数据处理协议是控制者(决定为何处理个人数据的组织)与处理者(代控制者处理数据的组织)之间签订的合同。如果你通过提供商向欧盟境内的人发送电子邮件或 SMS,该提供商就是你的处理者,这份协议不是你可以跳过的形式。
《欧盟第 2016/679 号条例》第 28 条规定了该合同的必备条款。以下引文来自《官方公报》文本。
为什么必须签订?
因为条例规定这种关系必须受合同约束,并明确了合同必须包含的内容:
Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller.
在此之前,你在选择提供商时就已承担义务:
Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.
因此义务是双重的:选择能够达到标准的提供商,并以书面形式载明所要求的条款。
合同必须包含什么?
八项规定。按条例原文,合同应规定处理者:
(a) processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law
(b) ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
(c) takes all measures required pursuant to Article 32;
(d) respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;
(e) taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III;
(f) assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor;
(g) at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;
(h) makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
条款 (a) 是最关键的。"Only on documented instructions" 正是使提供商成为处理者而非独立控制者的依据,也是为什么提供商若将你的收件人数据用于自身目的就完全超出了该安排的范围。
条款 (g) 应在你需要它之前就仔细阅读。服务结束时删除还是返还数据由你选择,该条款的实际价值在于它在关系结束之前就已存在,而不是在退出过程中才去谈判。
提供商自己的供应商呢?
它们继承相同的条款,责任仍留在原处。
The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.
以及
Where a processor engages another processor ... the same data protection obligations as set out in the contract ... shall be imposed on that other processor ... Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor's obligations.
由此得出两点。使用一般授权的提供商有义务通知你新的次级处理者并给你反对的机会,这就是为什么公开发布次级处理者清单并提供变更通知是通行做法。而且委托不会稀释责任:你的提供商对其自身供应商的行为仍对你承担全部责任。
仅凭认证是否足够?
不够。认证是证据,不是替代品:
Adherence of a processor to an approved code of conduct as referred to in Article 40 or an approved certification mechanism as referred to in Article 42 may be used as an element by which to demonstrate sufficient guarantees as referred to in paragraphs 1 and 4 of this Article.
"An element by which to demonstrate" 是关键措辞。认证有助于你证明你选择了具备充分保障的提供商。但它不能取代合同,合同仍必须包含八项条款。
条例还允许合同全部或部分采用欧盟委员会制定或监管机构通过的标准合同条款,这就是为什么大多数提供商的协议读起来大同小异。
我实际应该检查什么?
无需律师即可核实的三件事。
- 确认协议已存在并对你的账户生效,而不是仅在请求后才提供。
- 次级处理者清单发布在哪里,以及变更如何通知,因为条款 (d) 和第 2 段赋予你反对权,而没有通知你就无法行使该权利。
- 数据存储和处理的地点,因为条款 (a) 将向第三国的传输视为必须有你书面指示的事项。这是一个数据驻留问题,什么是数据驻留介绍了在 Bird 上如何确定。
简而言之
这是法定要求,不是可选的文书工作。
欧洲法律规定处理者的处理活动应受合同约束,并明确了合同必须规定的内容。
处理者仅按你的书面指示行事。
这是第一项必备条款,也是让你对处理目的承担责任的关键所在。
次级处理者继承相同义务,责任不会转移。
将工作委托出去的提供商必须向下游施加相同条款,并且在下游方违约时对你承担全部责任。
协议必须允许审计,并包含服务终止时的删除条款。
这两项条款常被略读,但恰恰是决定关系结束或出现问题时后果的关键条款。