This clause defines who is responsible for what when it comes to data protection. The "controller" decides why and how data is used; the "processor" handles the data on the controller's behalf (like a cloud storage company or payroll service). Under GDPR, each party has different legal duties—the controller is ultimately responsible, but the processor must follow strict security rules. If data is breached, regulators and individuals will look to this clause to determine who is liable. Getting this wrong means you might be held responsible for another company's security failures.
Identify clearly whether you are the controller or processor in this contract. If you're the processor, ensure the clause requires the controller to provide written instructions for how you handle data, and that it limits your liability to breaches caused by your own negligence. If you're the controller, make sure the processor agrees to implement specific security measures and allows you to audit their practices. ---
Frequently Asked Questions
What does this clause mean in simple terms?
This clause defines who is responsible for what when it comes to data protection.
Why should I care about this clause?
The "controller" decides why and how data is used; the "processor" handles the data on the controller's behalf (like a cloud storage company or payroll service).
What are my options?
Under GDPR, each party has different legal duties—the controller is ultimately responsible, but the processor must follow strict security rules.
How does this affect small businesses?
If data is breached, regulators and individuals will look to this clause to determine who is liable.
