Table of Contents
Just when you thought you had mastered compliance with Australian privacy law, one of your customers in the European Union (EU) requests that you consider requirements under the General Data Protection Regulation (GDPR).
This article will:
- explain when the GDPR applies;
- outline the GDPR’s requirements for processors and for controllers; and
- provide some practical tips for compliance.
What is the GDPR and When Does It Apply?
The GDPR is an EU regulation that regulates how businesses handle the personal data of individuals. They apply to businesses which satisfy the following two criteria.
1. An EU Link
For GDPR to apply to your business, you must either:
- have an establishment in the EU; or
- offer goods or services or target your goods or services to EU-based individuals. For example, you may accept payment in Euros, or have a website in the language of an EU member state; or
- monitor the behaviour of EU-based individuals, such as monitoring the behaviour of EU individuals through payroll software.
2. Processor or Controller Status
Your business must also fall into one of the following categories:
- controller: A controller is a business that determines how users’ personal data will be used. For example, an e-commerce business may use personal data to send marketing emails to their customers;
- processor: A processor is a business that processes personal data on behalf of a controller. For example, Mailchimp holds personal data for e-commerce businesses that send marketing emails to their customers;
- processor and controller: A business may act in both roles. For example, Mailchimp may also send marketing emails to their own customers.
A processor must comply with the GDPR even if they do not process the personal data within the EU.
Why Does My Customer Want Me to Comply With the GDPR?
If You Are a Processor
By servicing an EU-based customer, you may become a processor. If you are a processor, your EU-based customers may be concerned with some of your GDPR requirements in order to comply with theirs.
Controllers are liable if a processor handles data inconsistently with the GDPR – unless it can be shown that the controller was not in any way responsible. To ensure the processor’s compliance, controllers must sign a data processing agreement with processors which sets out the parties’ obligations.
You may also choose to comply with the GDPR because your customers request it and it makes commercial sense to do so.
However, your customer may prefer you to comply with GDPR requirements:
- because it believes you are a processor;
- as a precaution;
- to observe an internal policy; or
- to comply with best practice.
Privacy compliance can be onerous; you should weigh up the cost of compliance against the benefit of your relationship with your customer.
Requirements Under the GDPR
If you are a processor, the GDPR requires your data processing agreement to include, and for you to comply with, the following statements that you as a processor, will:
- take appropriate measures to ensure the security of processing;
- keep records of processing activities;
- only engage sub-processors with the prior consent of the controller and under a written contract;
- promptly notify the data controller of any data breaches after becoming aware of the personal data breach;
- cooperate with supervisory authorities;
- only act on the written instructions of the controller;
- ensure that people processing the data are subject to a duty of confidence to keep the information confidential;
- assist the controller in providing data subjects with access and allowing data subjects to exercise their rights under the GDPR;
- assist the controller in meeting its GDPR obligations in relation to the security of processing and data protection impact assessments;
- delete or return all personal data to the controller as requested at the end of the contract;
- submit to audits and inspections; and
- provide the controller with whatever information it needs to ensure the company and controller are both meeting their Article 28 obligations. Here, tell the controller immediately if it is asked to do something infringing the GDPR or other data protection law of the EU or a member state.
It is best practice to prepare your own data processing agreement to ensure you understand what you agree to. If your customer supplies the agreement, it is important to ensure that you understand your obligations under the agreement and how they work in practice.
EU-based companies are increasingly requiring non-EU-based service providers to comply with GDPR requirements. If you are a processor, your customer may require you to sign and comply with a data processing agreement to comply with its own requirements under the GDPR. Even if you are not legally required to, you may choose to comply with your customers’ demands for commercial purposes. You should ensure that you understand these obligations before committing to them, especially as privacy costs can be onerous relative to the commercial gain.
For more information on your business obligations, our experienced privacy lawyers can assist as part of our LegalVision membership. For a low monthly fee, you will have unlimited access to lawyers to answer your questions and draft and review your documents. Call us today on 1300 544 755 or visit our membership page.
We appreciate your feedback – your submission has been successfully received.