The EU's General Data Protection Regulation establishes strict requirements for organizations when engaging third parties to process personal data
The General Data Protection Regulation (GDPR) represents the most significant change in data privacy regulation in decades. It not only affects organizations within the European Union but any organization that processes the personal data of EU residents.
Articles 28-30 specifically address the relationship between data controllers and data processors, establishing clear obligations and responsibilities for third-party risk management in the context of personal data processing.
Active - Effective since May 25, 2018
European Union (with extraterritorial reach)
National Data Protection Authorities, European Data Protection Board
Up to €20 million or 4% of global annual turnover, whichever is higher
Essential GDPR provisions for processor management and third-party risk
Controllers must use only processors that provide sufficient guarantees to implement appropriate technical and organizational measures to meet GDPR requirements and protect data subjects' rights.
This article establishes restrictions on who may process personal data under the processor's authority.
Each controller and processor must maintain records of processing activities under their responsibility.
Several other GDPR articles directly impact third-party risk management requirements:
Practical steps for ensuring GDPR compliance in third-party relationships
Identify and document all third parties that process personal data on your behalf:
Evaluate processors to ensure they provide "sufficient guarantees" to implement appropriate measures:
Implement contracts that include all Article 28 requirements:
Establish processes for controlling and overseeing sub-processors:
Establish a program to monitor processor compliance over time:
Develop plans for secure termination of processor relationships:
Helpful materials for understanding and implementing GDPR processor requirements
Full text of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data.
Access documentEuropean Data Protection Board's guidance on concepts of controller and processor in the GDPR.
Access documentEU-approved standard contractual clauses for controller-processor relationships under Article 28.
Access documentInteractive tool to evaluate processor compliance with GDPR requirements.
Access toolComprehensive checklist for ensuring your data processing agreements meet GDPR requirements.
Download checklistEducational webinar on best practices for managing processors under GDPR.
Watch webinarSolutions to help organizations manage processor relationships in compliance with GDPR
Centralized repository for tracking data processors and processing activities.
Tool for creating custom GDPR-compliant data processing agreements.
Framework for evaluating the risk level of data processors.
System for scheduling, conducting, and tracking processor audits.
Tools for assessing data transfers to processors outside the EEA.
Dashboard for monitoring ongoing compliance status of all processors.
Our team of data protection experts can guide your organization through the complexities of GDPR compliance