Skip to main content

Rule B · Articles 28 and 32 GDPR

The data processing agreement decides who stands in the dock

Before arguing about what measures were in place, a court decides whose duty it was to have them.

When the claim arrives, the first question is not what measures were in place. It is who was obliged to have them. And that question is not answered by the reality of your systems: it is answered by a contract.

Security duties do not fall on everyone

Article 32 of the GDPR imposes measures on the controller and on the processor. On nobody else. Anyone who holds neither of those two capacities cannot infringe Article 32, however much data they may have had in front of them, because those duties were not attributable to them.

This is not a doctrinal subtlety. The Madrid Provincial Court of Appeal (Audiencia Provincial de Madrid) acquitted a defendant on exactly that reasoning, because it could not be taken as proven that it was either the controller or the processor.

SAP Madrid 371/2023, of 28 July
[...] since it cannot be taken as proven that the defendant is the controller or the processor, which is who the obligations said to have been infringed are attributed to, and it must be expressly noted that the fact that the USB sticks were unencrypted is likewise not attributable to it, for the same reasons [translation]

Look at the end of that paragraph. Not even the objective fact that the media were unencrypted was attributable to it. Not because it had been done well, but because the duty was not its own. That is the force of allocating roles, and it works in both directions.

The other direction: when the duty is indeed yours

If you are the controller, a breach that occurs in a supplier's system is still your problem. The data subject will claim against you, because you are the one they know and the one they contracted with. Whether you can later recover from the supplier what you have had to bear depends, once again, on what the contract says.

That is why the data processing agreement is not compliance paperwork. It is the document that decides who stands in the dock and who gives evidence as a witness. It is signed once and it governs everything that comes afterwards.

What you must set out in writing

  • Who is the controller and who is the processor in each processing operation, in those exact words.
  • The subject matter, duration and purpose of the processing, and which categories of data it covers.
  • Which security measures the processor takes on, and how it must be able to evidence them to you.
  • The duty to notify you of any breach, with a deadline in hours and a named recipient.
  • Who decides and who carries out the notification to the authority and to those affected.
  • Whether sub-processors are allowed, on what prior authorisation and under what identical duties.
  • What happens on termination: return or erasure of the data, with documentary evidence.
  • What you may audit, on what notice and within what period the information must be delivered.
  • The allocation of liability towards third parties and the right of recourse between the parties.

Not one of those nine points is technical. They are nine business decisions, and they are taken by whoever signs.

What happens when you do not set it out

Three things, and all three are bad. First: you answer for everything, because yours is the only capacity established on the file. Second: you cannot require the supplier to produce evidence of its measures, and without that evidence your own defence is lame. Third: when you finally do claim against it, you will argue about what the parties ‘understood’, which is the worst contractual position imaginable.

There is a fourth effect, less visible and more costly at the critical moment: with no written allocation you do not know who to call in the first hour. And the notification deadline starts running from the moment you become aware of the incident, not from the moment you manage to track down the right contact.

A supplier with no data processing agreement is not the supplier's risk: it is yours, and it is already running.

The map that comes before the contract

No contract is any use to you if you do not know how many contracts you need. Before reviewing clauses, draw up the list: which suppliers access your clients' data, which data, since when and under what signed document. In most mid-sized companies that list does not exist, and when it is drawn up, access appears that nobody remembered granting.

That map serves two purposes at once. It tells you where contracts are missing, and it lets you, on the day of the claim, point precisely to who handled what. Without it, the only available answer is ‘I do not know’, which before a court reads as a lack of control. The other points where that lack of control is paid for are in what a court looks at when the claim arrives.

Three frequent corrections

  1. The contract exists, but it is the supplier's template and it puts on you everything the supplier does not want to take on.
  2. The contract allocates responsibilities, but it does not oblige the supplier to hand you evidence; on the day of the case you have nothing with which to prove someone else's diligence.
  3. The contract is sound and unsigned, or signed by someone without sufficient authority. For evidential purposes, it is as if it did not exist.

Can I pass all liability to my supplier?

Not as against the person affected: if you are the controller, you answer to them. What the contract does govern is the internal allocation between you and the supplier, and that allocation decides who ultimately bears the consequences.

And if the supplier decides on its own how to process the data?

Then it may be acting as a controller, not as a processor, with duties of its own. The contract should reflect that reality, because what is examined is the actual function, not the label.

If you do not know how many of your data processing agreements would survive a formal request, the Breach Management Test will tell you in a few minutes.

Do your contracts say who answers?

Check whether you could prove the allocation of responsibilities with every supplier that accesses your clients' data.

Take the Breach Management Test
articulos/art28-quien-responde
Article 28 GDPR: who answers when there is a breach | ILP Abogados