The effects of GDPR on data processors

The effects of GDPR on data processors

The long-awaited General Data Protection Regulation (GDPR), which came into force in April 2016, will apply in full by May 2018. That means enforcement of its measures is only a little over a year away.

The scope of the GDPR is much wider than the previous 1995 data Protection Directive, and nowhere is that clearer than on data processors, with increased direct obligations.

Alongside this sea change is the possibility of data subjects enforcing their rights directly against data processors and a regime which could see non-compliant processors open to increased, hefty fines. Data processors have a variety of business models from on-premises processing to, increasingly, cloud services, but the provisions that apply to processing personal data are the same no matter what the platform.

A processor means a natural or legal person, public authority or agency or other body which processes personal data on behalf of the controller. The GDPR identifies processing activity as follows:

Data processors appointed by controllers must provide sufficient guarantees to implement appropriate technical and organisational measures to ensure processing meets the requirement of the GDPR and process personal data in accordance with the controller’s instructions.

Data processors require prior written consent from the controller to subcontract their activities. The processor is required to inform the controller of any new sub-processors, allowing the controller to object. The lead processor is required to reflect the main contractual responsibility in its sub processing agreements and remains liable to the controller for the action or inaction of the sub processor.

Data processing activity must be governed by contractual obligations between controller and processor. There is scope for this to be replaced with Member State or EU Law. The binding obligations must cover the duration, nature and purpose of the processing, the types of data processed and the obligations and rights of the controller. There are a number of specific requirements, such as documented processing and requirements to assist the controller in meeting obligations.

A common theme of the GDPR is accountability and compliance. Processors must maintain a record of all categories of processing activities. This must include details of the controller and any other processors as well as the relevant contact details of the Data Protection Officer (DPO), the categories of processing carried out, details of any transfers or data exports, and a description of technical and organisational security measures. These records must be available to the Supervisory Authority, which in Ireland would be the Data Protection Commissioner, on request.

Processors must have appropriate security measures and what’s appropriate is assessed in terms of a variety of factors including:

Processors are required to take ownership of these issues and, under the GDPR, the onus and responsibility has shifted significantly from the controller to the processor in this regard.

Processors are required to notify the controller of any breach without “undue delay” after becoming aware of it.

 

Share it:
Share it:

[Social9_Share class=”s9-widget-wrapper”]

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

You Might Be Interested In

Is AI in danger of becoming too male?

3 Sep, 2019

Juan Mateos-Garcia, Nesta and Joysy John, NestaArtificial Intelligence (AI) systems are becoming smarter every day, beating world champions in games …

Read more

How you can stay up to date with your #AI and #MachineLearning knowledge

18 Aug, 2018

Andrew Ng is a great fan of reading research papers as a long term investment in your own study (On …

Read more

Predictive Analytics in the Real World: Utilities and the Pandemic

30 Sep, 2020

Using predictive analytics can help utilities safeguard revenues and protect at-risk customers. In the age of coronavirus, when millions of …

Read more

Recent Jobs

Senior Cloud Engineer (AWS, Snowflake)

Remote (United States (Nationwide))

9 May, 2024

Read More

IT Engineer

Washington D.C., DC, USA

1 May, 2024

Read More

Data Engineer

Washington D.C., DC, USA

1 May, 2024

Read More

Applications Developer

Washington D.C., DC, USA

1 May, 2024

Read More

Do You Want to Share Your Story?

Bring your insights on Data, Visualization, Innovation or Business Agility to our community. Let them learn from your experience.

Get the 3 STEPS

To Drive Analytics Adoption
And manage change

3-steps-to-drive-analytics-adoption

Get Access to Event Discounts

Switch your 7wData account from Subscriber to Event Discount Member by clicking the button below and get access to event discounts. Learn & Grow together with us in a more profitable way!

Get Access to Event Discounts

Create a 7wData account and get access to event discounts. Learn & Grow together with us in a more profitable way!

Don't miss Out!

Stay in touch and receive in depth articles, guides, news & commentary of all things data.