Data Processing Agreements Flashcards

1
Q

What must the agreement contain?

A

Article 28(3)

(a) Processing only on documented instructions from controller
(b) Confidentiality
(c) Technical and organisational measures regarding security
(d) Sub-processors (only engage after consent + initial processor fully liable)
(e) Assist controller in regards to data subject’s rights
(f) Assist controller in compliance regarding security, notification and DPIA
(g) Processor must delete or return and delete existing copies after the end of the provision of services
(h) Make available to C all information necessary to demonstrate compliance and allow for and contribute to audits and inspections.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How is liability delegated?

A

Article 82
Both C and DP are fully liable for any compensation due to infringements of provisions of GDPR and damage suffered (both material and non-material).

Article 28(4) 
In case of a sub-processor, the initial processor is fully liable for this other processors fails to fulfil its obligations.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Is there any formal requirements to a processing agreement?

A
Article 28(9)
Agreement must be written, including in electronic form.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly