Skip to main content

Service · Prevention

Let the contract say who answers, before a judge decides it

Almost no breach happens entirely inside your own house. If the allocation of liability is not in writing, the court will do it, and by default it will look at whoever decides about the data: you.

Your data does not sit only in your systems. It sits in the tool you licensed, in the service of the supplier that invoices on your behalf, in the platform that handles your deliveries. When something fails at one of those points, the first fight in the case is not about security: it is about who held which status at that specific point.

Contractual Liability Allocation turns that fight into a document you have already signed. We review and draft your Article 28 data processing agreements so that they say, without ambiguity, who answers for what in each system.

Who it is for

  • Companies that have outsourced parts of their operation and do not know, one by one, which suppliers access their customers' personal data.
  • Anyone working with inherited processing agreements, signed years ago on generic templates and never reviewed.
  • Anyone who has grown by adding tools and services without anyone keeping the map of who touches what.
  • Groups whose companies provide services to each other and have not formalised the internal allocation of roles.

If you are not sure where you stand, the second and third questions of the Breach Management Test measure exactly this.

What it includes, exactly

  1. Supplier map. Who accesses what data, for what purpose and in what capacity: controller, processor or sub-processor.
  2. Contract review. Examination of every contract in force to find where the allocation of liability does not exist, is ambiguous or works against you.
  3. Drafting or addendum. Processing clauses that set out each party's obligations, the duty to give notice of an incident and the deadline within which that notice must reach you.
  4. Sub-processing chain. Which suppliers yours may subcontract, with what authorisation and with what obligations passed down.
  5. Notification protocol. How an incident is communicated between the parties and what each of them documents, so that the trail exists from the first minute.
  6. Allocation register. A single, maintainable table that says at a glance who answers for which system.

Which rule it addresses

Rule B — Only the controller or the processor answers. The security obligations in Article 32 GDPR can be attributed only to whoever holds that status, and not to a third party outside it. The Madrid Provincial Court of Appeal ruled out the defendant's liability on that ground, and by the same reasoning ruled out that the state of the storage media could be attributed to it.

SAP Madrid 371/2023, of 28 July (Articles 28 and 32 GDPR)
[...] since it cannot be held proven that the defendant is the controller or the processor of the data, which is the party on whom the obligations that the claimant considers infringed are imposed, and it must be expressly noted that the fact that the USB sticks were unencrypted is not attributable to it either, for the same reasons. [translation]
Allocation in writing is not paperwork: it is the barrier that decides who sits in the dock.

With that allocation documented, part of the claim stops being yours before you even begin to argue it. Without it, you will also answer for what happened in a system you do not run.

Deliverables

  • Map of suppliers and of access, with the capacity of each one.
  • Contractual risk report: which contract leaves you exposed and why.
  • New data processing agreements or addenda ready for signature.
  • Incident notification protocol between the parties.
  • Liability allocation table, maintainable by your own team.

Indicative timescale

Between three and six weeks for a typical portfolio of suppliers. Negotiation with each supplier comes afterwards and at your own pace: we give you the text and the arguments to hold it.

The full reasoning, with the case law behind it, is in what a court really looks at after a breach.

Contractual Liability Allocation

Send us the list of suppliers that process data on your company's behalf and we will tell you where you are exposed today.

Talk to ILP Abogados
servicios/delimitacion-art28
Contractual Liability Allocation (Article 28) | ILP Abogados