Umowa o przetwarzanie danych to umowa między administratorem, czyli organizacją decydującą o celu przetwarzania danych osobowych, a podmiotem przetwarzającym, czyli organizacją przetwarzającą te dane w imieniu administratora. Jeśli wysyłasz e-maile lub SMS do osób w Unii Europejskiej za pośrednictwem dostawcy, ten dostawca jest Twoim podmiotem przetwarzającym, a umowa nie jest formalnością, którą można pominąć.
Artykuł 28 rozporządzenia (UE) 2016/679 określa wymagane postanowienia tej umowy. Poniższy cytat pochodzi z tekstu Dziennika Urzędowego.
Dlaczego umowa jest wymagana?
Ponieważ Rozporządzenie stanowi, że relacja musi być regulowana umową, a następnie określa, co ta umowa musi zawierać:
Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller.
Wcześniej ciąży na Tobie obowiązek już na etapie wyboru dostawcy:
Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.
Obowiązek jest więc dwojaki: wybierz dostawcę, który jest w stanie spełnić standard, i ujmij relację na piśmie z wymaganymi postanowieniami.
Co musi zawierać umowa?
Osiem postanowień. Słowami Rozporządzenia, umowa stanowi, że podmiot przetwarzający:
(a) processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law
(b) ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
(c) takes all measures required pursuant to Article 32;
(d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;
(e) taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III;
(f) assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor;
(g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;
(h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
Klauzula (a) jest kluczowa. "Only on documented instructions" sprawia, że dostawca jest podmiotem przetwarzającym, a nie odrębnym administratorem, i dlatego dostawca wykorzystujący dane Twoich odbiorców do własnych celów wykraczałby poza tę relację.
Klauzulę (g) warto przeczytać, zanim jej potrzebujesz. Usunięcie lub zwrot danych po zakończeniu usługi następuje według Twojego wyboru, a praktyczna wartość tej klauzuli polega na tym, że istnieje przed zakończeniem relacji, a nie jest negocjowana w trakcie wyjścia.
A co z własnymi dostawcami podmiotu przetwarzającego?
Przejmują te same warunki, a odpowiedzialność pozostaje tam, gdzie się zaczęła.
The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.
oraz
Where a processor engages another processor ... the same data protection obligations as set out in the contract ... shall be imposed on that other processor ... Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor's obligations.
Wynikają z tego dwie rzeczy. Dostawca korzystający z ogólnej autoryzacji jest zobowiązany powiadomić Cię o nowych podwykonawcach i dać Ci możliwość sprzeciwu, dlatego standardem jest publikowana lista podwykonawców z powiadomieniem o zmianach. Delegowanie nie rozmywa odpowiedzialności: Twój dostawca pozostaje wobec Ciebie w pełni odpowiedzialny za działania swoich własnych dostawców.
Czy certyfikacja wystarcza sama w sobie?
Nie. To dowód, nie substytut:
Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.
"An element by which to demonstrate" to kluczowe sformułowanie. Certyfikacja pomaga wykazać, że wybrałeś dostawcę z wystarczającymi gwarancjami. Nie zastępuje umowy, a umowa nadal musi zawierać osiem klauzul.
Rozporządzenie dopuszcza też oparcie umowy, w całości lub w części, na standardowych klauzulach umownych przyjętych przez Komisję lub organ nadzorczy, dlatego umowy większości dostawców wyglądają podobnie.
Co właściwie powinienem sprawdzić?
Trzy rzeczy, które czytelnik może zweryfikować bez prawnika.
- Że umowa istnieje i obowiązuje dla Twojego konta, a nie jest jedynie dostępna na życzenie.
- Gdzie publikowana jest lista podwykonawców i w jaki sposób ogłaszane są zmiany, ponieważ klauzula (d) i ustęp 2 dają Ci prawo sprzeciwu, z którego nie możesz skorzystać bez powiadomienia.
- Gdzie dane są przechowywane i przetwarzane, ponieważ klauzula (a) traktuje przekazanie do państwa trzeciego jako coś, co musi wynikać z Twoich udokumentowanych instrukcji. To kwestia rezydencji danych, a czym jest rezydencja danych wyjaśnia, jak jest ona ustalana na Bird.
W skrócie
To wymóg, nie opcjonalna formalność.
Prawo europejskie stanowi, że przetwarzanie przez podmiot przetwarzający musi być regulowane umową, i określa, co ta umowa musi zawierać.
Podmiot przetwarzający działa wyłącznie na podstawie Twoich udokumentowanych instrukcji.
To pierwsza wymagana klauzula i to właśnie ona sprawia, że to Ty ponosisz odpowiedzialność za cel przetwarzania.
Podwykonawcy przejmują te same obowiązki, a odpowiedzialność nie przechodzi dalej.
Dostawca, który deleguje przetwarzanie, musi nałożyć te same warunki na dalsze podmioty i pozostaje wobec Ciebie w pełni odpowiedzialny, jeśli któryś z nich zawiedzie.
Umowa musi dopuszczać audyty i zawierać klauzulę o usunięciu danych po zakończeniu usługi.
Dwie klauzule, które ludzie pomijają, a które decydują o tym, co się stanie, gdy relacja się zakończy lub coś pójdzie nie tak.