Full text
Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor as referred to in paragraph 3 shall be imposed on that other processor by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing will meet the requirements of this Regulation. Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor's obligations.
How it connects
Cited by
- CJEU: DPA may investigate complaints but cannot impose penalties outside its territory
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
- UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria
All 13
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- Opinion 20/2021 on Tobacco Traceability System
- Opinion 18/2021 on the draft Standard Contractual Clauses submitted by the LT SA (Article 28(8) GDPR)
- EDPB-EDPS Joint Opinion 1/2021 on standard contractual clauses between controllers and processors
- EDPB-EDPS Joint Opinion 2/2021 on standard contractual clauses for the transfer of personal data to third countries
- Opinion 14/2019 on the draft Standard Contractual Clauses submitted by the DK SA (Article 28(8) GDPR)
- Sub Agent: Insufficient technical and organisational measures to ensure information security
- Sole trader: Insufficient technical and organisational measures to ensure information security