Expertise Technical assistanceProject managementCustom solutions Industries BankingInsuranceFinance Approach Commitments Insights About Join Pronaxis
Contact us Français

GDPR and IT providers: who does what?

Controller, processor, Article 28 clauses, sub-processors, breaches, end of engagement: how roles are shared with an IT provider under the GDPR.

Pronaxis9 October 20265 min read

As soon as an IT provider works on a system containing personal data, the General Data Protection Regulation (GDPR) applies to the relationship. In a bank or an insurer, this is almost always the case: data about customers, beneficiaries, employees, prospects.

The starting question is simple to ask: who is responsible for what? This article goes through the key concepts and the points to check in a services contract.

Controller and processor

The GDPR distinguishes two main roles.

The controller determines the purposes and means of processing. It decides why the data is processed and, in essence, how. In a relationship between a bank and its provider, this is generally the bank.

The processor processes personal data on behalf of the controller, on its instructions. A provider that develops, maintains or operates an application containing personal data often falls into this category.

The qualification depends on the facts, whatever the contract is called. A provider that decided on its own to use the data for its own purposes would step outside the processor role for that processing, with the responsibilities that follow. The GDPR also covers joint controllers, where two organisations jointly determine the purposes and means.

The French data protection authority, the CNIL, has published a guide for processors that explains these concepts and is a useful reference for both parties.

The Article 28 contract

When a controller uses a processor, Article 28 of the GDPR requires a contract, or another legal act, governing the processing. It sets out the subject matter and duration of the processing, its nature and purpose, the type of personal data and the categories of data subjects.

It must also provide that the processor:

  • processes the data only on documented instructions from the controller;
  • ensures that persons authorised to process the data are bound by confidentiality;
  • implements the security measures required by Article 32;
  • respects the conditions for engaging another processor;
  • assists the controller in responding to requests from data subjects exercising their rights;
  • assists the controller with its obligations on security, breach notification and impact assessments;
  • deletes or returns the data at the end of the service;
  • makes available the information needed to demonstrate compliance and allows for audits.

The processor must also immediately inform the controller if, in its opinion, an instruction infringes the GDPR.

Sub-processors

A provider may itself rely on others: an independent consultant, another company, a hosting or tooling provider. When they process the client’s data, they are sub-processors.

The GDPR sets conditions for this:

  • the processor may not engage one without the controller’s prior written authorisation, specific or general;
  • under a general authorisation, it informs the controller of any intended change, and the controller can object;
  • the same data protection obligations are imposed on the sub-processor by contract;
  • the initial processor remains fully liable to the controller for the performance of those obligations.

For a buyer, the question to ask is direct: apart from the consultant put forward, who will have access to the data?

Breach notification

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

The obligations are divided as follows:

  • the processor notifies the controller without undue delay after becoming aware of the breach;
  • the controller notifies the supervisory authority (the CNIL in France) without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals;
  • where the risk is high, the controller also informs the data subjects, subject to the exceptions provided for.

The contract should specify the channel, the contacts and the expected content of the processor’s notification. In the financial sector, other incident reporting regimes may apply in parallel, such as DORA’s for ICT-related incidents.

End of the engagement

At the end of the service, the processor must, at the controller’s choice, delete all personal data or return it, and delete existing copies, unless Union or Member State law requires them to be kept.

In a technical assistance engagement, this concretely covers:

  • access to applications and environments, to be revoked;
  • equipment supplied by the client, to be returned;
  • any files on the provider’s workstations or storage, to be deleted;
  • communications containing data, to be handled according to the agreed rules.

We recommend formalising this step with a checklist and a deletion certificate given to the client.

The processor’s other obligations

The processor also has obligations of its own. It keeps a record of the categories of processing activities carried out on behalf of its clients. It appoints a data protection officer where the conditions of Article 37 are met. It ensures that any transfer of data outside the European Union complies with Chapter V of the GDPR.

What we apply

In our engagements, our consultants work within the client’s environment, on its equipment or access, and according to its instructions. We do not take data out of that environment. We give advance notice of any use of another contributor, and we organise the end of each engagement so that access and data are handled in a verifiable way.

This article sets out the general framework. The precise qualification of roles and the drafting of clauses are matters for your legal teams and your data protection officer.

All insights Français

A project, a team to reinforce, a question?

Tell us what you need. Our management team will reply.