Save Risks, Efforts, and Costs by Requesting Your Data Processors to Be GDPR-Certified
Under Art. 28 GDPR, data controllers are liable in the event of non-compliance by their data processors.
Article 28 GDPR states:
“Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of this Regulation and ensure the protection of the rights of the data subject.”
In other words, it is the data controller’s responsibility to demonstrate that its data processors comply with the applicable GDPR provisions. Failing to do so may expose the controller to fines under Art. 83(4) GDPR resulting from deficiencies on the part of its data processors.
To meet this obligation, data controllers must assess and continuously monitor the GDPR compliance of their data processors. When performed properly, this requires substantial due diligence efforts and generates costs for both parties: the data controller and its data processors.
Fortunately, Article 28 recognises GDPR certification of data processors as a means “to demonstrate sufficient guarantees”. Now that Europrivacy has been approved for use worldwide, this mechanism is available to both European and non-European data processors.
By selecting GDPR-certified data processors, a data controller benefits in several ways:
- It reduces its risk exposure and the likelihood of being fined because of its data processors’ deficiencies.
- It simplifies the compliance process with data processors.
- It reduces the workload and costs associated with compliance assessments, monitoring activities, and due diligence.
How can organisations take advantage of Art. 28 GDPR?
- Update procurement policies to integrate GDPR certification as a requirement or, at a minimum, as a selection criterion.
- Contact existing data processors and invite them to certify their services within a reasonable timeframe (e.g. 12 months).
- Explore the Europrivacy Procurement Support resources to facilitate implementation.
This approach creates value for both parties. Data controllers reduce compliance risks and due diligence costs, while certified data processors strengthen their market position, differentiate themselves from competitors, and reduce the resources required to respond to customer compliance assessments.
Take the Next Step with Europrivacy
Welcome Pack: https://www.europrivacy.com/en/welcomepack
Procurement Support: https://www.europrivacy.com/en/procurement-support

The post Save Risks, Efforts, and Costs by Requesting Your Data Processors to Be GDPR-Certified appeared first on Europrivacy Community.