The gdpr introduces new responsibilities for both controller and processor.
Gdpr controller vs processor responsibilities.
The gdpr draws a distinction between a controller and a processor in order to recognise that not all organisations involved in the processing of personal data have the same degree of responsibility.
Controllers although the role of controller existed under the previous eu data privacy rule data protection directive 95 46 ec the gdpr expands its obligations significantly.
For more information about a processor s direct responsibilities under the gdpr please see our guidance on controllers and processors.
The accountability requirement is first laid out in article 5 1 of the gdpr listing six required principles underpinning.
Controller means the natural or legal person public authority agency or other body which alone.
The roles and responsibilities of data controllers and data processors will become increasingly important as organizations strive to maintain compliance with gdpr.
Understanding the differences between the two and how the role that your organization serves in any particular scenario alters your responsibilities is key to compliance.
However article 4 10 of the gdpr defines third party as a natural or legal person public authority agency or body other than the data.
The gdpr defines these terms.
According to article 4 of the eu gdpr different roles are identified as indicated below.
Can a processor be held liable for non compliance.
As a data controller one must ensure that the data processor s remain aware of their gdpr obligations.
Controllers and processors have distinctly different responsibilities but work together to attain the gdpr s data privacy standards.
A processor may be contractually liable to the controller for any failure to meet the terms of their agreed contract.
However where a processor breaches one of its few legal obligations.
Obligations of a controller vs a processor.
Data controllers must process all personal data in compliance with the gdpr and be able to provide evidence of this to the relevant supervisory authority.
As the controller is the key decision maker with regards to personal data most of the responsibilities for compliance with the gdpr fall on the controller s shoulders.
As a common recommendation confirm that there exists a clear and specific data processing agreement before handing over the processing to a third party.
Controller means the natural or legal person public authority agency or other body which alone or jointly with others determines the purposes and means of the processing of personal data processor means a natural or legal person public authority agency or other body which processes.