Sign Up

What is 8 + 4?

Have an account? Sign In Now

Sign In

What is 8 + 4?

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

What is 8 + 4?

Have an account? Sign In Now

Please type your username.

Please type your E-Mail.

Please choose an appropriate title for the question so it can be answered easily.
Please choose the appropriate section so the question can be searched easily.

Type the description thoroughly and in details.

What is 8 + 4?

Sign InSign Up

Watercooler by DPOrganizer

Watercooler by DPOrganizer Logo Watercooler by DPOrganizer Logo

Watercooler by DPOrganizer Navigation

Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Categories
    • GDPR
    • Privacy Management
    • Professional Development
    • Software tips and tricks
    • Polls
  • Help
  • About Watercooler
Home/ Questions/Q 5920
Next
In Process
Henk van Leussen
Henk van Leussen

Henk van Leussen

  • Netherlands
  • 3 Questions
  • 11 Answers
  • 0 Best Answers
  • 11 Points
View Profile
  • 0
Asked: April 9, 20212021-04-09T13:43:40+01:00 2021-04-09T13:43:40+01:00In: GDPR

Data Processor or Other Recipient

  • 0

I have the following discussion: are auditors, such as Ernst & Young or TUV, a Data Processor or an Other Recipient? Imo they are an Other Recipient and no processing agreement is required.

What do I think about this?

  • 7 7 Answers
  • 0 Followers
  • 0
Answer
Share
  • Facebook

    7 Answers

    • Voted
    • Oldest
    • Recent
    1. HellenB

      HellenB

      • 2 Questions
      • 83 Answers
      • 0 Best Answers
      • 79 Points
      View Profile
      HellenB Silver contributor
      2021-04-09T14:10:08+01:00Added an answer on April 9, 2021 at 2:10 pm

      Barry is absolutely right with regards to the ‘it depends’ answer.
      To add another twist to this excellent question, there are instances where some professional service providers are considered to be agents rather than either a Controller or a Processor (an outsourced DPO for instance can be considered an agent).
      The ICO do give examples of whether these particular organisations are a controller or processor in their guidance document:
      https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/controllers-and-processors/what-are-controllers-and-processors/
      I tend to qualify ‘other recipients’ as organisations that the business is legally obligated to disclose to rather than one they would choose to.

      • 1
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
      • Barry Moult

        Barry Moult

        • 0 Questions
        • 29 Answers
        • 0 Best Answers
        • 29 Points
        View Profile
        Barry Moult Bronze contributor
        2021-04-09T16:00:19+01:00Replied to answer on April 9, 2021 at 4:00 pm

        Hi Hellen
        I love your last sentence definition, i’m going to use to use it if you don’t mind, sums it up nicely.

        “I tend to qualify ‘other recipients’ as organisations that the business is legally obligated to disclose to rather than one they would choose to”

        • 0
        • Reply
        • Share
          Share
          • Share on Facebook
          • Share on Twitter
          • Share on LinkedIn
        • HellenB

          HellenB

          • 2 Questions
          • 83 Answers
          • 0 Best Answers
          • 79 Points
          View Profile
          HellenB Silver contributor
          2021-04-09T19:13:24+01:00Replied to answer on April 9, 2021 at 7:13 pm

          Barry – I’m very flattered 🙂
          Be my guest.

          • 0
          • Reply
          • Share
            Share
            • Share on Facebook
            • Share on Twitter
            • Share on LinkedIn
    2. Barry Moult

      Barry Moult

      • 0 Questions
      • 29 Answers
      • 0 Best Answers
      • 29 Points
      View Profile
      Barry Moult Bronze contributor
      2021-04-09T13:56:44+01:00Added an answer on April 9, 2021 at 1:56 pm

      I suspect you will get a number of differing replies to this.
      Of course the standard reply is going to be ‘it depends’. It depends what they are auditing.
      What will they have access to? how will they have access?
      In Health i have always treated auditors as ‘data processors’ and they only process the data as instructed in the contract.
      Would you want a data processing agreement? I’ve been there when I felt the ‘contract’ was not specific enough of what they will be doing (or not doing) with the data and insisted on an agreement. (belt & braces)
      Just think what could go wrong if its not clear 🙁

      • 1
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    3. Dean

      Dean

      • 0 Questions
      • 41 Answers
      • 0 Best Answers
      • 41 Points
      View Profile
      Dean Silver contributor
      2021-04-09T13:53:21+01:00Added an answer on April 9, 2021 at 1:53 pm

      Hi Henk,

      I would tend to agree that auditors are not processors, mainly because they are not operating to specific instructions for the purpose of processing data. I think they would have their own audit methodology and protocol for auditing and therefore would claim an element of autonomy.
      So “other recipient”, subject to appropriate safeguards of confidentiality, of course.

      Thanks, Dean

      • 1
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
      • Alexander Sturing

        Alexander Sturing

        • 1 Question
        • 14 Answers
        • 0 Best Answers
        • 13 Points
        View Profile
        Alexander Sturing Bronze contributor
        2021-04-14T12:41:58+01:00Replied to answer on April 14, 2021 at 12:41 pm

        I would like to add to Deans answer that it also depends on the type of audit. In some cases, audits are mandatory by law, this makes the auditor >not< being a data processor since it's not the controller determining what the auditor can audit, but specific legislation.

        • 1
        • Reply
        • Share
          Share
          • Share on Facebook
          • Share on Twitter
          • Share on LinkedIn
    4. BlueBottle

      BlueBottle

      • 0 Questions
      • 26 Answers
      • 0 Best Answers
      • 27 Points
      View Profile
      BlueBottle Bronze contributor
      2021-04-14T12:40:42+01:00Added an answer on April 14, 2021 at 12:40 pm

      I sign auditors up as processors, with a processor agreement and/or appropriate terms in their service agreement, NDA, etc.

      The documented instructions of the controller include the instruction to audit us, and to access confidential information for the purpose stated in the contract, which should be narrow enough to constitute processing on the documented instructions of the controller.

      I agree in theory that a contractor could be an agent, however if they are not an employee they are not part of the body corporate and thus are not the [original] controller.

      We have an agency relationship with introducers, and they are both a separate controller and a processor at different points in the customer journey, but for the purpose of data protection law we never consider them to be acting as us.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn

    Leave an answer
    Cancel reply

    You must login to add an answer.

    What is 8 + 4?

    Forgot Password?

    Sidebar

    Ask A Question

    Trending contributors

    Smurf333

    Smurf333

    • 11 Answers
    Bronze contributor
    Dave_Wylie

    Dave_Wylie

    • 28 Answers
    Bronze contributor
    CRodica

    CRodica

    • 6 Answers
    Rising star contributor
    Atis

    Atis

    • 4 Answers
    Ian G

    Ian G

    • 5 Answers
    Rising star contributor

    Recent questions

    • Ian G

      Revoke.com - new third party portal for customer right requests

      • 0 Answers
    • Anonymous

      Instagram!!

      • 0 Answers
    • Olga

      DPO in EU and UK

      • 1 Answer
    • Smurf333

      DBS scenario with HR retaining excessive information for longer than ...

      • 0 Answers
    • CRodica

      Parties role towards employees data for administrative purposes

      • 0 Answers

    Explore

    • Home
    • Categories
      • GDPR
      • Privacy Management
      • Professional Development
      • Software tips and tricks
      • Polls
    • Help
    • About Watercooler

    Footer

    Your privacy

    • Cookie notice
    • Privacy notice

    Terms and policy

    • Acceptable Use Policy
    • Terms of Use

    © 2021 DPOrganizer. All Rights Reserved. With Love by DPOrganizer.