Processing Agreement

A processing agreement regulates the agreements between organizations and companies that process personal data on behalf of each other. Almost every company will have to deal with processing agreements.

A simple example. Almost every company has a website, with a contact page on it. Visiting the website, and completing the contact page, leads to the processing of personal data. This personal data is not only processed by the company behind the website but also by, for example, the hosting provider through which the website can be made available online.

In this case, the website owner will have to make an appointment with the hosting provider to ensure the careful processing of personal data. These agreements are laid down in a processing agreement. The requirements for the processing agreement follow from the GDPR

ict recht

Processing Agreement in the GDPR (AVG)

Personal data may not be processed just like that. Companies and organizations that want to process personal data must comply with the GDPR (AVG) (and the U-AVG). The GDPR regulates that controlling always remains obligatory for the processing of personal data.

According to the GDPR, it, therefore, does not matter whether the controller processes the personal data itself or whether it outsources this to another party – a processor. However, this final responsibility does not affect the fact that the processor also has responsibilities under the GDPR. The parties must arrange responsibility for the careful processing of personal data in a processor agreement. If the parties fail to do so, they will both be in violation of the GDPR. 

Handelsnaamrecht

Processor or Controller?

A processing agreement is not always mandatory.

For example, a processing agreement is only mandatory if the company or organization engages another party to process personal data on behalf of it. However, the controller determines what should be done with the data and how.

If this is not the case, but personal data is nevertheless provided to another party, which also processes the personal data itself (and determines what should be done with it, in which way), it may be that the other party is also (or even jointly) responsible for the processing. In that case, a processor agreement is not required. However, the provision of personal data to this (co-) controller must comply with the rules of (further) processing.

What should be included in a Processing Agreement?

The GDPR requires that the processing agreement has to be written and cover the agreements for the careful processing of personal data.

The processing agreement must in any case address the following subjects:

  • general description of the processing (subject, duration, nature, the purpose of the processing, the type of personal data, the categories of data subjects, rights and obligations of controllers);
  • in principle, the processing may only take place on the basis of written instructions from the controller;
  • the processor may not use the personal data for his own purposes;
  • parties involved in the processing, such as employees and hired workers, must observe secrecy;
  • the personal data must be adequately secured (technically and organisationally), such as through pseudonymisation and encryption of personal data, information security, restoration of availability, access to data in the event of incidents and regular security tests;
  • sub-processors may not be engaged just like that, in principle, this requires the prior written permission of the controller;
  • the sub-processor must be held to the same obligations as the processor towards the controller;
  • the processor remains liable for breaches of obligations by sub-processors;
  • the processor must cooperate in complying with the privacy rights of data subjects, such as
    • the right of access,
    • the right of correction,
    • the right to be forgotten,
    • the right to data portability
  • the processing must cooperate in the fulfilment of other obligations, such as
      • reporting data breaches
      • performing a data protection assessment (DPIA)
      • audits
      • any prior consultation of the Dutch Data Protection Authority
  • the processor must delete data after the processing service has ended unless this is required by law, or any return obligation.

The processing agreement may not contain agreements that are contrary to the GDPR. In that case, the GDPR takes precedence over what has been arranged in the processing agreement.

intellectueel eigendom vastleggen

Conflicts over the Content of a Processor Agreement

Parties are not obliged to agree to the processing agreement of another party. There is no contract enforcement. If parties do not agree on the content of the processor agreement, they can choose not to cooperate. Working together without a processing agreement, in any case, means a violation of the GDPR.

Contact

LAWFOX’s lawyers specialize in privacy law. We deal with processing agreements every week. We assist processors, controllers and data subjects. We draw up processing agreements, negotiate processing agreements, advise on privacy issues such as data leaks, requests from data subjects and supervision by the Dutch Data Protection Authority, and assist with conflicts in the area of ​​privacy law.

Contactform

  • This field is for validation purposes and should be left unchanged.

ict recht advocaten in de rechtbank

Google reviews LAWFOX

0 / 10 0 reviews