Module 06 · GDPR in Procurement

GDPR roles: Controller vs Processor

GDPR - The fundamental framework

Objective: Understand the roles of data controller and data processor under the GDPR, and know how to identify them in your supplier contracts.

The General Data Protection Regulation (GDPR, EU Regulation 2016/679) is the reference text for personal data protection in the European Union, applicable since 25 May 2018. In France, it is supplemented by the French Data Protection Act (Loi Informatique et Libertés, Law No. 78-17 of 6 January 1978, as amended).

For every buyer, understanding the GDPR is essential because almost every supplier contract involves personal data: supplier contacts, outsourced HR data, customer data in a SaaS CRM, browsing data on a hosted website...

Identifying roles in the data processing chain

🏢 Data Controller

Definition: Determines the purposes and means of processing

In procurement: The buyer who collects supplier contact data for their management system

Obligations:

  • Legal basis for each processing activity
  • Record of processing activities
  • Information to data subjects
  • Overall compliance

🔧 Data Processor

Definition: Processes data on behalf of the controller

In procurement: SaaS provider, payroll service provider, cloud host, IT service provider

Obligations:

  • Act only on documented instructions
  • Confidentiality and security
  • No sub-processing without consent
  • Assistance to the controller

🤝 Joint Controllers

When two parties jointly determine the purposes and means.

Example: Shared collaborative procurement platform

Mandatory agreement defining respective responsibilities (Art. 26 GDPR)

Open in the appSaved progress, quizzes and certificate