Every cloud service that processes personal data must have a Data Processing Agreement (DPA) compliant with GDPR Article 28. Such agreements are crucial for ensuring that data processors adhere to the GDPR's stringent requirements. This guide outlines the mandatory clauses, sub-processor management, audit rights, and the use of Standard Contractual Clauses (SCCs) for non-EU providers.
Every cloud service that processes personal data must have a Data Processing Agreement (DPA) compliant with GDPR Article 28. Such agreements are crucial for ensuring that data processors adhere to the GDPR's stringent requirements. This guide outlines the mandatory clauses, sub-processor management, audit rights, and the use of Standard Contractual Clauses (SCCs) for non-EU providers.
GDPR Article 28: Mandatory DPA Requirements
GDPR Article 28 sets out specific requirements that must be included in a Data Processing Agreement. These requirements ensure that the processor acts only on the controller's instructions and provides sufficient guarantees to implement appropriate technical and organizational measures.
Eight Essential Clauses
- 1Processing Instructions: The processor must process personal data only on documented instructions from the controller.
- 2Confidentiality: Individuals authorized to process the data must commit to confidentiality.
- 3Security Measures: The processor must implement appropriate technical and organizational measures to ensure data security.
- 4Sub-processing: The processor cannot engage another processor without prior specific or general written authorization of the controller.
- 5Data Subject Rights: The processor must assist the controller in fulfilling data subject rights.
- 6Data Breach Notification: The processor must notify the controller without undue delay after becoming aware of a personal data breach.
- 7Data Deletion or Return: Upon termination of the processing services, the processor must delete or return all personal data to the controller.
- 8Audit and Inspection: The processor must make available all information necessary to demonstrate compliance and allow for audits.
Defining Processing: Subject Matter, Duration, Nature, and Purpose
A DPA must clearly articulate the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data, and the categories of data subjects involved. This clarity ensures that both parties have a mutual understanding of the processing activities and their scope.
Key Considerations
- Subject Matter: Define the specific data processing tasks to be undertaken.
- Duration: Specify the length of time the processing will occur.
- Nature and Purpose: Clearly state why the processing is necessary and what it entails.
- Data Types and Subjects: Identify the types of personal data processed and the categories of data subjects.
Sub-processor Management: Authorization, Notification, Flow-down
Effective sub-processor management is critical to maintaining GDPR compliance. Controllers must ensure that processors manage sub-processors appropriately.
Authorization and Notification
- Authorization: Controllers can provide either specific or general written authorization for sub-processors. General authorization requires the processor to inform the controller of any intended changes, giving the controller the opportunity to object.
- Notification: Processors must notify controllers of any changes to sub-processors, allowing for objections based on legitimate reasons.
Flow-down Obligations
Processors must ensure that any sub-processors are bound by the same data protection obligations as those set out in the DPA, ensuring a consistent level of protection throughout the processing chain.
Audit Rights: Conducting or Accepting Third-party Audits
Audit rights are a fundamental aspect of ensuring compliance with GDPR requirements. Controllers must have the ability to verify that processors are adhering to their obligations.
Conducting Audits
Controllers can conduct audits themselves or engage third-party auditors. These audits should be reasonable in scope and frequency, taking into account the nature of the processing.
Accepting Third-party Audits
In some cases, processors may offer third-party audit certifications or reports as a means of demonstrating compliance. Controllers should assess whether these reports are sufficient to meet their audit requirements.
Standard Contractual Clauses (SCCs) for Non-EU Cloud Providers
When engaging non-EU cloud providers, controllers must ensure that personal data transferred outside the EU is adequately protected. SCCs are a key mechanism for achieving this.
Implementing SCCs
- Relevance: SCCs provide a legal framework for data transfers to non-EU countries, ensuring compliance with GDPR.
- Adoption: Controllers must incorporate SCCs into their DPAs with non-EU processors to safeguard data transfers.
DPA Checklist for AWS, Azure, GCP, and SaaS Products
When drafting DPAs for cloud services like AWS, Azure, GCP, and SaaS products, controllers should ensure that all GDPR Article 28 requirements are met.
Key Elements
- Comprehensive Coverage: Ensure all mandatory clauses are included.
- Customization: Tailor the DPA to reflect the specific processing activities and risks associated with each service.
- Regular Updates: Review and update DPAs regularly to reflect changes in processing activities or regulatory requirements.
Consequences of Non-compliant DPAs: Enforcement Examples
Non-compliance with GDPR Article 28 can result in significant penalties and reputational damage. Regulators have imposed fines on organizations for inadequate DPAs, underscoring the importance of compliance.
Enforcement Actions
- Fines: Controllers and processors may face fines up to 10 million EUR or 2% of global turnover for non-compliance.
- Reputational Damage: Beyond financial penalties, non-compliance can lead to loss of customer trust and damage to brand reputation.
Next Step with NexCyber
Ensuring GDPR compliance is critical for cloud services processing personal data. NexCyber offers comprehensive tools and guidance to help you assess and enhance your data processing agreements. Visit [NexCyber](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=gdpr-article-28-processor-agreements-cloud) to learn how we can support your compliance journey.