breaches to the controller as soon as they become aware of them, must give the data controller the opportunity to carry out audits examining their GDPR compliance, must help the controller to comply with data subjects’ rights, must assist the data controller in managing the consequences of data breaches, must delete or return all personal data at the end of the contract at the choice of the controller, and must inform the controller if the processing instructions infringe GDPR.
What should be included in a data processing agreement?
Articles 28 through 36 of GDPR set conditions of data exchange and conditions of personal data between controller and processors. Here are the most important subjects you have to cover in your data processing agreement.
Details about processing
- the subject matter and duration of the processing;
- the nature and purpose of the processing;
- the type of personal data and categories of data subject;
- purpose and legal basis of personal data processing;
- the controller’s and processor’s rights and responsibilities.
Minimum required terms
The processor must act in accordance with written instructions of the controller
The agreement must say that the processor may only process personal data in line with the controller’s documented instructions (including when making an international transfer of personal data) unless it is required to do otherwise by EU or member state law.
An instruction can be documented by using any written form, including email. The instruction must be in a reproducible form, so that there is a record of the instruction.
This contract term should make it clear that it is the controller, rather than the processor, that has overall control of what happens to the personal data.
If a processor acts outside of the controller’s instructions in such a way that it decides the purpose and means of processing, then it will be considered to be a controller in respect of that processing and will have the same liability as a controller.
Confidentiality of processed personal data
The agreement has to say that the processor must obtain a commitment of confidentiality from anyone it allows to process the personal data, unless that person is already under such a duty by statute.
This contract term should cover the processor’s employees as well as any temporary workers and third-party workers who have access to the personal data.
Obligation to have adequate information security in place, technical and organisational measures to be met
The agreement has to oblige the processor to take all security measures necessary to meet the requirements on the security of processing (see Article 32).
Both controllers and processors are obliged to put in place appropriate technical and organisational measures to ensure the security of any personal data they process which may include, as appropriate:
- encryption and pseudonymisation;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to restore access to personal data in the event of an incident; and
- processes for regularly testing and assessing the effectiveness of the measures.
Codes of conduct and certification may help processors to demonstrate sufficient guarantees that their processing will comply with the GDPR.
The requirement to use sub-processors only with the data controller’s knowledge and consent
The agreement must say that:
- the processor should not engage a sub-processor without the controller’s prior specific or general written authorisation;
- if a sub-processor is employed under the controller’s general written authorisation, the processor should let the controller know of any intended changes and give the controller a chance to object to them;
- if the processor employs a sub-processor, it must put a contract in place imposing the same data protection obligations on that sub-processor;
- the processor is liable to the controller for a sub-processor’s compliance with its data protection obligations.
Cooperation of processor for the purpose of resolving subject access requests
The agreement has to provide for the processor to take appropriate technical and organisational measures to help the controller respond to requests from individuals to exercise their rights.
Cooperation of processor for the purpose of protecting the rights and privacy of data subjects
The agreement has to say that, taking into account the nature of the processing and the information available, the processor must assist the controller in meeting its obligations to:
- keep personal data secure;
- notify personal data breaches to the supervisory authority;
- notify personal data breaches to data subjects;
- carry out data protection impact assessments (DPIAs) when required; and
- consult the supervisory authority where a DPIA indicates there is a high risk that cannot be mitigated.
The agreement should be as clear as possible about how the processor will help the controller meet its obligations.
Duration of the processing and returning and/or deletion of personal data
The agreement has to say that at the end of the contract the processor must:
- at the controller’s choice, delete or return to the controller all the personal data it has been processing for it; and
- delete existing copies of the personal data unless EU or Member State law requires it to be stored.
It should be noted that deletion of personal data should be done in a secure manner, in accordance with the security requirements of Article 32.
The agreement has to include these terms to ensure the continuing protection of the personal data after the contract ends. This reflects the fact that it is ultimately for the controller to decide what should happen to the personal data being processed, once processing is complete.
The processor should allow the data controller to carry out audits examining their compliance
Under Article 28(3)(h) the agreement has to require:
- the processor to provide the controller with all the information that is needed to show that the obligations of Article 28 have been met; and
- the processor to allow for, and contribute to, audits and inspections carried out by the controller, or by an auditor appointed by the controller.
This provision obliges the processor to be able to demonstrate compliance with the whole of Article 28 to the controller. For instance, the processor could do this by giving the controller the necessary information or by submitting to an audit or inspection.
Keeping records of the processing activities would be useful for the processor to demonstrate compliance with Article 28. Requirements for processors to maintain records of their processing activities are set out in Article 30(2).
If required by GDPR, the data processor shall appoint a Data Protection Officer and both parties must agree on periodic review of terms of the agreement.