GDPR - The fundamental framework
Objective: Understand the roles of data controller and data processor under the GDPR, and know how to identify them in your supplier contracts.
The General Data Protection Regulation (GDPR, EU Regulation 2016/679) is the reference text for personal data protection in the European Union, applicable since 25 May 2018. In France, it is supplemented by the French Data Protection Act (Loi Informatique et Libertés, Law No. 78-17 of 6 January 1978, as amended).
Sources
For every buyer, understanding the GDPR is essential because almost every supplier contract involves personal data: supplier contacts, outsourced HR data, customer data in a SaaS CRM, browsing data on a hosted website...
Identifying roles in the data processing chain
🏢 Data Controller
Definition: Determines the purposes and means of processing
In procurement: The buyer who collects supplier contact data for their management system
Obligations:
- Legal basis for each processing activity
- Record of processing activities
- Information to data subjects
- Overall compliance
🔧 Data Processor
Definition: Processes data on behalf of the controller
In procurement: SaaS provider, payroll service provider, cloud host, IT service provider
Obligations:
- Act only on documented instructions
- Confidentiality and security
- No sub-processing without consent
- Assistance to the controller
🤝 Joint Controllers
When two parties jointly determine the purposes and means.
Example: Shared collaborative procurement platform
Mandatory agreement defining respective responsibilities (Art. 26 GDPR)