SlideShare una empresa de Scribd logo
1 de 5
Descargar para leer sin conexión
info@caneghem.be +32 495 58 54 45	
Scheme for the amendment or drafting of
processing contracts to comply with the
General Data Protection Regulation (GDPR)
November 2017
info@caneghem.be +32 495 58 54 45	
The General Data Protection Regulation of April 27, 2016, requires a written
processing contract (or other legal act) between data controllers and data
processors.
The GDPR also regulates the minimum content of the processing contracts.
Below follows an overview of the requirements of the GDPR for the content of
the processing contracts with a reference to the specific provisions of the
regulation and a suggested practical drafting approach.
	
	
	
Article		
	
Text of the GDPR article and a recommended drafting approach
28.1		 «The	controller	shall	use	only	processors	providing	sufficient	guarantees	to	implement	
appropriate	technical	and	organisational	measures	in	such	a	manner	that	processing	will	
meet	the	requirements	of	this	Regulation	and	ensure	the	protection	of	the	rights	of	the	
data	subject.»	
	
	 " Document the technical and organizational capabilities of the Processor, either
through referring to a standard obtained by processor (è art. 28.5: adherence to an
approved code of conduct or an approved certification mechanism may be used to
demonstrate sufficient guarantees) or to a schedule that documents those
capabilities.
" Make the maintenance of these standards a condition for the (continuation) of the
contract.
28.2	 «The processor shall not engage another processor without prior specific or general
written authorisation of the controller. In the case of general written authorisation, the
processor shall inform the controller of any intended changes concerning the addition or
replacement of other processors, thereby giving the controller the opportunity to object to
such changes.»
	
	 " Provide a general written authorization in the contract and specify that processor will
need to inform controller of any changes in sub-processors to which controller will
have the opportunity to object;
" alternatively, provide that a specific authorisation will be needed.
28.3		 «Processing by a processor shall be governed by a contract or other legal act under
Union or Member State law, that is binding on the processor with regard to the controller
and that sets out the subject-matter and duration of the processing, the nature and
purpose of the processing, the type of personal data and categories of data subjects and
the obligations and rights of the controller.»
info@caneghem.be +32 495 58 54 45	
	 " Provide a reference to a schedule that contains (a) the subject matter of the
processing; (b) the nature and the purpose of the processing; (c) the type of personal
data and categories of data subjects.
" Prepare and attach the schedule;
" Reserve to the controller the right to change the schedule within certain conditions
or/and spell out the consequences if parties do not agree on changes to the
schedule.
" Specify the obligations and rights of the controller in the contract.
" Insert a clause that sets the duration;
" Insert a clause that spells out the termination rights and conditions and the
consequences of termination.
28.3	
(a)	
«That contract or other legal act shall stipulate, in particular, that the processor:
(a) processes the personal data only on documented instructions from the controller,
including with regard to transfers of personal data to a third country or an international
organization, unless required to do so by Union or Member State law to which the
processor is subject; and that, in such a case, the processor shall inform the controller of
that legal requirement before processing, unless that law prohibits such information on
important grounds of public interest»
	
	 " Insert a clause to that borrows the language of art. 28.3 (a).
28.3	
(b)	
«That contract or other legal act shall stipulate, in particular, that the processor: (b)
ensures that persons authorised to process the personal data have committed
themselves to confidentiality or are under an appropriate statutory obligation of
confidentiality»
	 " Provide a default confidentiality clause or standard in the contract to be used by the
processor in the relation with its personnel or contractors and/or make a reference
to the applicable appropriate statutory obligation of confidentiality.
28.3	
(c)	
« That contract or other legal act shall stipulate, in particular, that the processor: (c) takes
all measures required pursuant to Article 32*»	
	
	 " List the measures of art. 32 that are deemed appropriate either in the contract or in a
schedule to the contract (see: * below).
" List the measures of art. 32 that are not deemed appropriate and document why.
This documentation is to be included in a schedule to the contract and in the
compliance documentation of each party.
" Insert a clause in the contract that provides for flexibility in case of changing
circumstances.»
28.3	
(d)	
« That contract or other legal act shall stipulate, in particular, that the processor: (d)
respects the conditions referred to in paragraphs 2 and 4 for engaging another
processor»	
	 " Provide that the processor shall respect the conditions of 28.2 and of 28.4 for
appointing a sub-processor.
" Provide that the processor shall pass on all its obligations to a sub-processor, in
particular the obligations to take appropriate technical and organisational measures
so that processing meets the requirements of the Regulation and ensures the
info@caneghem.be +32 495 58 54 45	
protection of the rights of the data subject (art. 28.1) and the obligations from the
article 28.3, while remaining liable for the sub-processor.
28.3	
(e)	
«That contract or other legal act shall stipulate, in particular, that the processor: (e)
taking into account the nature of the processing, assists the controller with appropriate
technical and organisational measures, insofar as this is possible, for the fulfilment of the
controller's obligation to respond to requests for exercising the data subject's rights laid
down in Chapter III»		
	
	 " Specify this obligation in the contract, if possible at a reasonable level of practical
detail.
28.3	
(f)	
« That contract or other legal act shall stipulate, in particular, that the processor: (f)
assists the controller in ensuring compliance with the obligations pursuant to articles 32
to 36 taking into account the nature of processing and the information available to the
processor»		
	
	 Provide	sections	in	the	contract	that	oblige	the	processor	to	assist	controller:		
" in	keeping	personal	data	secure	(art.	32);	
" in	notifying	personal	data	breaches	to	the	supervisory	authority	(art.	33);		
" in	advising	data	subjects	when	there	has	been	a	personal	data	breach	(art.	34);		
" in	carrying	out	data	protection	impact	assessments	(art.	35);		
" in	consulting	with	the	supervisory	authority	when	there	is	high	risk	(art.	36).		
	
28.3	
(g)	
« That contract or other legal act shall stipulate, in particular, that the processor: (g) at	
the	choice	of	the	controller,	deletes	or	returns	all	the	personal	data	to	the	controller	
after	the	end	of	the	provision	of	services	relating	to	processing,	and	deletes	existing	
copies	unless	Union	or	Member	State	law	requires	storage	of	the	personal	data»	
	
	 " Provide	this	obligation	at	a	reasonable	level	of	practical	detail	(delays,	records	to	be	kept	to	
demonstrate	compliance…).	
	
	
28.3	
(h)	
« That contract or other legal act shall stipulate, in particular, that the processor: (h)
makes	available	to	the	controller	all	information	necessary	to	demonstrate	compliance	
with	the	obligations	laid	down	in	this	article	and	allow	for and contribute	to	audits,	
including	inspections,	conducted	by	the	controller	or	another	auditor	mandated	by	the	
controller»
	
	 " Provide a section in the contract or a separate annex that specifies this
obligation, in particular the audit conditions, at a reasonable level of
practical detail.
" State this obligation in the contract.
28.3	
(h)(2)	
«With regard to point (h), the processor shall immediately inform the controller if, in its
opinion, an instruction infringes this Regulation or other Union or Member State data
protection provisions.»
info@caneghem.be +32 495 58 54 45	
	 " Include this as an obligation for the processor in the contract.
	
* Art. 32
Information
Extract	
«Taking into account the state of the art, the costs of implementation and the
nature, scope, context and purposes of processing as well as the risk of varying
likelihood and severity for the rights and freedoms of natural persons, the controller
and the processor shall implement appropriate technical and organisational
measures to ensure a level of security appropriate to the risk, including inter alia as
appropriate:
(a) the pseudonymisation and encryption of personal data;
(b) the ability to ensure the ongoing confidentiality, integrity, availability and
resilience of processing systems and services;
(c) the ability to restore the availability and access to personal data in a timely
manner in the event of a physical or technical incident;
(d) a process for regularly testing, assessing and evaluating the effectiveness of
technical and organisational measures for ensuring the security of the processing.	»

Más contenido relacionado

Similar a Overview of Mandatory Content for Processing Contracts (GDPR)

SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...
SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...
SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...Oliver Barreto Rodríguez
 
Guidelines on the application and setting of administrative fines for the pur...
Guidelines on the application and setting of administrative fines for the pur...Guidelines on the application and setting of administrative fines for the pur...
Guidelines on the application and setting of administrative fines for the pur...i-SCOOP
 
Pronti per la legge sulla data protection GDPR? No Panic! - Stefano Sali, Dom...
Pronti per la legge sulla data protection GDPR? No Panic! - Stefano Sali, Dom...Pronti per la legge sulla data protection GDPR? No Panic! - Stefano Sali, Dom...
Pronti per la legge sulla data protection GDPR? No Panic! - Stefano Sali, Dom...Codemotion
 
How will legislation shape procurement in the coming years?
How will legislation shape procurement in the coming years?How will legislation shape procurement in the coming years?
How will legislation shape procurement in the coming years?Procurement For Housing
 
Cloud Computing_CS_Oct2012
Cloud Computing_CS_Oct2012Cloud Computing_CS_Oct2012
Cloud Computing_CS_Oct2012Paras Kumar Jain
 
BARNES & THORNBURG LLP - Data Processing Agreement 4-6-18
BARNES & THORNBURG LLP - Data Processing Agreement 4-6-18BARNES & THORNBURG LLP - Data Processing Agreement 4-6-18
BARNES & THORNBURG LLP - Data Processing Agreement 4-6-18FortuneCMO, LLC
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017Cliff Ashcroft
 
Intro ataya inauguration event 12 dec 17
Intro ataya inauguration event 12 dec 17Intro ataya inauguration event 12 dec 17
Intro ataya inauguration event 12 dec 17Georges Ataya
 
General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary Compliance3
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016John Greenwood
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPRDipanjanDey12
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPRPavol Balaj
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET
 

Similar a Overview of Mandatory Content for Processing Contracts (GDPR) (20)

SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...
SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...
SLALOM Webinar Final Legal Outcomes Explanined "Using the SLALOM Contract Ser...
 
Quick guide gdpr
Quick guide gdprQuick guide gdpr
Quick guide gdpr
 
Data processing agreement
Data processing agreement Data processing agreement
Data processing agreement
 
Guidelines on the application and setting of administrative fines for the pur...
Guidelines on the application and setting of administrative fines for the pur...Guidelines on the application and setting of administrative fines for the pur...
Guidelines on the application and setting of administrative fines for the pur...
 
Pronti per la legge sulla data protection GDPR? No Panic! - Stefano Sali, Dom...
Pronti per la legge sulla data protection GDPR? No Panic! - Stefano Sali, Dom...Pronti per la legge sulla data protection GDPR? No Panic! - Stefano Sali, Dom...
Pronti per la legge sulla data protection GDPR? No Panic! - Stefano Sali, Dom...
 
Def ppt ippc vogel
Def ppt ippc vogelDef ppt ippc vogel
Def ppt ippc vogel
 
electronic commerce act 8792 (2000)
electronic commerce act 8792 (2000)electronic commerce act 8792 (2000)
electronic commerce act 8792 (2000)
 
How will legislation shape procurement in the coming years?
How will legislation shape procurement in the coming years?How will legislation shape procurement in the coming years?
How will legislation shape procurement in the coming years?
 
Cloud Computing_CS_Oct2012
Cloud Computing_CS_Oct2012Cloud Computing_CS_Oct2012
Cloud Computing_CS_Oct2012
 
BARNES & THORNBURG LLP - Data Processing Agreement 4-6-18
BARNES & THORNBURG LLP - Data Processing Agreement 4-6-18BARNES & THORNBURG LLP - Data Processing Agreement 4-6-18
BARNES & THORNBURG LLP - Data Processing Agreement 4-6-18
 
EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017EU General Data Protection Regulation - Update 2017
EU General Data Protection Regulation - Update 2017
 
Intro ataya inauguration event 12 dec 17
Intro ataya inauguration event 12 dec 17Intro ataya inauguration event 12 dec 17
Intro ataya inauguration event 12 dec 17
 
GDPR and Personal Data Transfers 1.1.pdf
GDPR and Personal Data Transfers 1.1.pdfGDPR and Personal Data Transfers 1.1.pdf
GDPR and Personal Data Transfers 1.1.pdf
 
General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary General Data Protection Regulations (GDPR) Summary
General Data Protection Regulations (GDPR) Summary
 
Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016Regulation (EU) 2016_679_GDPR_Overview_June 2016
Regulation (EU) 2016_679_GDPR_Overview_June 2016
 
Business Law - Unit 3
Business Law - Unit 3Business Law - Unit 3
Business Law - Unit 3
 
RLEAAT EMERSON EDUARDO RODRIGUES
RLEAAT EMERSON EDUARDO RODRIGUESRLEAAT EMERSON EDUARDO RODRIGUES
RLEAAT EMERSON EDUARDO RODRIGUES
 
Presentation on GDPR
Presentation on GDPRPresentation on GDPR
Presentation on GDPR
 
Quick Guide to GDPR
Quick Guide to GDPRQuick Guide to GDPR
Quick Guide to GDPR
 
ESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection RegulationESET Quick Guide to the EU General Data Protection Regulation
ESET Quick Guide to the EU General Data Protection Regulation
 

Último

Current Ethical Issues for Legal Professionals.ppt
Current Ethical Issues for Legal Professionals.pptCurrent Ethical Issues for Legal Professionals.ppt
Current Ethical Issues for Legal Professionals.pptVidyaAdsule1
 
Attestation presentation under Transfer of property Act
Attestation presentation under Transfer of property ActAttestation presentation under Transfer of property Act
Attestation presentation under Transfer of property Act2020000445musaib
 
Hungarian legislation made by Robert Miklos
Hungarian legislation made by Robert MiklosHungarian legislation made by Robert Miklos
Hungarian legislation made by Robert Miklosbeduinpower135
 
Grey Area of the Information Technology Act, 2000.pptx
Grey Area of the Information Technology Act, 2000.pptxGrey Area of the Information Technology Act, 2000.pptx
Grey Area of the Information Technology Act, 2000.pptxBharatMunjal4
 
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptxSarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptxAnto Jebin
 
Guide for Drug Education and Vice Control.docx
Guide for Drug Education and Vice Control.docxGuide for Drug Education and Vice Control.docx
Guide for Drug Education and Vice Control.docxjennysansano2
 
Analysis on Law of Domicile under Private International laws.
Analysis on Law of Domicile under Private International laws.Analysis on Law of Domicile under Private International laws.
Analysis on Law of Domicile under Private International laws.2020000445musaib
 
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTS
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTSTHE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTS
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTSRoshniSingh312153
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceMichael Cicero
 
1990-2004 Bar Questions and Answers in Sales
1990-2004 Bar Questions and Answers in Sales1990-2004 Bar Questions and Answers in Sales
1990-2004 Bar Questions and Answers in SalesMelvinPernez2
 
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiAlexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiBlayneRush1
 
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis LeeAlexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis LeeBlayneRush1
 
Illinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guideIllinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guideillinoisworknet11
 
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los Angeles
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los AngelesAre There Any Alternatives To Jail Time For Sex Crime Convictions in Los Angeles
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los AngelesChesley Lawyer
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesritwikv20
 
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptx
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptxThe Punjab Land Reforms AcT 1972 HIRDEBIR.pptx
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptxgurcharnsinghlecengl
 
Vanderburgh County Sheriff says he will Not Raid Delta 8 Shops
Vanderburgh County Sheriff says he will Not Raid Delta 8 ShopsVanderburgh County Sheriff says he will Not Raid Delta 8 Shops
Vanderburgh County Sheriff says he will Not Raid Delta 8 ShopsAbdul-Hakim Shabazz
 
Understanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal FrameworksUnderstanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal FrameworksFinlaw Associates
 
Alexis OConnell mugshot Lexileeyogi 512-840-8791
Alexis OConnell mugshot Lexileeyogi 512-840-8791Alexis OConnell mugshot Lexileeyogi 512-840-8791
Alexis OConnell mugshot Lexileeyogi 512-840-8791BlayneRush1
 
PPT Template - Federal Law Enforcement Training Center
PPT Template - Federal Law Enforcement Training CenterPPT Template - Federal Law Enforcement Training Center
PPT Template - Federal Law Enforcement Training Centerejlfernandez22
 

Último (20)

Current Ethical Issues for Legal Professionals.ppt
Current Ethical Issues for Legal Professionals.pptCurrent Ethical Issues for Legal Professionals.ppt
Current Ethical Issues for Legal Professionals.ppt
 
Attestation presentation under Transfer of property Act
Attestation presentation under Transfer of property ActAttestation presentation under Transfer of property Act
Attestation presentation under Transfer of property Act
 
Hungarian legislation made by Robert Miklos
Hungarian legislation made by Robert MiklosHungarian legislation made by Robert Miklos
Hungarian legislation made by Robert Miklos
 
Grey Area of the Information Technology Act, 2000.pptx
Grey Area of the Information Technology Act, 2000.pptxGrey Area of the Information Technology Act, 2000.pptx
Grey Area of the Information Technology Act, 2000.pptx
 
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptxSarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
 
Guide for Drug Education and Vice Control.docx
Guide for Drug Education and Vice Control.docxGuide for Drug Education and Vice Control.docx
Guide for Drug Education and Vice Control.docx
 
Analysis on Law of Domicile under Private International laws.
Analysis on Law of Domicile under Private International laws.Analysis on Law of Domicile under Private International laws.
Analysis on Law of Domicile under Private International laws.
 
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTS
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTSTHE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTS
THE INDIAN CONTRACT ACT 1872 NOTES FOR STUDENTS
 
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics GuidanceLaw360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
Law360 - How Duty Of Candor Figures In USPTO AI Ethics Guidance
 
1990-2004 Bar Questions and Answers in Sales
1990-2004 Bar Questions and Answers in Sales1990-2004 Bar Questions and Answers in Sales
1990-2004 Bar Questions and Answers in Sales
 
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogiAlexis O'Connell Arrest Records Houston Texas lexileeyogi
Alexis O'Connell Arrest Records Houston Texas lexileeyogi
 
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis LeeAlexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
Alexis O'Connell lexileeyogi Bond revocation for drug arrest Alexis Lee
 
Illinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guideIllinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guide
 
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los Angeles
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los AngelesAre There Any Alternatives To Jail Time For Sex Crime Convictions in Los Angeles
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los Angeles
 
Comparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use casesComparison of GenAI benchmarking models for legal use cases
Comparison of GenAI benchmarking models for legal use cases
 
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptx
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptxThe Punjab Land Reforms AcT 1972 HIRDEBIR.pptx
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptx
 
Vanderburgh County Sheriff says he will Not Raid Delta 8 Shops
Vanderburgh County Sheriff says he will Not Raid Delta 8 ShopsVanderburgh County Sheriff says he will Not Raid Delta 8 Shops
Vanderburgh County Sheriff says he will Not Raid Delta 8 Shops
 
Understanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal FrameworksUnderstanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
 
Alexis OConnell mugshot Lexileeyogi 512-840-8791
Alexis OConnell mugshot Lexileeyogi 512-840-8791Alexis OConnell mugshot Lexileeyogi 512-840-8791
Alexis OConnell mugshot Lexileeyogi 512-840-8791
 
PPT Template - Federal Law Enforcement Training Center
PPT Template - Federal Law Enforcement Training CenterPPT Template - Federal Law Enforcement Training Center
PPT Template - Federal Law Enforcement Training Center
 

Overview of Mandatory Content for Processing Contracts (GDPR)

  • 1. info@caneghem.be +32 495 58 54 45 Scheme for the amendment or drafting of processing contracts to comply with the General Data Protection Regulation (GDPR) November 2017
  • 2. info@caneghem.be +32 495 58 54 45 The General Data Protection Regulation of April 27, 2016, requires a written processing contract (or other legal act) between data controllers and data processors. The GDPR also regulates the minimum content of the processing contracts. Below follows an overview of the requirements of the GDPR for the content of the processing contracts with a reference to the specific provisions of the regulation and a suggested practical drafting approach. Article Text of the GDPR article and a recommended drafting approach 28.1 «The controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.» " Document the technical and organizational capabilities of the Processor, either through referring to a standard obtained by processor (è art. 28.5: adherence to an approved code of conduct or an approved certification mechanism may be used to demonstrate sufficient guarantees) or to a schedule that documents those capabilities. " Make the maintenance of these standards a condition for the (continuation) of the contract. 28.2 «The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.» " Provide a general written authorization in the contract and specify that processor will need to inform controller of any changes in sub-processors to which controller will have the opportunity to object; " alternatively, provide that a specific authorisation will be needed. 28.3 «Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller.»
  • 3. info@caneghem.be +32 495 58 54 45 " Provide a reference to a schedule that contains (a) the subject matter of the processing; (b) the nature and the purpose of the processing; (c) the type of personal data and categories of data subjects. " Prepare and attach the schedule; " Reserve to the controller the right to change the schedule within certain conditions or/and spell out the consequences if parties do not agree on changes to the schedule. " Specify the obligations and rights of the controller in the contract. " Insert a clause that sets the duration; " Insert a clause that spells out the termination rights and conditions and the consequences of termination. 28.3 (a) «That contract or other legal act shall stipulate, in particular, that the processor: (a) processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by Union or Member State law to which the processor is subject; and that, in such a case, the processor shall inform the controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest» " Insert a clause to that borrows the language of art. 28.3 (a). 28.3 (b) «That contract or other legal act shall stipulate, in particular, that the processor: (b) ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality» " Provide a default confidentiality clause or standard in the contract to be used by the processor in the relation with its personnel or contractors and/or make a reference to the applicable appropriate statutory obligation of confidentiality. 28.3 (c) « That contract or other legal act shall stipulate, in particular, that the processor: (c) takes all measures required pursuant to Article 32*» " List the measures of art. 32 that are deemed appropriate either in the contract or in a schedule to the contract (see: * below). " List the measures of art. 32 that are not deemed appropriate and document why. This documentation is to be included in a schedule to the contract and in the compliance documentation of each party. " Insert a clause in the contract that provides for flexibility in case of changing circumstances.» 28.3 (d) « That contract or other legal act shall stipulate, in particular, that the processor: (d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor» " Provide that the processor shall respect the conditions of 28.2 and of 28.4 for appointing a sub-processor. " Provide that the processor shall pass on all its obligations to a sub-processor, in particular the obligations to take appropriate technical and organisational measures so that processing meets the requirements of the Regulation and ensures the
  • 4. info@caneghem.be +32 495 58 54 45 protection of the rights of the data subject (art. 28.1) and the obligations from the article 28.3, while remaining liable for the sub-processor. 28.3 (e) «That contract or other legal act shall stipulate, in particular, that the processor: (e) taking into account the nature of the processing, assists the controller with appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III» " Specify this obligation in the contract, if possible at a reasonable level of practical detail. 28.3 (f) « That contract or other legal act shall stipulate, in particular, that the processor: (f) assists the controller in ensuring compliance with the obligations pursuant to articles 32 to 36 taking into account the nature of processing and the information available to the processor» Provide sections in the contract that oblige the processor to assist controller: " in keeping personal data secure (art. 32); " in notifying personal data breaches to the supervisory authority (art. 33); " in advising data subjects when there has been a personal data breach (art. 34); " in carrying out data protection impact assessments (art. 35); " in consulting with the supervisory authority when there is high risk (art. 36). 28.3 (g) « That contract or other legal act shall stipulate, in particular, that the processor: (g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data» " Provide this obligation at a reasonable level of practical detail (delays, records to be kept to demonstrate compliance…). 28.3 (h) « That contract or other legal act shall stipulate, in particular, that the processor: (h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller» " Provide a section in the contract or a separate annex that specifies this obligation, in particular the audit conditions, at a reasonable level of practical detail. " State this obligation in the contract. 28.3 (h)(2) «With regard to point (h), the processor shall immediately inform the controller if, in its opinion, an instruction infringes this Regulation or other Union or Member State data protection provisions.»
  • 5. info@caneghem.be +32 495 58 54 45 " Include this as an obligation for the processor in the contract. * Art. 32 Information Extract «Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate: (a) the pseudonymisation and encryption of personal data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing. »