GDPR Subcontractor: why regulate subcontracting?
GDPR contractual clauses, a mandatory framework for relations between GDPR processors and controllers
These clauses are important, as they help to frame the relationship between the parties and more particularly the issues of responsibilities.
It should be noted that these clauses must contain, at a minimum and in written form, according to Article 28 of the GDPR, the organization of the collaboration for the exercise of data subjects' rights and the various security clauses of Article 29. The procedure for notification in the event of a data breach must also be framed. Finally, data transfer clauses and audit clauses must appear.
Article to read: 11 actions to take for your GDPR compliance
We can identify several types of relationships, and for this research work we will assume that the organization, regardless of its role, is the one drafting the clauses. We will call it "organization A".
A. Defining the conditions of subcontracting
Organization A is the data controller, and its co-contractor is a GDPR processor. That is to say, it acts on behalf of and under the instructions of the data controller, in this case on behalf of organization A.
The challenge for organization A is to define the subcontracting conditions, i.e. to fulfill the obligations of the applicable regulation, in particular the obligation to enter into a contract. This allows the GDPR processor to be committed at the level defined by the organization. Particularly with regard to possible sub-processing — when processor 1 engages processor 2.
When organization A is a GDPR processor, drafting these clauses allows it to reduce the risk of being qualified as a joint data controller.
Indeed, the obligations differ. Moreover, this allows organization A not to commit to more than what it can, for example at the level of services to be performed. A requalification of organization A as a data controller is nevertheless not excluded in light of an "in concreto" analysis of the relationship between organization A and its principal in the context of the data processing concerned.
It is therefore important to ensure that in the context of the relationship with the principal, organization A does not behave as a co-controller at any time, in order to faithfully reflect what has been contractualized with the principal.
B. Information of data subjects
Organization A is the data controller and the recipients are the data subjects. Through these clauses, the data controller fulfills the obligations of the applicable regulation, in particular the obligation to inform data subjects.
Another scenario, organization A is still the data controller, but has an intermediary role with the data subjects. This is particularly the case when it is difficult or impossible to inform data subjects directly. It is then a matter of transferring this obligation to a co-contractor in contact with the data subjects, such as the employer for example.
Organization A is a GDPR processor and its co-contractor is the data controller. These clauses will make it possible to specify in the documents enforceable against end users that organization A is not the data controller, but only the processor, as it is not the one who determines the purposes and means of the processing.
C. Excluding subcontracting
Organization A is the data controller and so is its co-contractor. The clauses defining that each party is responsible for its compliance with the applicable regulation make it possible to avoid the qualification of processor.
D. Examples of limitation clauses
It becomes important for organizations to limit their liabilities, within the regulatory limit. As an example, below is a contractual clause illustrating this:
"The Partner shall ensure not to submit, transmit, store Data that would require The organization to comply with specific laws or regulations other than those expressly provided for in the Contract.
Within the meaning of Law No. 2004-575 of 21 June 2004, for Trust in the Digital Economy known as "LCEN", The organization is deemed to be the host of the Data and the Partner the publisher of the content and Data. Indeed, The organization does not carry out any prior verification of the Partner's Data, and therefore cannot be held responsible for the content or effects of this Data, without prejudice to compliance with the Data Protection Regulation in case of Personal Data".
The purpose here is to indicate that the organization does not control the personal data it processes, so it cannot be held responsible for any breach due to the data controller.
This wording can also be found:
"The Partner has informed The organization that its Data could include Personal Data. The Partner undertakes, however, to process and subcontract to The organization only the Personal Data strictly necessary to meet its own needs and those of its users in the context of the Services. The Partner acknowledges and accepts that it acts as "Data Controller" within the meaning of the Data Protection Regulation, on its Personal Data, The organization being deemed "Processor" and acting in this capacity under the Partner's instructions".
With each party having to define its capacity in the context of processing of personal data concerned, GDPR clauses are becoming increasingly detailed with variable consequences.
The end of the contractual relationship
These clauses, which govern the relationships, can provide for the consequences in case of termination of the contract between the parties, or even justify the termination of the contract in case of non-compliance with them. This is therefore a subject of particular attention during contract negotiation.
This end of relationship can be of two types, both because the contract reaches its term, or during a termination.
A. Contract Term
The contract ends because the service is completed: the data processing related to it therefore no longer has a purpose.
The clauses must provide for the fate of the data at the end of the contract. This is first of all necessary to allow operational management of internal policies regarding personal data. Without a "standardized" contractual commitment reflecting the internal personal data management policy, operational management (and therefore "real" compliance) becomes an even more arduous task. The objective being for the processor to limit, for example, the data retention period in order to avoid having to store "useless" data, which, beyond the associated costs, relieves them of their obligations as a processor concerning this data.
As an example, they will no longer have to, due to the deletion of the data, process any requests for rights transmitted by their data controller.
Obviously, it must be kept in mind that the law of the Union or of the Member State concerned may impose a minimum retention period for this data.
B. Contract Termination
If this is contractually provided for between the parties, non-compliance with contractual clauses can lead to the end of the contract, particularly through termination.
Below is a termination clause illustrating this:
"In case of non-compliance with these provisions, the Client may terminate this Contract automatically, without penalties and without prior notice, without prejudice to the possibility of requesting compensation for the damage suffered."
The insertion of such a clause is a real asset for the data controller, who will be able to free themselves from their obligations with their processor in case of non-compliance with contractual clauses relating to the GDPR.
Although compliance with the GDPR is obviously not an "option" for the processor, a GDPR clause imposing obligations on them beyond those of the GDPR could significantly jeopardize the sustainability of their relationship with their data controller. Thus, with such clauses, the data controller will be able to use these clauses to "exit" a processor without costs in case of non-compliance by the latter with contractual stipulations or to take advantage of this breach to drastically renegotiate the financial terms of the contract by threatening termination.
So let's remain vigilant! ?