AP · LAWYERS
0%

Data processor contracts and international data transfers

Data rarely stays still: it flows out to outsourced payroll, the cloud provider, the marketing platform, the contact centre or the parent company. Each of those flows needs a document stating who answers to the individual and under what instructions the information is handled. We review the contracts in force, draft the agreements that are missing and structure the flows that cross the border.

Transmission and transfer are not the same

The law distinguishes between transmission, which happens when a third party processes the data on the controller's behalf and under its instructions, and transfer, which happens when the third party receives the data to process it for its own account. Each party's obligations, and the document that has to be signed, follow from that distinction. Confusing the two is the origin of most contracts that turn out to be useless when they are needed.

The first step is therefore to classify each relationship: who decides about the data, who merely executes, and who also uses it for their own purposes. That last case appears more often than expected, particularly with technology platforms whose terms allow them to use the information to improve their own product.

The flows that almost always show up

  • Outsourced payroll, social security and benefits, carrying employee and dependant data.
  • Cloud, hosting and backup providers, where everything else usually sits.
  • Marketing platforms, bulk email tools and digital advertising.
  • Contact centres, customer service and external collections.
  • Parent company, affiliates and shared services abroad.
  • Analytics tools, web tracking and systems with artificial intelligence components.
  • Commercial partners with whom databases are shared for joint campaigns.

What the processor contract has to say

  • Scope and instructions. What data the provider receives, for exactly what, and what it may not do with it, including using it for its own ends.
  • Security. Concrete rather than declaratory measures, with access controls and confidentiality duties on the provider's staff.
  • Subcontracting. Whether the provider may rely on third parties, with what authorisation, and passing the same duties down to them.
  • Incidents. A duty to notify without delay, with what minimum information and to whom inside the company.
  • Data subject rights. How the processor cooperates when someone requests access, correction or deletion.
  • Audit and evidence. What the controller may verify and which certifications or reports the provider must hand over.
  • Termination. Return or deletion of the information, timing, and evidence that it happened.

When the provider imposes its own template —the norm with international platforms— the discussion stops being about ideal wording and becomes a contract negotiation: what can be moved, what compensation to demand and what risk the company knowingly accepts. We handle that negotiation through our contracts practice.

When data leaves the country

The general rule restricts sending data to countries that do not offer an adequate level of protection, and the authority maintains a list of the countries it considers do. Where the destination is not on that list, there are recognised routes: the express and unequivocal consent of the individual, the situations the statute itself excepts, and a declaration of conformity before the Superintendence. Choosing the right route depends on the type of data, the purpose and who the recipient is.

  • Identifying the real destination country, which is often not the provider's domicile but where its servers are.
  • Determining whether the flow is a transmission or a transfer, and which instrument fits each.
  • Drafting the transmission contract with clauses that also hold up towards the individuals concerned.
  • Preparing the declaration of conformity where that is the applicable route.
  • Updating the policy and the notice so the international flow is genuinely announced.

What the client receives

  • The map of providers and flows, with each relationship classified and the document it calls for.
  • A review of the existing contracts, with the gaps identified and replacement wording proposed.
  • The data processing contracts and annexes drafted and ready to sign.
  • The structure of the international flow, with the chosen instrument and its justification in writing.
  • A list of questions to put to a new provider before signing anything.

Let's solve your legal matter

Every case starts with an honest conversation. Book 30 minutes, no commitment.

Review my providers