The data processing agreement: what happens after signing
A data processing agreement shapes the legal link between the controller and the processor. Under the first paragraph of Article 36 of the Georgian Law on Personal Data Protection, a processor may process data only on the basis of a legal act or a written agreement which defines the grounds and purposes of processing, the categories of data to be processed, the term of processing and the rights and obligations of the parties. The focus of this page, however, is not the text of the agreement but its lifecycle: what obligations the parties bear while the agreement operates, in disputes and upon its termination.
The law distributes clear roles here. The processor processes data only in accordance with the controller's written assignment or instruction; it ensures that the natural person directly involved in processing has a duty of confidentiality; it ensures the security of data in accordance with the law; and upon cancellation or termination of the agreement it deletes the data or transfers them to the controller and deletes the copies, unless their retention is required by legislation. Further processing of the data for a purpose different from that defined by the agreement or legal act is inadmissible.
Preliminary verification and monitoring
Choosing a partner does not end at the moment of signing. Under the sixth paragraph of Article 36, the controller is obliged to demand from the processor, in advance, information on the processing of data in accordance with the law and to monitor the processing carried out by the processor. This means that the right and duty of control are continuous: they begin before the agreement and continue throughout its operation.
In addition, where the processor's activity or aims create a high risk of non-purpose processing of data or of violation of the rights of subjects, concluding an agreement with such a person is inadmissible at all. Managing the agreement therefore begins with a risk assessment: who the partner is, what it does and how far its activity corresponds to the purposes for which the data are transferred.
Sub-processors and the consent rule
The processing chain often does not stop at one processor. Under the seventh paragraph of Article 36, unless otherwise provided by Georgian legislation, it is inadmissible for the processor to transfer its rights and duties, in full or in part, to another person without the controller's prior written consent. An important addition: the controller's consent does not release the processor from the corresponding obligations and liability.
The practical effect is clear: consent is a formal permission for engaging a sub-processor and not a redistribution of responsibility. The controller remains answerable for the behaviour of the entire chain, which is why the list of sub-processors, verification of their compliance and the procedure for consenting to changes are indispensable parts of managing the agreement.
Disputes and the transfer of data
Where a dispute arises between the parties, the law halts the process: under the eighth paragraph of Article 36, the processor is obliged to cease processing immediately and to transfer to the controller in full all the data at its disposal. The ninth paragraph of the same article defines the consequence of the cancellation or termination of the agreement or legal act: processing must cease and the processed data must be transferred to the controller immediately and in full.
These norms rule out the widespread practice under which, after the end of cooperation, the data remain with the former partner in a kind of warehouse. The exit is either deletion or full transfer — a third option does not comply with the law. The processor is also obliged to take organisational and technical measures to assist the controller in performing obligations connected with the exercise of the rights of data subjects.
Security and immediate notification of incidents
The security obligation in the lifecycle of the agreement belongs to both parties. Under the second paragraph of Article 27 of the law, the controller and the processor are obliged to adopt organisational and technical measures corresponding to the possible and accompanying risks — including pseudonymisation of data, logging of access to data and information-security mechanisms. These measures must be assessed periodically and updated where necessary.
In the event of an incident, time is decisive. Under the second paragraph of Article 29, the processor is obliged to notify the controller of the incident immediately, since it is the latter that bears the duty to record the incident and to notify the State Audit Office no later than 72 hours from its detection. Accordingly, the agreement and internal procedures must provide for this transmission channel in advance.
Liability and fines
Article 84 of the law attaches a sanction to the failure to perform the obligations provided for by Articles 35 and 36. In the general case this act entails, for a natural person, a public agency, a non-commercial legal entity, a legal entity, a branch of an enterprise of a foreign country and an individual entrepreneur whose annual turnover does not exceed 500 000 lari, a warning or a fine of 1 000 lari; where the turnover exceeds 500 000 lari, a warning or a fine of 2 000 lari. With aggravating circumstances the fine rises to 2 000 and 4 000 lari respectively.
The Legal.ge team will help you manage the entire lifecycle of data processing agreements: from verifying the partner and structuring the agreement to documenting monitoring, sub-processor consents and exit procedures.
