Just when you thought you had mastered compliance with Australian privacy law, one of your customers in the European Union (EU) requests that you consider requirements under the General Data Protection Regulation (GDPR).

This article will:

  • explain when the GDPR applies; 
  • outline the GDPR’s requirements for processors and for controllers; and
  • provide some practical tips for compliance.

What Is the GDPR and When Does It Apply?

The GDPR is an EU regulation that regulates how businesses handle the personal data of individuals. They apply to businesses which satisfy the following two criteria.

1. An EU Link

For GDPR to apply to your business, you must either:

  • have an establishment in the EU; or
  • offer goods or services or target your goods or services to EU-based individuals. For example, you may accept payment in Euros, or have a website in the language of an EU member state; or
  • monitor the behaviour of EU-based individuals, such as monitoring the behaviour of EU individuals through payroll software.

2. Processor or Controller Status

Your business must also fall into one of the following categories:

  • controller: A controller is a business that determines how users’ personal data will be used. For example, an e-commerce business may use personal data to send marketing emails to their customers;
  • processor: A processor is a business that processes personal data on behalf of a controller. For example, Mailchimp holds personal data for e-commerce businesses that send marketing emails to their customers;
  • processor and controller: A business may act in both roles. For example, Mailchimp may also send marketing emails to their own customers.

A processor must comply with the GDPR even if they do not process the personal data within the EU.

Why Does My Customer Want Me to Comply With the GDPR?

If You Are a Processor

By servicing an EU-based customer, you may become a processor. If you are a processor, your EU-based customers may be concerned with some of your GDPR requirements in order to comply with theirs. 

For example, customers who are controllers have an obligation to make sure the personal data they handle is secure. This includes when processors, such as yourself, handle data. 

Controllers are liable if a processor handles data inconsistently with the GDPR – unless it can be shown that the controller was not in any way responsible. To ensure the processor’s compliance, controllers must sign a data processing agreement with processors which sets out the parties’ obligations.

By Request

You may also choose to comply with the GDPR because your customers request it and it makes commercial sense to do so. 

For example, you may operate a business in Australia and work only with Australian customers. You may not process or control any information about EU individuals. 

However, your customer may prefer you to comply with GDPR requirements:

  • because it believes you are a processor;
  • as a precaution; 
  • to observe an internal policy; or 
  • to comply with best practice.

Privacy compliance can be onerous; you should weigh up the cost of compliance against the benefit of your relationship with your customer.

What Are Your Requirements Under the GDPR?

If you are a processor, the GDPR requires your data processing agreement to include, and for you to comply with, the following statements that you as a processor, will:

  • take appropriate measures to ensure the security of processing;
  • keep records of processing activities;
  • only engage sub-processors with the prior consent of the controller and under a written contract;
  • promptly notify the data controller of any data breaches after becoming aware of the personal data breach;
  • cooperate with supervisory authorities;
  • only act on the written instructions of the controller;
  • ensure that people processing the data are subject to a duty of confidence to keep the information confidential;
  • assist the controller in providing data subjects with access and allowing data subjects to exercise their rights under the GDPR;
  • assist the controller in meeting its GDPR obligations in relation to the security of processing and data protection impact assessments;
  • delete or return all personal data to the controller as requested at the end of the contract;
  • submit to audits and inspections; and
  • provide the controller with whatever information it needs to ensure the company and controller are both meeting their Article 28 obligations. Here, tell the controller immediately if it is asked to do something infringing the GDPR or other data protection law of the EU or a member state.

It is best practice to prepare your own data processing agreement to ensure you understand what you agree to. If your customer supplies the agreement, it is important to ensure that you understand your obligations under the agreement and how they work in practice. 

Key Takeaways

EU-based companies are increasingly requiring non-EU-based service providers to comply with GDPR requirements. If you are a processor, your customer may require you to sign and comply with a data processing agreement in order to comply with its own requirements under the GDPR. Even if you are not legally required to, you may choose to comply with your customers’ demands for commercial purposes. You should ensure that you understand these obligations before committing to them, especially as privacy costs can be onerous relative to the commercial gain. If you have any questions, get in touch with LegalVision’s IT lawyers on 1300 544 755 or fill out the form on this page.

COVID-19 Business Survey
LegalVision is conducting a survey on the impact of COVID-19 for businesses across Australia. The survey takes 2 minutes to complete and all responses are anonymous. We would appreciate your input. Take the survey now.

About LegalVision: LegalVision is a tech-driven, full-service commercial law firm that uses technology to deliver a faster, better quality and more cost-effective client experience.

The majority of our clients are LVConnect members. By becoming a member, you can stay ahead of legal issues while staying on top of costs. For just $199 per month, membership unlocks unlimited lawyer consultations, faster turnaround times, free legal templates and members-only discounts.

Learn more about LVConnect

Nathalie King
Need Legal Help? Get a Free Fixed-Fee Quote

If you would like to receive a free fixed-fee quote or get in touch with our team, fill out the form below.

  • By submitting this form, you agree to receive emails from LegalVision and can unsubscribe at any time. See our full Privacy Policy.
  • This field is for validation purposes and should be left unchanged.
Our Awards
  • 2019 Top 25 Startups - LinkedIn 2019 Top 25 Startups - LinkedIn
  • 2019 NewLaw Firm of the Year - Australian Law Awards 2019 NewLaw Firm of the Year - Australian Law Awards
  • 2020 Fastest Growing Law Firm - Financial Times APAC 500 2020 Fastest Growing Law Firm - Financial Times APAC 500
  • 2020 AFR Fast 100 List - Australian Financial Review 2020 AFR Fast 100 List - Australian Financial Review
  • 2020 Law Firm of the Year Finalist - Australasian Law Awards 2020 Law Firm of the Year Finalist - Australasian Law Awards
  • Most Innovative Law Firm - 2019 Australasian Lawyer 2019 Most Innovative Firm - Australasian Lawyer
Privacy Policy Snapshot

We collect and store information about you. Let us explain why we do this.

What information do you collect?

We collect a range of data about you, including your contact details, legal issues and data on how you use our website.

How do you collect information?

We collect information over the phone, by email and through our website.

What do you do with this information?

We store and use your information to deliver you better legal services. This mostly involves communicating with you, marketing to you and occasionally sharing your information with our partners.

How do I contact you?

You can always see what data you’ve stored with us.

Questions, comments or complaints? Reach out on 1300 544 755 or email us at info@legalvision.com.au

View Privacy Policy