Data Sharing Agreements: Five Red Flags

If you’re a smaller or newer business, or you just don’t share personal data very often, then it is more than likely you won’t have your own standard template data sharing agreement. Instead, you’re likely to rely on the equivalent template provided by organisations you get personal data from or sent it to.

That’s absolutely fine. Why reinvent the wheel? And having any kind of agreement is better than none (which happens a lot more than you might think).

However, in my experience a lot of data sharing agreements leave a lot to be desired. Here are the top five red-flags that I come across most often.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

 

Periodic Table of the GDPR

 

What is a Data Sharing Agreement?

 

A Data Sharing Agreement or DSA does what is says on the tin. It is an agreement between two organisations to share personal data. It is a binding contractual document that either stands alone or forms part of a wider contract. You absolutely do need a DSA if you are sharing personal between organisations. The only real exceptions are if the data sharing is ad-hoc (for example, under the vital interests lawful basis) or I you have a statutory duty to share the information (payroll data to HMRC for example).

Often , but not always, the problem with DSAs is what they DON’T include.

 

The controller / processor relationship is not set out.

 

Under the GDPR a data controller decides what personal data is collected / shared and what processing may happen. The processor receives the personal data and processes it on the controller’s instructions. Controllers have certain accountabilities for their data processors’ handling of the personal data they share. It’s therefore important that the DSA is clear who is the controller and who is the processor. Alternatively, if all parties are controllers or controllers in common, this should also be clear.

For example:

  • A company wants to send marketing materials by post to existing customers. It asks another business to design, print and send the mailing and gives that business the mailing addresses of the customers to target. In this scenario the company initiating the campaign is the controller and the business printing and sending it is the processor. The controller is accountable for ensuring the processor only uses the personal data for the agreed purposes, and overseeing the processor’s GDPR compliance. The processor cannot retain or reuse the personal data one the mailing is done, but of course the controller can.
  • A company is recruiting and uses a recruitment agency to seek and review applications before sending a recommended interview list to the company. The company and the agency are likely to be joint controllers because the agency will have some flexibility about deciding what and how much personal data to collect from applicants, and will make decisions about people based on that information. The agency will then pass on that personal data for further processing to the company. Crucially the recruitment agency decides what information to share with the hiring company.

 

What happens when the DSA ends?

 

Any DSA should make clear what happens to personal data on termination of the agreement. This can be when the underlying purpose for the data sharing has been successfully completed. They also have a termination clause “either party can terminate this agreement by given seven days’ notice in writing” etc. Any termination clause should also set out what happens to personal data once the data sharing agreement is no longer required or in force. This is important partly because controllers are responsible for the compliance of data processors including preventing unauthorised processing and compliance with the principles around data retention. However, too often DSAs omit this crucial information.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

There is an overreliance on consent, or the lawful basis isn’t clear.

 

This is less of an issue than it used to be but still a lot of template data sharing agreements rely on consent as the lawful basis for data processing and don’t consider the other options. This could be because a standard template has not been adapted, or because of a lingering assumption that consent is the King of Lawful Bases. It isn’t. It is just one of many.

This is partly important because people’s data rights operate a little differently depending on what lawful basis you are relying on for data processing. It also impacts the controller because if someone were to withdraw consent for data processing they need to let the processor know and ensure they stop using that person’s information. That requires more vigilance and oversight than say relying on the performance of a contract as your lawful basis.

Also, if the controller is a public authority and processing personal data on that basis the processor cannot rely on that and another lawful basis should be found, and set out.

Finally, if relying on legitimate interests then discussing the appropriate balancing test that shows the processing is a reasonable intrusion into people’s privacy should be set out.

 

The DSA has not been reviewed by a Data Protection Officer

 

Sometimes people enter into DSAs without consulting a relevant expert such as a Data Protection Officer (DPO). This is always a good idea because they may spot things mere mortals may not. For example, I was asked to review a DSA that contain a clause reading that the processor may reuse personal data that it has received in error and that they can share personal data received properly with “carefully selected third parties”. Neither of these are acceptable.

It is an offence under s.170 of the Data Protection Act to knowingly or recklessly obtain personal data without the consent of the controller, and also to retain and process that data.

The controller really should know who, if anyone, else their personal data may be shared with and why, and have control over whether this happens. In most instances such wider sharing will be completely unnecessary. And, under Article 28 of the UK GDPR, if a processor does undertake this wider sharing they risk becoming a data controller in their own right with all the responsibilities and accountabilities that involves.

 

The DSA refers to the Data Protection Act 1998

This is one of my favourites because it shows either the DSA template is remarkably out of date or has not been updated or drafted properly. Obviously the correct Act is the 2018 Data Protection Act and if any DSA has this kind of error my advice is to hand it back to the author/sender and say you do not intend to review the document further until these basic mistakes have been rectified.

 

Learn from the Experts

This GDPR training course includes the following modules:

  • what are personal data?;
  • the privacy principles;
  • privacy by design
  • accountability under the GDPR;
  • people’s rights under the GDPR;
  • consent and other lawful routes for data sharing;
  • data flow mapping and records of processing activity;
  • Data Protection Impact Assessments;
  • restricted and special category data
  • Data security and Data Breaches

Plus six months’ free post course support to help you apply your learning

Interested in Becoming a GDPR Champion? Get The Brochure Here

rating of more than 4.5 stars out of five

Rated 4.8 out of 5 on Trustpilot

Name

 

Conclusion

 

The issues described above an be avoided with some fairly simply planning:

  • understand your information lifecycle from identifying the need for processing through to data deletion or destruction
  • be clear about the relationship between all parties
  • understand and where necessary justify your lawful basis for processing
  • give the right people the right information at the right time

A data sharing agreement is a document that the Information Commissioner or the courts can expect to rely on in the event of a complaint, dispute between the parties or data breach so it is hugely important to ensure it is accurate and comprehensive.