ANALYSISMEMBER

Controllers, processors and subprocessors in chains

Published
Subscribe to IAPP Newsletters

Contributors:

Ruth Boardman

Partner, Co-head, International Data Protection Practice

Bird & Bird LLP

On 7 Oct., the European Data Protection Board adopted Opinion 22/2024 "on certain obligations following from the reliance on processor(s) and sub-processor(s)."  It works through a number of tricky areas affecting controller-processor-subprocessor relationships.

According to the EDPB, processors must provide details of every subprocessor down the chain to the ultimate controller, along with associated information about processing. Further, the opinion explains the controller has an obligation to check that all of these can meet GDPR obligations. This is true irrespective of the risk posed by the processing, although it may affect the extent of verification carried out by the controller. The controller must also check for safeguards in the case of onward transfers.

The opinion also provides the language in contracts that allow processors to process data as instructed by the controller or as required by law applicable to the processor, which does not cut through the issue for the processor — but neither is the language offensive as a matter of principle. As this point occurs in almost every Article 28 agreement, it is considered first in the more detailed note below.

Although the opinion goes to great lengths to underline that ultimate responsibility rests on the controllers, in practice controllers will only be able to operationalize these obligations if processors provide them with the necessary information and tools. There is much for processors, as well as for controllers, to do here.

Following instructions unless applicable law requires otherwise

Contributors:

Ruth Boardman

Partner, Co-head, International Data Protection Practice

Bird & Bird LLP

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership