GDPR Guidance: Data Controllers Are Responsible For Processors’ Competency

Fox Rothschild LLP
Contact

The UK Information Commissioner’s Office (ICO) has issued a new guidance on the liabilities of Controllers and Processors, advising that the Controller is responsible for assessing that its Processor is competent to process personal data in line with GDPR’s requirements.

  • The assessment by Controller should take into account the nature of the processing and the risks to data subjects.
  • Some considerations:
    1. the extent to which the Processor complies with industry standards, if applicable
    2. whether the Processor has sufficient technical expertise to assist the Controller, e.g. in carrying out obligations under Articles 32-36 of the GDPR (technical measures, breach notifications and DPIAs)
    3. providing Controller with relevant documentation, e.g. privacy, record management and information security policies
    4. adherence to an approved code of conduct (when available)
  • Controllers should continue to monitor a Processor’s compliance, with frequency and methods used to audit compliance depending on the circumstances of the processing.

Read the full guidance.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Fox Rothschild LLP

Written by:

Fox Rothschild LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Fox Rothschild LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide