Module 3 Flashcards
Controllers and processors
Controller
Article 4(7): ‘the natural or
legal person, public authority,
agency or other body which,
alone or jointly with others,
determines the purposes and
means of the processing of
personal data’
Middelen delegeren mag; doelen stelt
de verantwoordelijke vast
Joint controllers
Where two or more
controllers jointly determine
the purposes and means of
processing, they shall be
joint controllers.
(Article 26)
Processor
Article 4(8): ‘a natural or legal
person, public authority,
agency or other body which
processes personal data on
behalf of the controller’
Processor as controller
If a processor infringes this
Regulation by determining
the purposes and means of
processing, the processor
shall be considered to be a
controller in respect of that
processing (Article 28)
Vendor management
- Choose reliable processors
- Maintain quality control and
compliance throughout the
duration of the arrangements - Frame the relationship in a
contract (or other legally
binding act)
Engaging processors - Precontractual duediligence
- Appropriate technical and organisational measures to secure data
- Processor’s data protection knowledge
- Recent high profile breaches
- Under investigation?
- Accreditation
- Processor’s policy framework
- Sub-processors
Engaging processors - Components of a contract
Article 28
- Subject matter, duration and nature of the data processing
- Types of personal data and categories of data subjects
- Obligations and rights of the controller
- The processor’s responsibilities
Engaging processors - Contractual terms
- Process on documented instructions only
- Ensure confidentiality
- Implement appropriate security
- Get controller’s consent to engage processors
- Assist with data breach notifications
- Delete or return personal data
- Assist the controller in providing for data subject rights
- Demonstrate GDPR compliance
- Contribute to audits, including inspections
Soorten overeenkomst
- Verwerkersovereenkomst (verantwoordelijke en verwerker)
- Subverwerkersovereenkomst (verwerker en subverwerker)
- Data-uitwisselovereenkomst (verantwoordelijke en
verantwoordelijke) - Andere ‘onderlinge regeling’ (zelfstandige
verantwoordelijkheid)
True or false: A data controller
may be a natural person or a
legal entity, while a data
processor must be a legal
entity
False: Verwerker en verantwoordelijke kunnen zowel natuurlijk persoon als rechtspersoon zijn.
True or false: A contract protects a processor from being held to the same legal obligations as the controller.
False
True or false: A processor may decide where and how to process personal data.
False