The GDPR (Regulation (EU) 2016/679)
Reaches every agreement with a customer in the EU or EEA whose row names personal data: the processor terms of Art. 28(3), the confidentiality and instruction duties of Art. 29, the security duty of Art. 32 it points to, the breach duty of Art. 33, and, where the data leaves the EEA and the United Kingdom, the transfer rules of Art. 44 and 46.
On the register, tick "GDPR" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: GDPR (Regulation (EU) 2016/679).
What it expects, term by term
| processor terms | Art. 28 · Art. 29 · Art. 32Where the row names personal data the supplier handles |
|---|---|
| audit right | Art. 28On an ICT service arrangement, or where processor terms are expected |
| breach clock | Art. 33Where the row names personal data |
| transfer terms | Art. 44 · Art. 46Where personal data leaves the EEA and the United Kingdom for the supplier's home |
The clauses, quoted
6Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.
GDPR Art. 28 ProcessorUse only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.
Where it usually falls short: The processor's own standard terms accepted, which commonly omit the audit right, the deletion choice and the instruction infringement notice
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 29 Processing under the authority of the controller or processorThe processor, and any person acting under the authority of the controller or of the processor who has access to personal data, must not process that data except on instructions from the controller, unless required to do so by Union or Member State law.
Where it usually falls short: Instructions existing only as the original contract, never updated as the processing changed over years of service
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 32 Security of processingImplement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. Assess the appropriate level of security against the risks presented by the processing, in particular accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. Take steps to ensure that any person acting under the controller's or processor's authority who has access to personal data processes it only on instructions.
Where it usually falls short: Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 33 Notification of a personal data breach to the supervisory authorityOn becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made later than 72 hours must be accompanied by the reasons for the delay. A processor must notify its controller without undue delay after becoming aware of a breach. The notification must at least describe the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, give the name and contact details of the data protection officer or other contact point, describe the likely consequences, and describe the measures taken or proposed including any measures to mitigate adverse effects. Information may be provided in phases where it cannot all be given at once. Document every personal data breach, including the facts, its effects and the remedial action taken, so the supervisory authority can verify compliance with this Article.
Where it usually falls short: The awareness clock started at the end of the investigation rather than at the point of reasonable certainty that a breach had occurred
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 44 General principle for transfersTransfer personal data undergoing processing, or intended for processing after transfer, to a third country or an international organisation only where the conditions laid down in Chapter V are complied with by the controller and the processor, including for onward transfers from that third country or international organisation to another third country or international organisation. Apply all the provisions of Chapter V so that the level of protection of natural persons guaranteed by the Regulation is not undermined.
Where it usually falls short: Remote support access, cloud administration and follow the sun operations from third countries never recognised as transfers at all
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
GDPR Art. 46 Transfers subject to appropriate safeguardsIn the absence of an adequacy decision, transfer personal data to a third country or an international organisation only where the controller or processor has provided appropriate safeguards and on condition that enforceable data subject rights and effective legal remedies are available. Safeguards requiring no specific authorisation are a legally binding and enforceable instrument between public authorities or bodies, binding corporate rules under Article 47, standard data protection clauses adopted by the Commission, standard clauses adopted by a supervisory authority and approved by the Commission, an approved code of conduct together with binding and enforceable commitments from the recipient to apply the safeguards including as to data subject rights, or an approved certification mechanism with the same commitments. Subject to authorisation from the competent supervisory authority, safeguards may also be provided by contractual clauses between the parties or by provisions inserted into administrative arrangements between public authorities that include enforceable and effective data subject rights.
Where it usually falls short: Standard clauses signed with the annexes unfilled, so the data, the purposes and the security measures the clauses are meant to bind are left undefined
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
See what it expects of your list
Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.
Check my contract list