Sign Up

What is 8 + 4?

Have an account? Sign In Now

Sign In

What is 8 + 4?

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

What is 8 + 4?

Have an account? Sign In Now

Please type your username.

Please type your E-Mail.

Please choose an appropriate title for the question so it can be answered easily.
Please choose the appropriate section so the question can be searched easily.

Type the description thoroughly and in details.

What is 8 + 4?

Sign InSign Up

Watercooler by DPOrganizer

Watercooler by DPOrganizer Logo Watercooler by DPOrganizer Logo

Watercooler by DPOrganizer Navigation

Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Categories
    • GDPR
    • Privacy Management
    • Professional Development
    • Software tips and tricks
    • Polls
  • Help
  • About Watercooler
Home/ Questions/Q 6400
Next
In Process
Anonymous
  • 0
Asked: April 19, 20212021-04-19T19:03:40+01:00 2021-04-19T19:03:40+01:00In: GDPR, Privacy Management

Negotiating a DPA

  • 0

Hi, I’m negotiating a DPA with a data processor, and I’m not sure how much I can push in terms of liability.
Should I expect a data processor to accept liability (uncapped) for fines or damages we get that result from them violating the DPA or the law? Or can I trust that they will be the party fined if it is indeed their fault?

Thankful for input

  • 5 5 Answers
  • 0 Followers
  • 0
Answer
Share
  • Facebook

    5 Answers

    • Voted
    • Oldest
    • Recent
    1. HellenB

      HellenB

      • 2 Questions
      • 83 Answers
      • 0 Best Answers
      • 79 Points
      View Profile
      HellenB Silver contributor
      2021-04-20T14:43:56+01:00Added an answer on April 20, 2021 at 2:43 pm

      It is very doubtful that even if you could get a processor to take on unlimited liability that it would stand up as a fair contract.
      The norm is to split the liability, with one part attached to the performance of the contract and one to an action/actions that result in a breach which would materially affect your business.
      Always remember that as the Controller, your due diligence will be held to account first, unless it is absolutely clear cut that any breach of the regulations was caused by your processor’s negligence or ‘bad action’.

      • 1
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    2. Stephen Lark

      Stephen Lark

      • 2 Questions
      • 29 Answers
      • 0 Best Answers
      • 26 Points
      View Profile
      Stephen Lark Bronze contributor
      2021-04-27T15:34:21+01:00Added an answer on April 27, 2021 at 3:34 pm

      Negotiate as much as you can but you can’t simply pass liability. Exercise and document your due diligence and regularly audit. In reality you would need to bring a case against the processor for damages not the ICO.
      The good news is that almost 100% of the fines have been for PECR violations and not data breach.
      The ICO are looking to punish those who flagrantly disregard good practice, not those who fall victim to sophisticated bad actors.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    3. Ceebs

      Ceebs

      • 0 Questions
      • 1 Answer
      • 0 Best Answers
      • 1 Point
      View Profile
      Ceebs
      2021-04-27T15:10:04+01:00Added an answer on April 27, 2021 at 3:10 pm

      We were discussing this earlier today in relation to a relatively low value contract. We reached a similar conclusion to that given by Yorkie82. An organisation with data controller responsibilities cannot expect a supplier/processor to be liable for a lack of due diligence or under baked service specifications. However, processors must be aware or and accept their responsibilities.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    4. PhilM

      PhilM

      • United Kingdom (UK)
      • 1 Question
      • 7 Answers
      • 0 Best Answers
      • 6 Points
      View Profile
      PhilM Rising star contributor
      2021-04-21T09:20:21+01:00Added an answer on April 21, 2021 at 9:20 am

      As controller, you are first and foremost accountable for any breach by your processors. This would mean the breach investigation, remediation and any notification obligations. Any fines would be apportioned between yourselves and the processor involved according to the extent of the responsibility. If you have done your homework correctly as suggested elsewhere, you stand to minimise these fines, but I would not go to far as to say that you are ‘insulated’.

      Liability on the other hand is a commercial consideration. The liability you specify in the contract is generally to cover you for your costs incurred as a direct result of any event caused by the processor. These would include costs of remediation (e.g. writing to customers, paying for credit monitoring services etc.). As to the amount, I would very much doubt any company would accept unlimited. Many limit to the damages to the value of the fees paid under the contract, but in the end, it’s just a negotiation. Good luck.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn
    5. Yorkie82

      Yorkie82

      • 0 Questions
      • 19 Answers
      • 0 Best Answers
      • 19 Points
      View Profile
      Yorkie82 Bronze contributor
      2021-04-20T11:43:54+01:00Added an answer on April 20, 2021 at 11:43 am

      Passing on liability for intent or gross negligence should be a no-brainer.
      But also if you have done your due diligence on the processor, obtained the required cyber safety guarantees in place and their commitment to the process in line with data protection legislation and audit the compliance on a regular basis, you can insulate yourself from potential fines if they caused a breach or another violation.

      • 0
      • Reply
      • Share
        Share
        • Share on Facebook
        • Share on Twitter
        • Share on LinkedIn

    Leave an answer
    Cancel reply

    You must login to add an answer.

    What is 8 + 4?

    Forgot Password?

    Sidebar

    Ask A Question

    Trending contributors

    Smurf333

    Smurf333

    • 11 Answers
    Bronze contributor
    Dave_Wylie

    Dave_Wylie

    • 28 Answers
    Bronze contributor
    CRodica

    CRodica

    • 6 Answers
    Rising star contributor
    Atis

    Atis

    • 4 Answers
    Ian G

    Ian G

    • 5 Answers
    Rising star contributor

    Recent questions

    • Ian G

      Revoke.com - new third party portal for customer right requests

      • 0 Answers
    • Anonymous

      Instagram!!

      • 0 Answers
    • Olga

      DPO in EU and UK

      • 1 Answer
    • Smurf333

      DBS scenario with HR retaining excessive information for longer than ...

      • 0 Answers
    • CRodica

      Parties role towards employees data for administrative purposes

      • 0 Answers

    Explore

    • Home
    • Categories
      • GDPR
      • Privacy Management
      • Professional Development
      • Software tips and tricks
      • Polls
    • Help
    • About Watercooler

    Footer

    Your privacy

    • Cookie notice
    • Privacy notice

    Terms and policy

    • Acceptable Use Policy
    • Terms of Use

    © 2021 DPOrganizer. All Rights Reserved. With Love by DPOrganizer.