When GÉANT, as Data controller (DC), engage another organization as Data processor (DP) to process personal data on behalf of GÉANT, requirements defined in Article 28. of GDPR should be met and appropriate Data processing agreement (DPA) should be signed between GÉANT and DP.
Outline of DPA
Main part
Main part of DPA contains legal framework based on GDPR requirements which is common for all services. Regarding security of processing the following general security measures are defined:
- measures to ensure that the Personal Data can be accessed only by authorized personnel for the purposes set forth in Annex 2 of this Data Processing Agreement;
- In assessing the appropriate level of security account shall be taken in particular of all the risks that are presented by processing, for example from accidental or unlawful destruction, loss, or alteration, unauthorized or unlawful storage, processing, access or disclosure of Personal Data;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- measures to identify vulnerabilities with regard to the processing of Personal Data in systems used to provide services to the Data controller;
- measures to identify malicious activity or breach;
- measures to audit access control and privileges;
More specific security measures are defined in Annex 3.
Annex 1 - contact information
Contains contact information of DC's and DP's Data Protection Officers (DPO).
Annex 2 - list of personal data
Contains list of all personal data which will be processed and categories of Data subjects involved.
Annex 3 - specific security measures *DRAFT*
Besides general security measures defined in main part of DPA, specific security measures which should be applied by DP in order to ensure protection of personal data can be defined. When properly implemented they can provide assurance that DP can provide adequate protection of rights of data subjects. These security measures are service specific and depends on architecture, scope and other factors and those are chosen based on risk assessment. Here is list of some types of security measures which can be used as reminder. Chosen measures should be elaborated in more details as appropriate.
- personnel - trained in data security; signed AUP or Statement of Confidentiality concerning personal data
- access management - strong password or 2-factor authentication are used for authorization; access to data are logged
- access protection - firewall or ACL protection
- stored data protection - pseudonymisation; anonymisation; database encryption; hard disk and removable media encryption; other forms of data encryption
- data transfer protection - during transfer data are protected with secure versions of encryption methods such as TLS, VPN, WPA2, SSH
- vulnerability management - software are timely patched; regular vulnerability scanning or penetration testing of applications or systems
- malware protection - end-station malware protection; email malware protection; education of personnel
- data leak protection - IDS; continuous monitoring; removable media policy
- regular backups - stored on safe place; encrypted; restore regularly checked
- incident management - incident response; timely reporting all incident to data controller
- (D)DOS protection - on network, system or application level
Annex 4 - data transfers outside EU
Description of personal data transfers outside EU during processing.
DPA approval procedure
Process of drafting, approving and signing of DPA is shown on the following figure.
Roles and their activities
There are several roles involved in this process and each of them perform the following activities:
- Service support - WP5-T3.6 team which prepare initial draft of DPA, finalize approved version adding reference number and store it to DPA store and update Confluence wiki.
- Service owner - owner of GÉANT's service.
- DPA manager - member of GÉANT with legal background who negotiate DPA with DP and approve final version.
- Data processor - representative of DP, usually with legal background who negotiate and agree with DPA proposed by GÉANT.
- GÉANT representative - representative of the GÉANT authorized to sign the DPA.
- DP representative - representative of the DP authorized to sign the DPA.