Data Processors: Get your house in order for cyber security and GDPR
30th September 2023
Data Processors: Get your house in order for cyber security and GDPR
In our complex and ever-evolving data management landscape, data Processors play a pivotal role as the custodians of sensitive information. Whether you’re a seasoned data Processor or new to the game, it’s crucial to get your house in order when it comes to cybersecurity and GDPR compliance. Failing to do so can leave you holding the baby, just as Verizon was when they had to pay ‘$4 million to settle claims when it didn’t fully implement agreed and required cybersecurity controls when it provided IT services to federal agencies’ in the US. [source Global Data Review.com]
Here’s some crucial advice on both safeguarding your organisation and protecting the personal data you handle, ensuring you meet both your contractual and legal obligations.
Understand Your Role as a Processor
First and foremost, processors must have a crystal-clear understanding of their role. You are not the data Controller but rather the data custodian acting on their instructions and on their behalf. This distinction is vital because it determines your responsibilities and obligations under GDPR.
Due Diligence Matters
Just as a Controller has a legal obligation to perform due diligence on Processors before entering into any formal relationship before you sign any data processing agreements, you should conduct due diligence on your prospective client (Controller). You must ensure that what they are asking you to do is actually GDPR compliant and that they have robust data protection policies in place, confirming that they are committed to GDPR compliance. This proactive approach will save you from headaches down the road.
Data Processing Agreements: your foundation
Data processing agreements (DPAs) are your best friends. Not only are they a legal requirement under Article 28 of the GDPR, this document will form the foundations of your contractual obligations. These legally binding contracts outline the purpose, means, terms and conditions of data processing, ensuring that both parties are on the same page. DPAs are a GDPR requirement and should be a non-negotiable part of your relationships with data Controllers.
This document will cover the technical (cybersecurity) and organisational elements both organisations must abide by.
One word of warning: a Controller will always try and build in punitive indemnity clauses to any DPA; this is not a legal obligation under the GDPR but a civil contractual term; read them carefully before signing.
Secure Your Infrastructure
Cybersecurity should be at the forefront of your efforts to keep personal data safe. Invest in robust security measures, including encryption, access controls, and regular security audits. A data breach can lead to severe financial penalties and reputational damage, so prevention is vital.
Employee Training
Your team is often your first and last line of defence. You may have state-of-the-art technical measures, but breaches will occur if staff can circumvent controls. Ensure your staff are well-trained in data protection principles and know how to respond to security incidents. Implement a culture of vigilance when it comes to data security.
Regular Audits and Assessments
Don’t wait for a regulator to knock on your door. Conduct regular audits and risk assessments to identify and address vulnerabilities in your data processing practices. This proactive approach enhances security and demonstrates your commitment to compliance.
Data Minimisation
Adopt a data minimisation strategy. Only collect and process the data necessary for the specific purpose for which it was provided. Storing excess data increases the risk of data breaches and GDPR non-compliance.
A word of warning – the minute you step outside of the lines of the DPA and process personal data beyond the agreement of the Controller you become the Controller and fully liable for the data held. For example, the client may say you can only hold the data for 6 months, but you retain it for 12 months – you are now the Controller for that data and must have a lawful reason for processing the information in this new way.
Incident Response Plan
Develop a comprehensive incident response plan. A well-prepared response can mitigate damages and regulatory repercussions in the unfortunate event of a data breach. Ensure all stakeholders know their roles in this process.
Stay Informed
Data protection regulations are continuously evolving. Stay informed about the latest developments, as compliance requirements may change. Regularly review and update your processes and policies to align with the latest legal standards.
Transparency with Data Controllers
Maintain open lines of communication with data Controllers. Inform them promptly of any security incidents or breaches. Transparency builds trust and allows for a collaborative approach to resolving issues.
As a data Processor, you must take your cybersecurity and GDPR compliance obligations seriously. These are two sides of the same coin.
Contractual obligations, such as due diligence and data processing agreements, are not mere formalities but crucial tools for safeguarding your organisation’s reputation and financial stability. By implementing strong security measures, staying informed, and fostering a culture of compliance, you can ensure that you’re well-prepared to meet the challenges of data processing in today’s digital world. Remember, it’s not a matter of if a breach will occur, but more than likely, when.
Recent months are sadly littered with high-profile examples where back-office failures have led to data breaches, such as Zellis, the UK payroll provider that hackers breached to gain access to the BBC, Boots and BA’s data. Even more frightening is the breach caused by cybercriminals penetrating a data processor who had been given the responsibility of producing new police IDs for the London Metropolitan Police Force and thus photos, names, rank, vetting status, payroll number and more, of 47,000 officers and civil staff from the Met were stolen.
If you are a data Processor and doubt whether your house is in order – get a handle on things now before it’s too late.
Being prepared is your best defence against attack, human error, potential liabilities and regulatory actions.
- The first thing to do right now is to ensure you have performed due diligence on all Controllers and that a DPA is in place with each.
- Next, review the content of the DPAs.
- Check the DPAs are robust and fully compliant.
- Check that both parties are doing everything they committed in the signed DPAs.
- Ensure all staff are aware and have been trained recently (In the last 12 months).
Another excellent consideration would be a data protection audit. If you need help or advice, please take advantage of your complimentary 30-minute data consultation with one of our specialists. You can book yours here.