Skip to content

Security1 publisher2 min readPublished

ICO puts its processor guidance under review after the Data (Use and Access) Act

The page that sets out how UK processors must contract with controllers and authorise sub-processors now says it may change under the Data (Use and Access) Act. The duties on it apply meanwhile, and the revision timetable sits elsewhere.

The Watch · Security desk

Illustration accompanying ICO puts its processor guidance under review after the Data (Use and Access) Act

What happened

  • The ICO's page on what it means to be a processor now carries a notice saying that, because of changes made by the Data (Use and Access) Act, the guidance is under review and may be subject to change.
  • The page still sets out nine direct obligations on processors, from acting only on controller instructions through to co-operating with supervisory authorities.
  • Sub-processors may not be engaged without the controller's prior specific or general written authorisation, and the downstream contract must offer an equivalent level of protection to the upstream one.
  • Three routes can make a processor pay: ICO enforcement powers and fines, a contract claim by the controller, and a direct claim brought in court by an individual.
  • Breach notification to the controller is due without undue delay, and the ICO says most controllers expect immediate notice and may write that requirement into the contract.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint The ICO's publication schedule sets the date of the rewrite, so a data processing agreement signed as final faces a re-read on the regulator's timing.
  • exposure The defence against an individual's claim runs through the processor's own paperwork, so the supplier that cannot produce the instruction it acted on is the one carrying the damage.
  • decision Anyone onboarding sub-processors under a standing general authorisation has to choose between continuing on that basis and routing each new one back to the controller before the guidance is republished.
  • precedent Contracts that incorporate ICO guidance by reference will change meaning when the regulator republishes the text, without either party signing anything.

The duties on the page apply while the review runs. A processor may still only act on the controller's instructions unless law requires otherwise, and one that steps outside those instructions, or processes for its own purposes, becomes a controller for that processing [4].

Two of the nine obligations on the page are paperwork. The first is the binding contract with the controller, which has to carry the compulsory provisions [5]. The second is sub-processor authorisation [6].

An individual's claim succeeds only where the processor failed UK GDPR provisions that apply specifically to processors, or acted without the controller's lawful instructions or against them [16]. Article 82 covers non-material damage, including distress [15]. The defence is hard to make out: the processor must prove it is not in any way responsible for the event that gave rise to the damage [17]. Documented instructions, and evidence they were followed, are what that proof is made of.

A duty also runs the other way. If a controller's instruction would breach the UK GDPR or local data protection law, the processor has to tell the controller immediately [9]. Transfers out of the UK sit on the same footing for processors as for controllers, and each one needs the controller's authorisation as well as compliance with the transfer provisions [11].

The notice does not say which of these the Act touched. Its wording is that the guidance "is under review and may be subject to change" [1]. The ICO keeps the list of what will be updated, and when, on its Plans for new and updated guidance page [2].

What to watch

  • The ICO's Plans for new and updated guidance page naming a publication date for the revised controllers and processors material.
  • Whether the rewrite alters the sub-processor wording, in particular the general written authorisation route and the equivalent-protection test.
  • Whether the updated text changes how the ICO describes the Article 82 defence available to processors.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories