Please note: The deadline for bringing existing contracts into compliance with the GDPR is approaching.

Date
May 5, 2022

It will soon be four years since the General Data Protection Regulation (GDPR or the Regulation) has been fully in effect. Specifically, on May 25, 2022. This will certainly be a good time for companies to assess their progress and their actual compliance status, if they have not already done so over the past few years.

But that date also marks the end of a grace period that, according to some interpretations, was granted to us by our Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (LOPD GDD). And I say it was granted to us because, unlike the Regulation itself—which says nothing expressly on the matter— Transitional Provision 5 of our national law established that data processor agreements entered into prior to the GDPR’s entry into force—in accordance with the requirements of the previous Organic Law on Data Protection—could remain in effect for the term agreed upon therein and, if entered into for an indefinite term, until May 25, 2022.

Since the Regulation took effect, any of these contracts that are newly signed—or that renew the provision of services—must include, at a minimum, the commitments that Article 28 of the GDPR requires to be included in them. These commitments are more stringent than those required by our previous Data Protection Act (LOPD) and, in practice, have resulted in longer contracts. Contracts that had already been signed prior to the Regulation’s entry into force had to be brought into compliance with it, and this is where the deadline comes into play—a deadline that, for open-ended or indefinite-term contracts, is about to expire.

Consequently, any contract entered into for an indefinite term with a vendor that will process personal data as a data processor must be fully compliant with the GDPR by May 25 at the latest.

To determine this, it is best to analyze each case individually. It is not strictly necessary to enter into a new service agreement—or master agreement—if the existing one remains in effect and is not to be amended. A new engagement agreement may not even be entirely necessary; in some cases, it may be sufficient to add an addendum—either to the master agreement or to the engagement agreement, as appropriate—containing the necessary provisions in accordance with the Regulation.

In any case, let us remember that the GDPR requires the data controller to select only data processors that provide guarantees that they will respect the rights and freedoms of data subjects in the processing of personal data. In other words, companies must evaluate those of their suppliers who will process personal data under their responsibility. Furthermore, as the Spanish Data Protection Agency has already indicated in some of its rulings, this evaluation cannot be limited to the time of contracting but must be repeated periodically. Neither the Regulation nor our national legislation specifies the frequency with which this assessment must be conducted, and an organization may very well assess its data processors at different intervals, depending on the risk associated with the processing, the risk associated with the data processor, or other reasons or criteria.

In any case, now is a good time to evaluate those data processors with whom contracts dating from before May 25, 2018, are still in effect, if this has not been done during this entire period. Ideally, this should be done using a system or procedure that is as objective as possible and that is embedded within the supplier approval process—if the organization has such a process in place (data protection by design and by default)—but which, at the same time, for the reasons stated, can be activated independently to carry out the relevant periodic reviews.

Furthermore, if the data processor—or any of its entities involved in data processing—is located outside the European Economic Area (EEA) in a jurisdiction that has not been designated a safe haven through an appropriate adequacy decision by the European Commission, the risk associated with this international data transfer must be assessed. This is done through assessments known as TIA (transfer impact assessment), in which the ideal approach is to analyze the risk associated with four elements: the data exporter, the characteristics of the transfer itself, the legal framework of the data’s destination, and the data importer or recipient.

Finally, it is important to remember that the obligation to enter into a data processing agreement—or to include equivalent provisions in the main contract itself—rests with both the data controller and the data processor, and that such an agreement or legal instrument must be in writing, whether in physical or digital format.

Bonus track: For the purposes of both interpreting the contract and providing evidence in the event of potential claims and/or disputes between the parties, it is very useful to include, as annexes to the data processing agreement, the questionnaire that the data processor was required to complete for evaluation and, where applicable, to assess the risk of an international data transfer, as well as—if not included in said questionnaire— the specific security measures that the processor declares to have implemented in connection with the data processing it will carry out on behalf of the data controller.

 

By Ruth Benito