To be able to create an article 30.2 record as data processor, you need to register where you process personal data for which customers.
-
Initiate a Processing Activity: Begin by setting up a processing activity where you act as a data processor, such as Customer Support, Data Retention, or providing an application to your customers. You may choose to identify your role as both data controller and data processor within a single activity or separate them. The latter, focusing solely on the data processor role, is more commonly adopted.
-
Gather Information for Your Article 30.2 Record:
- Security Measures: Document these under "Data Subjects."
- Data Categories: Specify these under "Categories of Personal Data."
- Transfers to Third Countries: Include these details in a registered transfer under "Transfers of Personal Data > Data Controller." Additional guidance is provided later in this article.
- Identifying Your Customers: Note who you are processing data for under "Transfers of Personal Data > Data Controller," further explained below.
- Security Measures: Document these under "Data Subjects."
-
Navigate to 'Transfers of Personal Data': This step is crucial for registering your customers.
-
Choose 'Data Controller' in the Sub-stepper: This indicates that a data controller is transferring data to you, in your capacity as a data processor.
-
Add a Data Processor: Here, you'll select your own group company. Ensure your group company is associated with the processing activity (in the step association) beforehand to make this selection.
-
Detail the Transfer: Provide a name for the transfer, confirm if it's supported by a data processor agreement with your customers, and add any relevant details.
-
Register Your Customers: Under "Which companies use you as a data processor," add your customers for whom you process personal data. For example, users of your app. Although you can add multiple customers, each will be listed individually in your Article 30.2 record. Further details are available here.
-
Ensure Customer Profiles Are Created: You can select customers already listed under the "Companies" tab. Make sure to create these profiles beforehand. Instructions are available here.
- Register sub-processors: If you make use of sub-processors, register these on the transfer as well. If a subprocessor is based in an unsecured third country this will be listed in the record afterwards.
-
Maintain an Updated Record: As you onboard new customers, routinely add them to ensure your Article 30.2 record and customer overview remain current.