Use of Sub-Processors Under Equivalent Contract Terms, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 28(3)(h).

Assessment Step

1
Use of Sub-Processors Under Equivalent Contract Terms (UseofSub-ProcessorsUnderEquivalentContractTerms)
If the entity engages another data processor, does it do so by way of a written contract that imposes data protection obligations equivalent to those in the contract with the data controller, including sufficient guarantees for appropriate technical and organisational measures?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Use of Sub-Processors Under Equivalent Contract Terms
Where the data processor engages another data processor, it must do so by way of a written contract imposing the same data protection obligations as set out in the contract between the controller and the processor, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing meets GDPR requirements.
Citation
GDPR
Art. 28(3)(h), Recital 81