Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Contact

What is a Data Processing Agreement (DPA) Playbook


Why is a DPA Necessary?

Legal compliance of all involved parties is the primary reason for DPAs. As a central pillar of operating business is processing personal data and exchanging it with other businesses, it is necessary for businesses to construct a lawful DPA with the party they exchange personal information with in order to avoid injustice and conflict of interest in the future.

GDPR doesn’t have legal restrictions on the form of the DPA, however, exceptionally in situations where the processor is located outside the EU and international data transfer happens, there are some specific requirements to the format of documentation, such as standard contractual clauses (SCC), binding corporate rules (BCR), etc. It is advised to have a DPA as a separate document for clarity and security.

Advertisement

Furthermore, a key benefit of DPA is risk minimisation referring to how your organisations can minimise the impact of data breaches or unauthorised access by having clear definitions of controller and processor roles. Additionally a DPA demonstrates how your organisation protects the rights of individuals hence having a strong emphasis on individual rights protection.

Similarly, building stakeholder trust is very crucial for data protection. DPAs aim to build this trust through transparency by including adequate security measures and data processing protocols. Moreover, with a comprehensive DPA, parties involved may enhance collaboration which strengthens efficient data processing. In general, DPAs can help support your long-term business relationships.

Additionally, according to Articles 28 through 36 of the GDPR, on an individual basis, if you exchange personal data with other parties, you should have a DPA in place.

Joint Controller’s Role in DPA

According to Article 26 of the GDPR, joint controllers are two or more controllers jointly determining the purposes and means of processing. Regardless of those arrangements, each controller remains responsible for complying with all the obligations of controllers under the GDPR.

  • Possess a transparent arrangement that sets out roles you have agreed upon and responsibilities.
  • Preferably, according to the European Data Protection Board (EDPB) recommends in its guidance to obtain a binding document such as a Joint Controller Agreement or other binding act under EU or Member State law to which the controllers are subject.
  • Include the requirement of making the Joint Controller Agreement available to data subjects your privacy policy, for increased transparency and accountability.

The Joint Controller Agreement must provide certainty and could be used to evidence transparency and accountability. Indeed, in case of non-compliance with the agreed allocation provided in the arrangement, its binding nature allows one controller to seek the liability of the other for what was stated in the Joint Controller Agreement as falling under its responsibility. The essence of such agreements should be made available to data subjects.

What EU Regulations Require DPAs?

Various EU regulations refer to data protection and DPAs. The following regulations refer to the obligation of signing DPAs or equivalent contracts, or otherwise are involved in data handling:

  • Law Enforcement Directive (EU) 2016/680 (LED)
  • European Data Protection Board (EDPB) guidance
  • Standard Contractual Clauses (SCCs)
  • EU Data Governance Act (EU) 2022/868
  • EU Data Act (Regulation (EU) 2023/2854)
  • Digital Services Act (DSA)
  • Digital Markets Act (DMA)

What Other Regulations Require DPAs?

Similarly, different countries have adopted the requirement of signing DPAs just like EU’s GDPR:

  • Brazil LGPD
  • Dubai PDPA
  • EU GDPR
  • South Africa POPIA
  • Thailand PDPA
  • UK GDPR
  • US California CCPA/CPRA
  • US Colorado CPA
  • US Connecticut DPA
  • US Virginia CDPA

International Transfers of Personal Data

For international trade and international cooperation, personal data must flow into and out of the European Union. A Third Country is any country outside the European Economic Area (the “EEA”), but the transfer of such personal data from the EU to controllers and processors located outside the EU should not reduce the level of protection of the individuals concerned. The General Data Protections Regulation Chapter V should therefore be strictly followed when transferring data to third countries or international organisations.

There are different basis for transfer available and they influence how the Data Processing Agreement is formulated.

Transfer Based on Adequacy Decision Covered by GDPR Article 45

The existence of an “adequacy decision” should be taken into account before transferring personal data to a third country. An adequacy decision means that the European Commission has determined that a third country or an international organization provides an adequate level of data protection.

The European Commission considers factors like laws, adherence to human rights and freedoms, national security, data protection authority, and legally binding agreements the country has made regarding data protection when determining whether the level of protection is adequate.

List of Countries that Provide Adequate Level of Personal Data Protection:

  • Andorra
  • Argentina
  • Canada (only for commercial organisations)
  • Faroe Islands
  • Guernsey
  • Israel
  • Isle of Man
  • Japan
  • Jersey
  • New Zealand
  • Republic of Korea (South Korea)
  • Switzerland
  • United Kingdom
  • Uruguay
  • United States (only for organisations participating in the EU-US Data Privacy Framework)

For those countries there is no requirement of providing additional safeguards and standard Data Processing Agreement can be used.

Transfers Subject to Appropriate Safeguards (GDPR Article 46)

If the country where the personal data is transferred does not have the Adequacy Decision, the data can still be transferred if the controller or processor has implemented appropriate safeguards. Such protections could be:

Standard Contractual Clauses (SCC)

The European Commission has approved these sample data protection clauses, which when incorporated into a Data Processing Agreement allow for the free flow of personal data. The SCCs include rights for the people whose personal data is transferred as well as contractual obligations for the Data Exporter and Data Importer. These rights are directly enforceable by individuals against the Data Importer and Data Exporter. Between a controller and another controller, there are two sets of standard contractual clauses for restricted transfers, and between a controller and a processor, there is only one set.

The European Commission has made updated Standard Contractual Clauses available on 4th of June 2021. Therefore, from December 2022, all organizations must use the 2021 SCCs for already existing and new transfers. Nevertheless, DPAs are expected to emphasise the necessity of TIAs, and where necessary supplementary safeguards in addition to SCCs in order to ensure compliance with GDPR, EDPB guidelines, and Schrems II judgement.

Binding Corporate Rules (BCR)

Binding Corporate Rules are internal codes of conduct that operate within a multinational group of companies and are legally binding. They are applicable to the transfers of personal data from the group’s EEA entities to its non-EEA entities. This group could be a corporation or a collection of businesses that are involved in a joint economic activity, like joint ventures or franchises. BCRs are legally binding data protection rules that have been authorised by the relevant Data Protection Authority.

Two different BCR types may be approved: BCR for Controllers, which group entities use to transfer data under their control, like employee or supplier information, and BCR for Processors, which are used by organizations that act as processors for other controllers and are typically added as an addendum to the Service Agreement or Data Processing Agreement. Additional guidelines for the use of BCRs as a suitable safeguard for personal data transfers are provided in GDPR Article 47.

Approved Codes of Conduct

The GDPR’s Article 40 (3) introduced the use of Codes of Conduct as a transfer mechanism in certain situations. Codes, which are optional, specify specific data protection guidelines for various controller and processor categories. They can be a useful and effective accountability tool, providing a thorough explanation of the most appropriate, ethical, and legal behavior within a sector.

Therefore, from the perspective of data protection, codes can serve as a guide for controllers and processors who create and carry out GDPR-compliant data processing activities that give practical meaning to the data protection principles outlined in European and national law.

Codes of Conduct that are applicable to the processing of personal data by controllers and processors in more than one EU Member State and for which the EU Commission has adopted an implementing act, along with legally-binding agreements made by the controller or processor in the third country, may be used as a transfer tool.

Approved Certification Mechanisms

The Article 42(2) of the GDPR states that certification mechanisms may be created to show the existence of suitable safeguards provided by controllers and processors in third countries. Additionally, these controllers and processors would agree to adhere to the safeguards, which would include provisions for data subject rights.

Legally binding and enforceable instruments with public authorities or international organisations

According to Article 46 (2)(a) of GDPR, a restricted transfer may be made by an organisation if it is one public authority or body transferring to another public authority or body. This agreement or other document must contain enforceable rights and practical resources for the people whose personal data is transferred. This is not a suitable safeguard if either the receiving organisation or the sending organisation is a private entity or an individual. A public authority or body may consider an administrative arrangement that includes enforceable and effective individual rights as an alternative if it lacks the authority to enter into legally binding and enforceable agreements (Article 46 (3)(b) of GDPR).

Derogations for specific situations (Article 49 of GDPR)

Derogations under Article 49 are exceptions to the general rule that states that personal data may only be transferred to a third country if that country offers an adequate level of protection. Before using the derogations allowed by Article 49 (1), a Data Exporter should first try to frame transfers with one of the mechanisms guaranteeing adequate safeguards listed above. These exemptions or derogations permit transfers in certain circumstances, such as those based on consent, for the performance of a contract, for the assertion of legal claims, to safeguard the data subject’s vital interests when they are unable to give consent, or for significant public interest considerations. Additionally, the EDPB emphasises that these derogations can be used for systematic or large-scale transfers, hence they are strictly exceptional and considered in case-specific situations.





Source link

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Advertisement
D P3 Sh.p.k.
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.