Agreement between controller and processor

Printer-friendly versionPrinter-friendly versionPDF verziaPDF verzia

Formation of relationship between controller and processor

Controller is entitled to entrust personal data processing upon processor based on a written agreement between the processor and processor.

Data subject´s consent with entrusting personal data processing upon processor is not required for the purpose of conclusion of this agreement. This does not affect an obligation of controller to inform the data subject at the moment of data acquisition pursuant to Section 15 of the Act on Personal Data Protection.  


Competence of the processor

While selecting the processor, the controller shall take into consideration professional, technological, organisational and personal skills and its competence to ensure security of the processing of personal data.


Agreement and its requirements

The controller and processor may establish individual agreement or include it into other agreement before the commencement of personal data processing. Requirements of such agreement are:

  • identification data of contractual parties,
  • date of processor´s authorization to  commence the processing of personal data on behalf of the controller,
  • purpose of personal data processing,
  • name of the filing system,
  • list of personal data to be processed; the list of personal data may be substituted with the scope of the personal data,
  • group of data subjects,
  • conditions of the processing of personal data  including list of permitted operations with personal data,
  • controller´s declaration that he took into consideration professional, technological, organisational and personal skills of the processor and his competence to ensure security of the processing of personal data,
  • controller´s consent with personal data processing by processor at the hand of a different person (sub-processor),
  • duration upon which the contract is concluded,
  • date of the contract conclusion and the signatures of contract parties

 

When should the agreement be concluded?

Written agreement between controller and processor must be concluded or its requirements must be included in another contract before the commencement of personal data processing, on the day of the commencement of personal data processing at latest.

 

Desktop version
2018 Office for Personal Data Protection of the Slovak Republic