EDPB 22/2024
Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
What it covers
This opinion, issued at the request of the Danish supervisory authority under Article 64(2) GDPR, addresses controllers' obligations regarding the identification, verification and documentation of processors and sub-processors, and the wording of controller-processor contracts, including in the context of international transfers.
Why it matters
It provides a harmonised interpretation of controllers' due diligence obligations towards their processing chain and clarifies acceptable contractual wording, which is directly relevant when negotiating or auditing processor agreements.
Refer to it when
- negotiating or reviewing a data processing agreement
- assessing how much verification of sub-processors is required
- drafting a clause on instructions and third-country legal orders
- assessing accountability for a multi-tier processing chain involving transfers
Questions this document addresses
- What information must a controller have about processors and sub-processors in its chain?
- How much verification of a (sub-)processor's guarantees is required, and does this depend on risk?
- Must a controller review sub-processing contracts?
- How do Article 28 obligations interact with Chapter V when transfers occur within the processing chain?
- Is the wording 'unless required to do so by Union or Member State law' mandatory in processor contracts?
Topics
- Controller & processor
- International transfers
- Data subject rights
Clarifies controllers' duties when using processors and sub-processors: verifying sufficient guarantees, keeping information on the whole processing chain, authorising sub-processors and passing obligations down the chain.
Mapped GDPR Articles
Reproduced from official EDPB publications for reference. Not legal advice.