Module 3: Controllers & Processors Flashcards
What is a data subject?
An individual about whom information is being processed.
What is a controller?
An organisation or individual with the authority to decide how and why personal data about subjects is to be processed.
How does GDPR define a data controller?
Article 4(7) - natural or legal person, public authority, agency or other body which alone or jointly with others determined the purposes and means of processing of personal data”
When might two organisations be considered joint controllers?
When both jointly determine the purposes and means for processing a data set.
Under Article 26, what are the obligations for joint controllers?
To determine their respective responsibilities for compliance with the obligations under GDPR in a compliant manner - e.g. data subject rights, DSARs, contact points and making the essence of their arrangement available to data subjects
Irrespective of the terms of the arrangement between joint controllers, data subjects can…
Exercise their data rights against either controller.
An example of joint controllers.
A travel agency sharing data with airlines and hotels; each controller is responsible for its own processing.
- Two controllers sharing a black list
- Fincrime / police
What is a processor?
An org or individual that processes data on behalf of the data controller (Article 4(8))
Under Article 29, what does a processor do?
Processes on written instruction only.
Under Article 28, what does a processor do?
Provides a service to the controller and assists and informs them of any GDPR infringement.
Under Article 28, what does a processor have the obligation to do?
Protect personal data and ensure confidentiality and appropriate technical and organisational measures are in place.
Under Article 30, what must a processor do?
Demonstrate compliance by keeping a record of processing activities on all categories of personal data processing being carried out on behalf of the controller. It has enhanced obligations under GDPR.
Under Article 28, if a processor infringed on the regulation by determining the purposes and means of the processing, the processor will…
Be considered a controller in respect of that processing.
In relation to processors, an organisation should…
- Choose reliable processors
- Maintain quality control and compliance throughout the duration of the arrangement
- Frame the relationship in a contract or legally binding act
- Do due diligence to check that the processor has appropriate technical and organisational measures to secure data, and a good knowledge of data protection, before signing any contract.
What should a controller check about a processor before entering a contract, aside from due diligence?
Whether they are under investigation, have any high profile recent breaches, their accreditations, policy frameworks and any sub processors