In the realm of data processing, particularly when dealing with personal data, law firms often outsource specific tasks to specialised service providers, known as 'processors.' These processors handle data on behalf of the firms (controllers) and are granted access under strict conditions. This relationship is governed by Article 28 of the General Data Protection Regulation (GDPR), which sets the legal framework for such collaborations, encompassing everything from the selection of processors (vendor assessment) to the establishment of a data processing agreement (DPA).
This guide will provide insights into selecting a processor and the essential elements of a data processing agreement, ensuring the protection of data subject rights and GDPR compliance.
Roles of the Parties Involved
In a data processing context, two main roles exist:
- Controller: The entity (natural or legal person) determines the purposes and means of processing personal data.
- Processor: The entity that processes personal data on behalf of the controller, excluding controller employees.
Vendor Assessments: Key Considerations
As Article 28 of the GDPR outlines, law firms must be meticulous in selecting processors. The controller should choose processors capable of implementing necessary technical and organisational measures for GDPR compliance. This is where vendor assessments come into play.
Ensuring Sufficient Guarantees
Controllers must evaluate processors based on their knowledge, reliability, and resources during vendor assessment. This includes reviewing the processor’s privacy and security policies, terms of service, records of processing activities, and external audit reports. Checking for recognised certifications, like the ISO 27000 series is also advisable. The processor’s reputation in the market is another critical factor to consider.
Pre-Contractual Due Diligence
Before finalising a processor, controllers should request detailed information, including:
-
Security and privacy policies.
-
Details on international data transfers, if applicable.
-
A list of technical and organisational measures taken to protect personal data.
When data processing poses significant risks, it is prudent to request audit reports or conduct a new audit and review the processor's Data Breach Registry to ensure they haven’t been involved in substantial data breaches.
Validating the Data Processing Agreement
Under Article 28 of the GDPR, a written contract or another legally binding act based on EU or Member State law is mandatory for data processing activities. This contract must be documented, including in electronic formats. Controllers are advised to draft their DPAs whenever possible or thoroughly review and negotiate the processor's provided templates to ensure GDPR compliance.
Essential Clauses in a Data Processing Agreement
A valid DPA should minimally include:
-
The subject matter, duration, nature, and purpose of processing, the type of personal data and categories of data subjects.
-
Clauses ensure the processor only processes data on documented instructions from the controller.
-
Requirements for confidentiality agreements for persons authorised to process the data.
-
Obligations for implementing appropriate technical and organisational measures, as detailed in Article 32 GDPR, to maintain a suitable level of security based on the processing risks.
Handling Sub-Processors
Processors must obtain specific or general authorisation from controllers to engage subprocessors. If general authorisation is granted, the processor must inform the controller of any changes to subprocessors, allowing the controller to object. Subprocessors must adhere to the same data protection obligations as the central processor.
Assisting the Controller
Processors are also required to assist controllers in responding to data subject requests, managing data breaches, and conducting Data Protection Impact Assessments (DPIAs) when necessary. Upon completing the processing tasks, they must return or delete all personal data unless EU or Member State law requires retention.
Vendor Assessment for Processors Outside the EEA
Controllers should ideally choose processors within the European Economic Area (EEA) to benefit from established data protection standards. However, suppose processors are used outside the EEA. In that case, it's crucial to evaluate the data protection standards in those countries and consider implementing safeguards like Standard Contractual Clauses (SCC) if the government needs an adequate decision from the European Commission.
Processor Accountability
If a processor exceeds its role and determines the purposes and means of data processing, it becomes a controller and assumes all corresponding responsibilities under the GDPR, including breach notifications and DPIAs.
Post-Contractual Due Diligence
Controllers must continuously monitor the processor's compliance throughout the duration of the contract. The level of scrutiny depends on the risk associated with the data processing activities. Reviewing security documents may suffice for low-risk scenarios, while medium-risk situations may require audits, and high-risk activities necessitate periodic compliance assessments.
Conclusion
Evaluating a data processor's expertise and ensuring the validity of a data processing agreement are crucial steps in securing outsourced data processing activities. A rigorous assessment of the vendor's technical capabilities, compliance with data protection laws, and risk management are essential to building a trustworthy controller-processor relationship. Ongoing monitoring and reassessment help maintain a robust data protection framework, ensuring data integrity and stakeholder trust.

