Please enable JavaScript.
Coggle requires JavaScript to display documents.
18-OUTSOURCING (PROCESSORS (obligations irrespective of outsourcing …
18-
OUTSOURCING
PROCESSORS
obligations
irrespective of outsourcing
contract obligations
art.27(1)- extra EEA P to which GDPR applies shall designate a
EU representative
unless processing is occasional, special data processed on small scale, unlikely to create risks for rights and freedoms
art.28(2)-
sub processors
rules
controller
authorization
P
notification
to controller in case of
replacement
of subprocessor
same P obligations
to subprocessor
P remains liable
for sub-processor actions
art.28(3)-
contract
with controller is mandatory
art.30(2)-keeping
records
of processings on behalf of controller
unless <250 employees
art.31-
cooperation
duty with DPA
art.32-tech and
security measures
art.33-
breach notification
to controller
art.37-
DPO
appointing if conditions apply
art.44-compliance with
data transfers
rules
acting only on controller
instructions
P employees
confidentiality
duty
other obligations
assist controller
in
DS rights exercise
in data security/breach
notification
/PIA
delete or return
controller data at his request
accountability
allows
controller audits