The Belgian DPA rules that both controllers and processors are liable for missing DPAs

New Belgian Data Protection Authority decision:
– Both the controller *and* the processor can be liable for not having a data processing agreement (DPA) in place
– If you sign a DPA with “retroactivity clause” (i.e. foreseeing an earlier effective date than the signature date), that retroactivity clause does not have any effect from a GDPR compliance perspective – the signature date is relevant for determining whether you had a DPA in place covering the processing
=> Conclusion for both the controller and the processor: infringement of Art. 28(3) GDPR, because they did not actually have a DPA in place at the time of the relevant processing

A few key excerpts (machine translation):

Para. 27: “the obligation to conclude a contract or to be bound by a binding legal act lies on both the controller (here the first defendant) and the processor (here the second defendant) and not on the controller alone. This is particularly important where, as is the case here, a processor offers its specialist services to a large number of separate controllers. It would not be consistent with the GDPR (or, moreover, with the reality on the ground) to consider that the initiative for concluding the contract (and its proposed content) should come solely from the data controller.

Para. 29: “the Litigation Chamber is of the opinion that the retroactivity clause provided for in the contract of [DATE] is not such as to compensate for the absence of a contract at the time of the facts. If such a retroactivity clause were to be accepted, it would de facto make it possible to circumvent the temporal application of the obligation under Article 28.3. of the GDPR, which, as was as developed in points 26 and 27 above, on both the controller and the processor. the processor. However, as explained in point 28 above, the GDPR itself provides for a period of 2 years between its entry into force and its entry into application for progressive compliance by all the entities concerned.
[…]
The obligation to conclude such a contract […] also pursues the objective of guaranteeing the protection of the rights and freedoms of the data subjects whose data which will be processed in the context of the relationship which the controller (here the first defendant) and the processor (here the second defendant) choose to create between them are thus protected. This lack of protection – which is required by the GDPR – cannot be covered by a contractual retroactivity clause agreed by the defendants alone, in defiance of the rights of the data subjects – who are not parties to the contract – enshrined in a standard that is moreover of a European level.

Para. 30: “the Litigation Chamber concludes that both the first and second defendants [=> the controller *and* the processor] are guilty of a breach of Article 28(3) of the GDPR.

Link (decision in French): https://lnkd.in/dw4xzsW7
Data protection privacy

🫖

Did this analysis get you thinking? Reach out!

DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!

Get in touch ↗   Let's connect on LinkedIn ↗