Take-Aways (AI)
  • Data can be exch­an­ged in two stages: first as order pro­ce­s­sing with limi­t­ed access, then – if the data is remo­ved for own pur­po­ses – as trans­mis­si­on bet­ween controllers.
  • The “just in time” con­sent and infor­ma­ti­on obli­ga­ti­ons only ari­se when the data is coll­ec­ted, which streng­thens trans­pa­ren­cy and pur­po­se limi­ta­ti­on for data subjects.

When per­so­nal data is exch­an­ged bet­ween two data con­trol­lers, the fol­lo­wing applies – as always Pro­por­tio­na­li­ty prin­ci­ple. Howe­ver, it is often dif­fi­cult or hard­ly pos­si­ble – for ope­ra­tio­nal rea­sons – to limit the exch­an­ge of data to the needs of the reci­pi­ent. It may be, for exam­p­le, that a Group com­pa­ny trans­fers tran­sac­tion data or the result of an ana­ly­sis of such data to other Group com­pa­nies, e.g., for pur­po­ses of fraud pre­ven­ti­on, mar­ke­ting, cre­dit­wort­hi­ness checks, etc., or that a coll­ec­tion agen­cy recei­ves not only the neces­sa­ry bil­ling and con­tract data, but addi­tio­nal information.

In such cases, the prin­ci­ple of pro­por­tio­na­li­ty requi­res that only per­so­nal data neces­sa­ry for the recipient’s par­ti­cu­lar pur­po­se are trans­fer­red, and only when they are spe­ci­fi­cal­ly nee­ded (i.e., not retai­ned in advan­ce); apart from the fur­ther requi­re­ments of trans­pa­ren­cy, pur­po­se limi­ta­ti­on, etc. This can be dif­fi­cult in prac­ti­ce, which is why we pre­sent here a model that can sol­ve this problem:

The data exch­an­ge in the sce­na­ri­os descri­bed is an exch­an­ge bet­ween two Respon­si­blebecau­se the reci­pi­ent pro­ce­s­ses the trans­mit­ted data for its own pur­po­ses and deter­mi­nes the frame­work con­di­ti­ons of its pro­ce­s­sing itself.

Howe­ver, the exch­an­ge pro­cess can now be split:

Order pro­ce­s­sing

In a first step it can be used as Order pro­ce­s­sing be designed:

  • The trans­mit­ting com­pa­ny is obli­ged to spe­ci­fy the scope and time of the data exch­an­ge. to be limi­t­ed to the neces­sa­ry ext­ent. This requi­res tria­ge – the neces­sa­ry data must be sepa­ra­ted from sur­plus data. For data manage­ment and for this tria­ge, the recei­ving com­pa­ny can be used as an order pro­ces­sor. The data trans­fer in this step can the­r­e­fo­re be more com­pre­hen­si­ve. Per­so­nal data can thus also go in advan­ce to com­pa­nies that ulti­m­ate­ly do not need this data for their own purposes.
  • Abo­ve all, howe­ver, this pre­sup­po­ses that the two com­pa­nies have a Order Pro­ce­s­sing Agree­ment and the reci­pi­ent initi­al­ly actual­ly uses the per­so­nal data trans­fer­red only for the pur­po­ses of the trans­fer­ring com­pa­ny. Under cer­tain cir­cum­stances – depen­ding on the risks – it makes sen­se to agree on a penal­ty in the event of unaut­ho­ri­zed with­dra­wals, and – espe­ci­al­ly in the inter­nal rela­ti­on­ship – the que­sti­on of the trans­fer pri­ce for the ser­vice pro­vi­ded under con­tract must be con­side­red. The data recei­ved must be kept phy­si­cal­ly or logi­cal­ly sepa­ra­te, and the access opti­ons on the part of the reci­pi­ent must be limi­t­ed accor­din­gly, by means of a tech­ni­cal­ly imple­men­ted access con­cept, to what is necessary.
  • In this first step, the reci­pi­ent beha­ves like a hosting and data pre­pa­ra­ti­on ser­vice pro­vi­der, i.e. a clas­sic order pro­ces­sor. The fact that he also pur­sues ano­ther pur­po­se of his own does not detract from this, becau­se the data pro­ce­s­sing – and this is what mat­ters – is car­ri­ed out at this point exclu­si­ve­ly accor­ding to the spe­ci­fi­ca­ti­ons of the con­trol­ler, i.e., the trans­mit­ting com­pa­ny. And if the data con­trol­ler were to com­mis­si­on an order pro­ces­sor to pro­cess the data for the bene­fit of data con­trol­ler B, data con­trol­ler B would not be a data con­trol­ler in rela­ti­on to the order pro­ces­sor, even though the pro­ce­s­sing ser­ves its – down­stream – eco­no­mic interests.
  • In this first step, the­re will not neces­s­a­ri­ly be a shared respon­si­bi­li­ty. It is true that the ser­vice pro­vi­der spe­ci­fi­es to a cer­tain ext­ent the cri­te­ria accor­ding to which the data held by him are to be pre­pared, after this pre­pa­ra­ti­on has been deter­mi­ned for his pur­po­ses in a second step. Howe­ver, this applies to every data trans­fer that takes place for the bene­fit of the reci­pi­ent, inclu­ding, for exam­p­le, when a cli­ent trans­fers to his lawy­er – i.e. to a data con­trol­ler – the per­so­nal data that the lawy­er requi­res at his own dis­creti­on. It would be wrong to see almost every trans­fer of per­so­nal data to ano­ther con­trol­ler as a joint respon­si­bi­li­ty on the basis of this consideration.

Data extra­c­tion and own responsibility

In a second step the reci­pi­ent extra­cts the pro­ce­s­sed per­so­nal data from the data stock held on behalf of the trans­mit­ting com­pa­ny for its own purposes:

  • In this case, the reci­pi­ent beha­ves like a pro­ces­sor who­se pro­ce­s­sing goes bey­ond the limits of order pro­ce­s­sing. In such cases, it is reco­gnized (cf. Art. 28(10) GDPR, which, howe­ver, con­cerns the arbi­tra­ry task excess of the order pro­ces­sor) that the order pro­ces­sor must beco­mes the per­son respon­si­ble. An exam­p­le would be the order pro­ces­sor who uses order data as a con­trol­ler for his own ana­ly­ses, bench­mar­king, etc.. Only at this moment, the­r­e­fo­re, does a data trans­fer take place from one respon­si­ble par­ty to the other respon­si­ble party.
  • Only at this moment, if at all, justi­fi­ca­ti­on beco­mes neces­sa­ry. The pre­ce­ding trans­mis­si­on of the respon­si­ble per­son to the order pro­ce­s­sing is privileged.
  • The reci­pi­ent must stop pro­ce­s­sing the extra­c­ted data as soon as its pur­po­se has been achie­ved. Howe­ver, the con­tin­ued sto­rage of the same data as part of the ongo­ing order pro­ce­s­sing remains pos­si­ble. It must also inform the trans­fer­ring com­pa­ny about the extra­c­tion, eit­her in the indi­vi­du­al case or gene­ral­ly in advan­ce, unless the time of extra­c­tion is alre­a­dy deter­mi­ned by the recipient’s purpose.

Advan­ta­ges for the per­son concerned

This tem­po­ral or logi­cal stag­ge­ring is not a work­around, but has advan­ta­ges for the per­son con­cer­ned:

  • In the case of the dis­clo­sure of per­so­nal data to ano­ther data con­trol­ler for the latter’s pur­po­ses, justi­fi­ca­ti­on – inso­far as such justi­fi­ca­ti­on is requi­red, e.g. becau­se par­ti­cu­lar­ly sen­si­ti­ve per­so­nal data or per­so­na­li­ty pro­files are trans­mit­ted or becau­se the pur­po­se of the reci­pi­ent was not made trans­pa­rent by the trans­mit­ting com­pa­ny – is in many cases de fac­to only pos­si­ble by con­sent (becau­se an over­ri­ding or legi­ti­ma­te inte­rest as justi­fi­ca­ti­on of a data trans­fer for com­mer­cial pur­po­ses only is pos­si­ble, but is fraught with uncer­tain­ties and the­r­e­fo­re risks for the data con­trol­ler). Howe­ver, becau­se the data trans­fer requi­ring justi­fi­ca­ti­on only takes place when the reci­pi­ent actual­ly extra­cts the data in que­sti­on from the data stock held in order pro­ce­s­sing, the Con­sent only at this moment must be obtai­ned. This means that the trans­mit­ting com­pa­ny can wai­ve con­sent in advan­ce, pro­vi­ded that the reci­pi­ent obta­ins this con­sent on the occa­si­on of – but befo­re – the spe­ci­fic data extra­c­tion. An exam­p­le would be the use of the data recei­ved by the reci­pi­ent for fraud pre­ven­ti­on or for checking cre­dit­wort­hi­ness in a spe­ci­fic purcha­sing tran­sac­tion. In this case, con­sent can be obtai­ned pre­cis­e­ly within the scope of the recipient’s sales tran­sac­tion, e.g. if the cus­to­mer wis­hes to purcha­se on account. Such a “just in time” con­sent is advan­ta­ge­ous from a data pro­tec­tion point of view becau­se it is obtai­ned spe­ci­fi­cal­ly for the spe­ci­fic tran­sac­tion and not glo­bal­ly, for exam­p­le via gene­ral terms and con­di­ti­ons, at the time when the customer’s atten­ti­on is focu­sed on the spe­ci­fic tran­sac­tion and he can best assess the scope of the consent.
  • If the reci­pi­ent coll­ects per­so­nal data for dif­fe­rent pur­po­ses, he or she can also obtain con­sent for each indi­vi­du­al purpose.
  • Also the Infor­ma­ti­on requi­re­ments of the data reci­pi­ent only ari­se at this moment. The duty to inform can the­r­e­fo­re also be ful­fil­led “just in time”, which is ack­now­led­ged to be advan­ta­ge­ous for the data sub­ject (key­word “laye­red approach”).
  • The divi­si­on leads to a clear allo­ca­ti­on of roles among tho­se respon­si­ble, which increa­ses trans­pa­ren­cy and helps to ensu­re that respon­si­bi­li­ty for data pro­tec­tion obli­ga­ti­ons does not dif­fu­se in the divi­si­on of labor.

At first glan­ce, this exch­an­ge model may seem some­what con­tri­ved. Howe­ver, it has advan­ta­ges not only for the two respon­si­ble par­ties, but also for the data sub­ject, and it can help to ensu­re that intra-Group – but also extra-Group – data trans­fers are more deli­be­ra­te, tar­ge­ted and transparent.