Point of law
Reviewing processing agreements
Whether processing on behalf exists at all is decided by purposes and means, not by the type of contract. The European Court of Justice has said so expressly for joint controllership. An Art. 28 GDPR agreement covering processing that is not processing on behalf orders nothing and protects nobody.
The provider’s contract is on the table
The provider puts forward its processing agreement, eleven pages, with an annex on technical and organisational measures. It is to be signed by Friday. Whether the provider processes on instructions at all appears on none of the eleven pages.
The role follows the facts and not the contract
Whether processing on behalf exists at all comes before the question of what the contract should say. Under Art. 4(7) GDPR, whoever determines the purposes and means of processing is a controller. On 5 December 2023 the European Court of Justice held for joint controllership that the classification does not presuppose an agreement but follows from the fact alone that several entities participated in that determination.
Three roles, and the contract is the consequence
| Merkmal | Separate controllers | Joint controllers | Processing on behalf |
|---|---|---|---|
| Who determines purposes and means | Each entity for itself | Both togetherIncluding through converging separate decisions. | The client alone |
| Own purpose of the other side | YesFor instance a tax adviser bound by their own professional duties. | A shared purposeFor instance audience measurement serving both sides. | NoProcessing solely on instructions, Art. 29 GDPR. |
| What has to be concluded | No data protection contractAt most a basis for the transfer under Art. 6 GDPR. | Arrangement under Art. 26 GDPR | Agreement under Art. 28 GDPR |
| Who answers data subject rights | Each entity itself | As set out in the arrangementThe data subject may nonetheless approach either of them. | The clientAssisted by the processor, Art. 28(3)(e) GDPR. |
An Art. 28 GDPR agreement covering processing that is not processing on behalf orders nothing. It does not stop a supervisory authority from classifying correctly, and it gives the other side no legal basis for its own purposes.
The catalogue in paragraph 3 is the minimum equipment
What has to appear in the contract is listed in Art. 28(3) GDPR. It begins with the subject matter and duration, the nature and purpose, the type of personal data and the categories of data subjects. Eight obligations of the processor follow.
The eight obligations, grouped by what they trigger at your end
Instructions and confidentiality
Points (a) and (b). The instruction has to be documented, including for a transfer to a third country. The processor has to inform the controller immediately where it considers an instruction unlawful.
Security and sub-processors
Points (c) and (d). The measures under Art. 32 GDPR and the conditions for engaging further processors. These two points are where a contract either delivers something in substance or does not.
Assistance with rights and duties
Points (e) and (f). Assistance with data subject requests and with the obligations in Art. 32 to 36 GDPR. These two undertakings decide whether an access reply or a breach notification is possible within its deadline.
End of the service and demonstration
Points (g) and (h). Deletion or return at the choice of the controller, and making available all information needed to demonstrate compliance, including allowing audits. The choice belongs to the controller, and a clause leaving it to the provider departs from the wording.
The chain does not end at the first processor
The chain rarely ends at the first processor. Larger providers in particular engage further processors. Consent to their engagement may be given generally, but Art. 28(2) GDPR then requires notice of any intended change, so the controller can object if need be.
Where a sub-processor breaches its obligations, Art. 28(4) sentence 2 GDPR first holds the engaging processor liable to the controller. Towards the data subject, Art. 82 GDPR applies, limiting the processor’s liability to breaches of its own obligations or of instructions.
An annex made of buzzwords demonstrates nothing
What the annex on measures has to deliver follows from two provisions at once. Art. 28(1) GDPR permits working only with processors providing sufficient guarantees. Art. 32(1) GDPR names four requirements against which an annex can be measured.
Four questions for an annex on measures
Liste zu erledigender Punkte
- Does it name pseudonymisation and encryption, and for which data in which state
- Does it describe confidentiality, integrity, availability and resilience on an ongoing basis, or only the current state
- Does it say anything about restoring availability swiftly after an incident
- Does it name a process for regularly testing the effectiveness of the measures, required by Art. 32(1)(d) GDPR
A certification does not replace this review. Art. 28(5) GDPR names approved codes of conduct and certification mechanisms as an element to demonstrate sufficient guarantees, and an element is not proof.
How we support you in reviewing your data processing agreements
The stock of contracts can be derived from the record of processing activities, because the categories of recipients sit there. The review runs in two passes, first the role and then the content. Where the data protection role is wrongly determined, the entire contract rests on a mistaken basis and is therefore flawed.
Negotiating the contract itself lies outside data protection law. Limitation of liability, contractual penalties, termination rights and the review of pre-formulated clauses under sections 305 et seq. BGB run through the affiliated law firm.
Frequently asked questions
How do you recognise processing on behalf?
By the other side processing on instructions and without a purpose of its own, Art. 4(8) and Art. 29 GDPR. Whoever co-decides on purposes and means is a joint controller, and whoever pursues their own purposes is a controller in their own right. The type of contract follows from that and not the other way round.
Does every sub-processor need approval?
Art. 28(2) GDPR allows general written authorisation. The processor then has to inform the controller of any intended changes, so that objection remains possible. A clause pointing to a list on a website without providing for notification does not meet this.
What happens if a sub-processor breaches its duties?
Under Art. 28(4) sentence 2 GDPR the first processor remains liable to the controller for the performance of further (sub-)processors' obligations. Towards the data subject, Art. 82 GDPR applies alongside, with its own allocation of liability.
Is a certification of the provider enough?
It is a factor and not proof. Art. 28(5) GDPR names approved codes of conduct and certification mechanisms expressly as an element to demonstrate sufficient guarantees. Which processing the scope of a certification actually covers is a separate question.
Get in touch!
Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!
Contact usAlternatively you can request a call back.