- Data can be exchanged in two stages: first as order processing with limited access, then – if the data is removed for own purposes – as transmission between controllers.
- The “just in time” consent and information obligations only arise when the data is collected, which strengthens transparency and purpose limitation for data subjects.
When personal data is exchanged between two data controllers, the following applies – as always Proportionality principle. However, it is often difficult or hardly possible – for operational reasons – to limit the exchange of data to the needs of the recipient. It may be, for example, that a Group company transfers transaction data or the result of an analysis of such data to other Group companies, e.g., for purposes of fraud prevention, marketing, creditworthiness checks, etc., or that a collection agency receives not only the necessary billing and contract data, but additional information.
In such cases, the principle of proportionality requires that only personal data necessary for the recipient’s particular purpose are transferred, and only when they are specifically needed (i.e., not retained in advance); apart from the further requirements of transparency, purpose limitation, etc. This can be difficult in practice, which is why we present here a model that can solve this problem:
The data exchange in the scenarios described is an exchange between two Responsiblebecause the recipient processes the transmitted data for its own purposes and determines the framework conditions of its processing itself.
However, the exchange process can now be split:
Order processing
In a first step it can be used as Order processing be designed:
- The transmitting company is obliged to specify the scope and time of the data exchange. to be limited to the necessary extent. This requires triage – the necessary data must be separated from surplus data. For data management and for this triage, the receiving company can be used as an order processor. The data transfer in this step can therefore be more comprehensive. Personal data can thus also go in advance to companies that ultimately do not need this data for their own purposes.
- Above all, however, this presupposes that the two companies have a Order Processing Agreement and the recipient initially actually uses the personal data transferred only for the purposes of the transferring company. Under certain circumstances – depending on the risks – it makes sense to agree on a penalty in the event of unauthorized withdrawals, and – especially in the internal relationship – the question of the transfer price for the service provided under contract must be considered. The data received must be kept physically or logically separate, and the access options on the part of the recipient must be limited accordingly, by means of a technically implemented access concept, to what is necessary.
- In this first step, the recipient behaves like a hosting and data preparation service provider, i.e. a classic order processor. The fact that he also pursues another purpose of his own does not detract from this, because the data processing – and this is what matters – is carried out at this point exclusively according to the specifications of the controller, i.e., the transmitting company. And if the data controller were to commission an order processor to process the data for the benefit of data controller B, data controller B would not be a data controller in relation to the order processor, even though the processing serves its – downstream – economic interests.
- In this first step, there will not necessarily be a shared responsibility. It is true that the service provider specifies to a certain extent the criteria according to which the data held by him are to be prepared, after this preparation has been determined for his purposes in a second step. However, this applies to every data transfer that takes place for the benefit of the recipient, including, for example, when a client transfers to his lawyer – i.e. to a data controller – the personal data that the lawyer requires at his own discretion. It would be wrong to see almost every transfer of personal data to another controller as a joint responsibility on the basis of this consideration.
Data extraction and own responsibility
In a second step the recipient extracts the processed personal data from the data stock held on behalf of the transmitting company for its own purposes:
- In this case, the recipient behaves like a processor whose processing goes beyond the limits of order processing. In such cases, it is recognized (cf. Art. 28(10) GDPR, which, however, concerns the arbitrary task excess of the order processor) that the order processor must becomes the person responsible. An example would be the order processor who uses order data as a controller for his own analyses, benchmarking, etc.. Only at this moment, therefore, does a data transfer take place from one responsible party to the other responsible party.
- Only at this moment, if at all, justification becomes necessary. The preceding transmission of the responsible person to the order processing is privileged.
- The recipient must stop processing the extracted data as soon as its purpose has been achieved. However, the continued storage of the same data as part of the ongoing order processing remains possible. It must also inform the transferring company about the extraction, either in the individual case or generally in advance, unless the time of extraction is already determined by the recipient’s purpose.
Advantages for the person concerned
This temporal or logical staggering is not a workaround, but has advantages for the person concerned:
- In the case of the disclosure of personal data to another data controller for the latter’s purposes, justification – insofar as such justification is required, e.g. because particularly sensitive personal data or personality profiles are transmitted or because the purpose of the recipient was not made transparent by the transmitting company – is in many cases de facto only possible by consent (because an overriding or legitimate interest as justification of a data transfer for commercial purposes only is possible, but is fraught with uncertainties and therefore risks for the data controller). However, because the data transfer requiring justification only takes place when the recipient actually extracts the data in question from the data stock held in order processing, the Consent only at this moment must be obtained. This means that the transmitting company can waive consent in advance, provided that the recipient obtains this consent on the occasion of – but before – the specific data extraction. An example would be the use of the data received by the recipient for fraud prevention or for checking creditworthiness in a specific purchasing transaction. In this case, consent can be obtained precisely within the scope of the recipient’s sales transaction, e.g. if the customer wishes to purchase on account. Such a “just in time” consent is advantageous from a data protection point of view because it is obtained specifically for the specific transaction and not globally, for example via general terms and conditions, at the time when the customer’s attention is focused on the specific transaction and he can best assess the scope of the consent.
- If the recipient collects personal data for different purposes, he or she can also obtain consent for each individual purpose.
- Also the Information requirements of the data recipient only arise at this moment. The duty to inform can therefore also be fulfilled “just in time”, which is acknowledged to be advantageous for the data subject (keyword “layered approach”).
- The division leads to a clear allocation of roles among those responsible, which increases transparency and helps to ensure that responsibility for data protection obligations does not diffuse in the division of labor.
At first glance, this exchange model may seem somewhat contrived. However, it has advantages not only for the two responsible parties, but also for the data subject, and it can help to ensure that intra-Group – but also extra-Group – data transfers are more deliberate, targeted and transparent.