What is then most logical way of applying the controller and processor roles to an outsourcing relationship?
To treat the customer as the controller an the supplier as the processor.
What are the practical implications of treating the controller as the customer and the supplier as the processor in an outsourcing relationship?
Aside from the strict contractual relationship, the GDPR establishes 13 direct legal obligations for processors. These obligations exist irrespective of an outsourcing contract’s contractual provisions. List the 13 obligations.
Under Article 27 of the GDPR, a non-EU processor that falls within the scope of the GDPR doesn’t need to appoint an EU rep if the processing meets what 3 criteria?
The processing is
1. Occasional
2. Doesn’t include on a large scale processing of special categories of data or personal data relating to criminal convictions and offenses
3. And is unlikely to result in a risk to the rights and freedoms of individuals
The written record obligation imposed on processors under Article 30(2) doesn’t apply if a processor employs fewer than 250 employees unless one of what 3 conditions is present?
The processing conducted
1. Is likely to result in a risk to the rights and freedoms of data subjects
2. Isn’t occasional
3. Or includes special categories of data referred to in Article 9(1) or personal data relating to criminal convictions and offenses referred to in Article 10
Under Article 32 of the GDPR, a processor must implement appropriate technical and organizational security measures relative to the risks that arise from processing to ensure personal data is protected. These measures can include what 4 things?
Under Article 37 of the GDPR, what 2 circumstances require a processor to appoint a DPO?
Under Article 38 of the GDPR, a processor must ensure what 3 things for their DPO?
In an outsourcing relationship is it common for the supplier to take an active role in making certain decisions about the processing?
Yes, due to their expertise however they can’t go beyond their mandate from the customer, i.e. the controller
For suppliers that use AI to provide their services, what is the crucial factor when determining whether the development of AI is undertaken in a processor capacity?
The extent to which a supplier may or may not have an interest in the underlying personal data used for AI development purposes other than to provide services to its clients.
Modern outsourcing is hardly ever limited to a relationship between two parties. Describe the 3 part model outsourcing arrangements generally follow.
Vetting employees is an obligation linked to organizational security measures. This obligation may require to the supplier to ensure what 3 things?
In addition to the basic obligations previously set out under the GDPR the outsourcing contract must include provisions that require the supplier to do what 6 things?
Where the outsourcing relationship is likely to involve a chain of processors and subprocesors the contract between the controller entering into the outsourcing contract and the main supplier should take place subject to what 4 conditions?