Reading time: 5 minutes

Just when you thought you had mastered compliance with Australian privacy law, one of your customers in the European Union (EU) requests that you consider requirements under the General Data Protection Regulation (GDPR).

This article will:

  • explain when the GDPR applies; 
  • outline the GDPR’s requirements for processors and for controllers; and
  • provide some practical tips for compliance.

What Is the GDPR and When Does It Apply?

The GDPR is an EU regulation that regulates how businesses handle the personal data of individuals. They apply to businesses which satisfy the following two criteria.

1. An EU Link

For GDPR to apply to your business, you must either:

  • have an establishment in the EU; or
  • offer goods or services or target your goods or services to EU-based individuals. For example, you may accept payment in Euros, or have a website in the language of an EU member state; or
  • monitor the behaviour of EU-based individuals, such as monitoring the behaviour of EU individuals through payroll software.

2. Processor or Controller Status

Your business must also fall into one of the following categories:

  • controller: A controller is a business that determines how users’ personal data will be used. For example, an e-commerce business may use personal data to send marketing emails to their customers;
  • processor: A processor is a business that processes personal data on behalf of a controller. For example, Mailchimp holds personal data for e-commerce businesses that send marketing emails to their customers;
  • processor and controller: A business may act in both roles. For example, Mailchimp may also send marketing emails to their own customers.

A processor must comply with the GDPR even if they do not process the personal data within the EU.

Why Does My Customer Want Me to Comply With the GDPR?

If You Are a Processor

By servicing an EU-based customer, you may become a processor. If you are a processor, your EU-based customers may be concerned with some of your GDPR requirements in order to comply with theirs. 

For example, customers who are controllers have an obligation to make sure the personal data they handle is secure. This includes when processors, such as yourself, handle data. 

Controllers are liable if a processor handles data inconsistently with the GDPR – unless it can be shown that the controller was not in any way responsible. To ensure the processor’s compliance, controllers must sign a data processing agreement with processors which sets out the parties’ obligations.

By Request

You may also choose to comply with the GDPR because your customers request it and it makes commercial sense to do so. 

For example, you may operate a business in Australia and work only with Australian customers. You may not process or control any information about EU individuals. 

However, your customer may prefer you to comply with GDPR requirements:

  • because it believes you are a processor;
  • as a precaution; 
  • to observe an internal policy; or 
  • to comply with best practice.

Privacy compliance can be onerous; you should weigh up the cost of compliance against the benefit of your relationship with your customer.

What Are Your Requirements Under the GDPR?

If you are a processor, the GDPR requires your data processing agreement to include, and for you to comply with, the following statements that you as a processor, will:

  • take appropriate measures to ensure the security of processing;
  • keep records of processing activities;
  • only engage sub-processors with the prior consent of the controller and under a written contract;
  • promptly notify the data controller of any data breaches after becoming aware of the personal data breach;
  • cooperate with supervisory authorities;
  • only act on the written instructions of the controller;
  • ensure that people processing the data are subject to a duty of confidence to keep the information confidential;
  • assist the controller in providing data subjects with access and allowing data subjects to exercise their rights under the GDPR;
  • assist the controller in meeting its GDPR obligations in relation to the security of processing and data protection impact assessments;
  • delete or return all personal data to the controller as requested at the end of the contract;
  • submit to audits and inspections; and
  • provide the controller with whatever information it needs to ensure the company and controller are both meeting their Article 28 obligations. Here, tell the controller immediately if it is asked to do something infringing the GDPR or other data protection law of the EU or a member state.

It is best practice to prepare your own data processing agreement to ensure you understand what you agree to. If your customer supplies the agreement, it is important to ensure that you understand your obligations under the agreement and how they work in practice. 

Key Takeaways

EU-based companies are increasingly requiring non-EU-based service providers to comply with GDPR requirements. If you are a processor, your customer may require you to sign and comply with a data processing agreement in order to comply with its own requirements under the GDPR. Even if you are not legally required to, you may choose to comply with your customers’ demands for commercial purposes. You should ensure that you understand these obligations before committing to them, especially as privacy costs can be onerous relative to the commercial gain. If you have any questions, get in touch with LegalVision’s IT lawyers on 1300 544 755 or fill out the form on this page.

Webinars

Raising Capital: Getting Investment Ready

Tuesday 6 April | 12:00 - 12:45pm

Online
Are you a founder or business owner looking to raise capital? Attend this webinar to learn the strategies to prepare your business for investment.
Register Now

The COVID-19 Vaccine Rollout: Considerations for Employers

Thursday 22 April | 11:00 - 11:45am

Online
Are you a business owner or employer? Attend this webinar to learn about what you need to know about the COVID-19 vaccine rollout.
Register Now

About LegalVision: LegalVision is a tech-driven, full-service commercial law firm that uses technology to deliver a faster, better quality and more cost-effective client experience.

The majority of our clients are LVConnect members. By becoming a member, you can stay ahead of legal issues while staying on top of costs. From just $119 per week, get all your contracts sorted, trade marks registered and questions answered by experienced business lawyers.

Learn more about LVConnect

Need Legal Help? Get a Free Fixed-Fee Quote

If you would like to receive a free fixed-fee quote or get in touch with our team, fill out the form below.

  • 2020 Excellence in Technology & Innovation – Finalist – Australasian Law Awards 2020 Excellence in Technology & Innovation Finalist – Australasian Law Awards
  • 2020 Employer of Choice – Winner – Australasian Lawyer 2020 Employer of Choice Winner – Australasian Lawyer
  • 2020 Fastest Growing Law Firm - Financial Times APAC 500 2020 Fastest Growing Law Firm - Financial Times APAC 500
  • 2020 AFR Fast 100 List - Australian Financial Review 2020 AFR Fast 100 List - Australian Financial Review
  • 2020 Law Firm of the Year Finalist - Australasian Law Awards 2020 Law Firm of the Year Finalist - Australasian Law Awards
  • Most Innovative Law Firm - 2019 Australasian Lawyer 2019 Most Innovative Firm - Australasian Lawyer