Data Processors
Jump to
Data Processors Start Comparison
Are there obligations for controllers to establish controls with respect to data processors?

[Last reviewed: January 2025]

Yes.

The obligations are as follows:

☒   controllers must conduct due conduct diligence on the processor to ensure it will provide appropriate security and processing of the personal data

☒   controllers must only use processors subject to a written agreement that complies with specific requirements

Are there any direct regulatory or statutory requirements on processors?

[Last reviewed: January 2025]

Yes.

The following provisions apply directly to processors:

Art. 33 Spanish Data Protection Law and Art. 28, 29, 30 para. 2, 31, 32, 33 para. 2, 37 et seq., 44 et seq. GDPR.