GDPR · Domain 3
Controller & Processor Obligations
About 20% of the exam
Who is who
- Controller
- decides purposes and means
- Joint controllers
- jointly decide purposes and means
- Processor
- acts only on documented instructions
- Sub processor
- engaged by the processor
- Third party
- outside the controller's direct authority
- Recipient
- anyone the data is disclosed to
- Representative
- local contact for an outside controller
A processor that starts deciding purposes becomes a controller for that processing under Article 28(10), and inherits every controller duty with it
Article 28 contract clauses
- Subject matter, duration, nature and purpose
- Types of data and categories of people
- Process only on documented instructions
- Confidentiality commitments from everyone involved
- Security measures meeting Article 32
- Sub processors only with written authorization
- Assist with rights requests and breaches
- Delete or return data at the end
- Allow audits and inspections
The contract must be in writing, and a general sub processor authorization still requires notice and a genuine chance to object
Records, Article 30
- Controllers record purposes and data categories
- Processors record categories of processing performed
- Recipients including those outside the Union
- Retention schedules wherever they can be given
- General description of security measures
- Produced to the authority on request
The small firm exemption
- Fewer than two hundred fifty employees
- Lost when processing risks people's rights
- Lost when processing is not occasional
- Lost for special category data
- In practice almost nobody escapes it
Impact assessment triggers
- Systematic extensive evaluation with significant effects
- Large scale special category processing
- Systematic monitoring of public areas
- Authority blacklists add national triggers
- New technology aimed at people
- Run it before processing begins
What an assessment contains
- Systematic description of the processing
- Necessity and proportionality assessment
- Risks to rights and freedoms
- Measures that reduce those risks
- Advice sought from the protection officer
- Views of affected people where appropriate
The data protection officer
When mandatory
- A public authority or body
- Large scale systematic monitoring as core
- Large scale special category processing
- National law may add cases
How they must work
- Report to the highest management level
- No instructions on how to advise
- No dismissal for doing the job
- Resources, access and ongoing training
One officer can serve a group of undertakings if they stay reachable from each establishment, and the role can sit with an external contractor
Conflicts of interest
- Chief executive or finance chief
- Head of information technology
- Head of human resources or marketing
- Anyone who sets processing purposes
- Advisory role, never the decision maker
Joint controllers, Article 26
- Arrangement allocating each party's duties
- Essence made available to people
- People may exercise rights against either
- Each remains accountable for its processing
- Embedded plugins can create the relationship
Prior consultation, Article 36
- Triggered by high residual risk
- Send the assessment and the measures
- Give purposes, means and officer contact
- Authority answers within eight weeks
- Extendable by six further weeks
- Processing waits for the answer
Design and default, Article 25
- Measures chosen when the means are decided
- Pseudonymization and minimization given as examples
- Only necessary data processed by default
- Defaults limit access and retention
- Nothing made public without human action
- Certification helps demonstrate the duty
Vendor failures that bite
- Generic terms with no Article 28 clauses
- Sub processors added with no notice
- Audit rights promised but never used
- Breach terms vaguer than the regulation
- No exit plan for data return
- Roles never revisited as services change
Appointing a processor, step by step
- Define the processing you need
- Check the guarantees they offer
- Sign an Article 28 contract
- Map sub processors and transfers
- Record it under Article 30
- Audit and review periodically
- Plan return or deletion at exit
- Certification evidences guarantees but not the contract
- Instructions must be documented, not verbal
- The controller stays accountable to people
- Processors carry direct duties of their own
Rapid recall: obligation articles
- Article 24
- controller responsibility and measures
- Article 25
- design and default
- Article 26
- joint controller arrangements
- Article 27
- representatives for outside bodies
- Article 28
- processor contracts
- Article 30
- records of processing
- Article 32
- security of processing
- Article 35
- data protection impact assessments
- Article 37
- designating the officer
Liability in a chain
- Controller
- answerable to people for everything
- Processor
- liable for its own breaches
- Sub processor failure
- processor answers to the controller
- Full payment
- claim contribution from the others
- Exemption
- prove you were not responsible
Reference strip: roles, contracts, records, assessments, officer
Roles
- Purposes and means decide it
- Roles can change over time
- One firm can be both
Contracts
- Written, with Article 28 clauses
- Sub processing needs authorization
- Delete or return at exit
Records
- Both roles keep them
- Show them on request
- The small firm exemption rarely applies
Assessments
- Before high risk processing starts
- Consult when residual risk stays
- Review when the risk changes
Officer
- Three mandatory triggers
- Independent and properly resourced
- Advises, never decides
Quick exam traps
- Trap: A processor can never be fined directly, only the controller
- Trap: Signing a processor contract transfers accountability to the vendor
- Trap: The data protection officer is personally liable for the controller's breaches
- Trap: Only bodies with more than two hundred fifty staff keep records of processing
- Trap: An impact assessment can be written up after the system goes live
- Trap: The head of information technology is the natural choice for protection officer
- Trap: General authorization for sub processors means the controller never has to be told
cybercertprep.com · original revision sheet written from the public body of knowledge