Knowledge items

Responsibilities in Drafting Data Processing Agreements

Navigating GDPR Compliance for Access and Identity Management

 

11 June 2018

Access control and identity management often involve multiple parties handling personal data. Understanding roles and responsibilities is crucial for ensuring GDPR compliance. Here’s how organizations can manage these responsibilities effectively: 

Understanding Roles: Controller vs. Processor 

The GDPR defines specific roles:

  • Controller: Determines the purpose and means of processing personal data.
  • Processor: Processes data on behalf of the controller, without direct oversight.

Examples:

  • A security company staffing a reception desk (processor) for an organization (controller).
  • A marketing agency using observation data for promotional campaigns (processor) on behalf of its client (controller).

What to Include in a Data Processing Agreement (DPA)? 

A DPA formalizes the relationship between the controller and processor. For instance, a petrochemical facility might require external security staff to scan IDs of visitors. The DPA must include:

  1. Purpose and Scope: Detailed justification for processing activities.
  1. Data Use Limitations: Restriction against processing data for unauthorized purposes.
  1. Security Measures: Steps to protect data.
  1. Data Breach Procedures: Clear protocols for handling breaches.
  1. Sub-Processor Agreements: Terms for involving third parties under the processor’s purview.

Benefits of a DPA in Practice 

A DPA ensures compliance and formalizes quality standards for service providers. For example, a security guard should know how to handle personal data properly and answer questions about why and how data is collected. These agreements drive accountability and improve service quality. 

Key Takeaway

Organizations must evaluate all collaborations and role allocations to retain control. Drafting a DPA based on your analysis ensures you maintain oversight.

Related

Topics