{"id":480,"date":"2021-06-11T10:09:00","date_gmt":"2021-06-11T10:09:00","guid":{"rendered":"https:\/\/vanleeuwenlawfirm.eu\/?p=480"},"modified":"2025-05-23T01:06:25","modified_gmt":"2025-05-23T01:06:25","slug":"data-processor-dp-and-responsibilities-under-the-general-data-protection-regulation-gdpr","status":"publish","type":"post","link":"https:\/\/vanleeuwenlawfirm.eu\/en\/expertises\/tech-and-digital\/privacy-data-and-cybersecurity\/data-processor-dp-and-responsibilities-under-the-general-data-protection-regulation-gdpr\/","title":{"rendered":"Data Processor (DP) and Responsibilities under the General Data Protection Regulation (GDPR)"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"480\" class=\"elementor elementor-480\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1c767b2c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1c767b2c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-a56ad44\" data-id=\"a56ad44\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-45abb500 elementor-widget elementor-widget-text-editor\" data-id=\"45abb500\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\n<p data-start=\"37\" data-end=\"742\">Data Processors operate in the shadow of the Controller but bear a set of strict obligations to ensure the confidentiality, integrity, and availability of personal data. This role not only involves following documented instructions but also actively supporting the Controller in complying with complex GDPR obligations. Operational processes must be designed in such a way that every step in the data processing chain is verifiable, from data intake and processing to archiving and deletion. Technical measures\u2014such as encryption, access management, and logging\u2014must never be considered in isolation from organizational controls, such as training, contract management, and incident response organizations.<\/p>\n<p data-start=\"744\" data-end=\"1376\">At the same time, Data Processors find themselves in a dynamic regulatory landscape: regulators tighten requirements, legal practices generate new interpretations, and technological developments\u2014such as AI and cloud-native services\u2014create unforeseen risks. In organizations where there are allegations of financial mismanagement, fraud, or sanctions violations, a poorly structured processor contract can quickly halt critical data flows and escalate to executives who can be held personally liable. A deep understanding of processor obligations is therefore unavoidable for any entity processing personal data on behalf of another.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-eeacc10 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"eeacc10\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c0718a4\" data-id=\"c0718a4\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3102923 elementor-widget elementor-widget-text-editor\" data-id=\"3102923\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\n<h4 data-start=\"1378\" data-end=\"1424\">(a) Processing Only Based on Instructions<\/h4>\n<p data-start=\"1426\" data-end=\"1956\">Data Processors must ensure that every processing action is strictly motivated by the previously documented instructions from the Controller. This requires that all processing operations\u2014from data consolidation to automated analysis\u2014are exhaustively described in instruction documents that are contractually binding. Technically, a processor must configure workflows and APIs that reject processing instructions that fall outside the defined instructions, with audit systems automatically signaling deviations to compliance teams.<\/p>\n<p data-start=\"1958\" data-end=\"2330\">In deviation situations, such as when national legislation imposes a conflicting obligation, the processor must immediately report to the Controller and trigger appropriate legal review. All unforeseen processing must be explicitly documented, including the legal basis and approval from the Controller, to counter any claims of excessive or unauthorized processing later.<\/p>\n<h4 data-start=\"2332\" data-end=\"2354\">(b) Data Security<\/h4>\n<p data-start=\"2356\" data-end=\"2872\">Data Processors are required to implement \u201cappropriate technical and organizational measures\u201d to protect personal data from unauthorized access, loss, or destruction. This includes industry-standard encryption algorithms, strict key management processes, and physical security of data centers. Operational teams must continuously perform detailed risk assessments to identify new vulnerabilities\u2014such as in third-party libraries or container images\u2014and immediately apply security patches and configuration hardening.<\/p>\n<p data-start=\"2874\" data-end=\"3262\">Additionally, the GDPR calls for a culture of continuous improvement. Security operations centers must provide 24\/7 monitoring with advanced SIEM tools and incident response protocols that follow well-established playbooks. Post-incident analyses should systematically produce root cause analyses, after which improvement measures are rolled out generically across all processing systems.<\/p>\n<h4 data-start=\"3264\" data-end=\"3288\">(c) Confidentiality<\/h4>\n<p data-start=\"3290\" data-end=\"3792\">All officers and subcontractors who have access to personal data must be bound by a legal or contractual confidentiality obligation. This requires organizations to link onboarding processes to confidentiality agreements that are legally enforceable. Operationally, this means daily checks on account privileges, periodic reaffirmation of confidentiality obligations by employees, and technical shielding through role-based access control and just-in-time privileges that automatically expire after use.<\/p>\n<p data-start=\"3794\" data-end=\"4170\">Non-compliance must be detected through data loss prevention solutions that block confidential data exfiltration attempts in real time. Compliance reports should indicate which accounts have been recently reaffirmed and which logs show deviations, so that regulators and internal governance committees have immediate insight into the effectiveness of confidentiality measures.<\/p>\n<h4 data-start=\"4172\" data-end=\"4204\">(d) Engaging Sub-processors<\/h4>\n<p data-start=\"4206\" data-end=\"4753\">Before a Data Processor engages a sub-processor, due diligence must be conducted to screen the sub-processor for technical and organizational security measures, their record of data breaches, and financial stability. Contracts with sub-processors must be formulated identically to the main processor agreement: the same obligations regarding security, confidentiality, audit rights, and waiver clauses. Operationally, it is necessary to maintain a sub-processor registry that makes every change in the sub-processor chain directly audit-traceable.<\/p>\n<p data-start=\"4755\" data-end=\"5151\">Furthermore, a Data Processor must continuously monitor compliance by sub-processors through on-site or remote audits. Audit findings lead to escalation to executive levels, where decisions are made about maintaining or terminating sub-mandates. Contractual penalties for non-compliance\u2014such as immediate suspension of services\u2014must be activated without exception to mitigate risks at the source.<\/p>\n<h4 data-start=\"5153\" data-end=\"5190\">(e) Assistance to the Controller<\/h4>\n<p data-start=\"5192\" data-end=\"5574\">Supporting the Controller extends to facilitating data subject rights requests, assisting in conducting DPIAs, and preparing prior consultation requests with regulators. Operationally, this means that Processors agree on service levels for response times to access and deletion requests and prepare specialized teams capable of providing technical and legal documentation for DPIAs.<\/p>\n<p data-start=\"5576\" data-end=\"5901\">The Processor must, if necessary, provide tools\u2014such as logs, data flow diagrams, and security assessments\u2014so that Controllers can timely and fully comply with their notification and reporting obligations. These supporting processes must be documented in joint SOPs and integrated into GRC platforms to generate audit trails.<\/p>\n<h4 data-start=\"5903\" data-end=\"5935\">(f) Reporting Data Breaches<\/h4>\n<p data-start=\"5937\" data-end=\"6311\">Data Processors must have processes in place to detect any potential or actual breach within hours and report it to the Controller within 72 hours. Technically, this requires multi-vector detection capabilities\u2014from network intrusion detection to anomaly analysis in application logs\u2014and automated escalation mechanisms that aggregate incident details into forensic records.<\/p>\n<p data-start=\"6313\" data-end=\"6693\">Operationally, this means assembling crisis teams with clear task divisions: IT security for containment and root cause, legal teams for reporting texts and communication management, and PR for media and stakeholder communication. All actions must be traceable via incident management systems so that the entire process is demonstrably completed in accordance with GDPR timelines.<\/p>\n<h4 data-start=\"6695\" data-end=\"6746\">(g) Data Protection Impact Assessments (DPIAs)<\/h4>\n<p data-start=\"6748\" data-end=\"7098\">When processing likely involves \u201chigh risk\u201d\u2014such as large-scale profiling or processing of special categories of data\u2014the Processor must assist the Controller in every stage of the DPIA. This includes providing technical data flow diagrams, risk inventories, and possible mitigation strategies for additional privacy risks, such as re-identification.<\/p>\n<p data-start=\"7100\" data-end=\"7493\">Once completed, the outcomes must be translated into concrete measures in the product or service configuration. Processors support the implementation of privacy-by-design adjustments and provide evidence to confirm the execution of the DPIA. Governance teams then follow up to ensure that all recommendations from the DPIA have been implemented and maintain real-time dashboards for oversight.<\/p>\n<h4 data-start=\"7495\" data-end=\"7531\">(h) Cross-Border Data Transfers<\/h4>\n<p data-start=\"7533\" data-end=\"7916\">Data Processors must cover each international transfer of personal data with a legal transfer basis: adequacy decision, model contract clauses, or BCRs. Operationally, this means that endpoints\u2014such as API gateways and ETL workflows\u2014are configured so that transfers occur only through encrypted channels, and destinations are automatically validated against current compliance lists.<\/p>\n<p data-start=\"7918\" data-end=\"8275\">Contractually, transfer clauses must explicitly mention all technical safeguards, such as cryptographic algorithms, key-rotation schedules, and incident procedures in the event of cross-border data breaches. Compliance teams must deploy tools that automatically detect when data flows enter new regions, after which immediate remedial steps are coordinated.<\/p>\n<h4 data-start=\"8277\" data-end=\"8323\">(i) Obligations for Processing Activities<\/h4>\n<p data-start=\"8325\" data-end=\"8720\">Data Processors must maintain a record of all processing activities they perform, including categories of personal data, processing purposes, duration, and the categories of recipients involved. Operationally, this requires an integrated contract and process management platform where each data process is recorded and continuously synchronized with data flow diagrams and metadata repositories.<\/p>\n<p data-start=\"8722\" data-end=\"9014\">Continuity controls\u2014periodic reviews, automatic alerts for deviating processing volumes, and reconciliations between processing logs and records\u2014must demonstrate that the record remains up to date and accurate. This record forms the basis for internal audits and any requests from regulators.<\/p>\n<h4 data-start=\"9016\" data-end=\"9065\">(j) Cooperation with Supervisory Authorities<\/h4>\n<p data-start=\"9067\" data-end=\"9422\">Data Processors must designate direct points of contact for supervisory authorities and proactively maintain relationships. Operationally, compliance teams maintain a repository of all interactions with authorities\u2014from prior notices to inspection reports\u2014so that all relevant correspondence and evidence is readily available for follow-up investigations.<\/p>\n<p data-start=\"9424\" data-end=\"9802\" data-is-last-node=\"\" data-is-only-node=\"\">Furthermore, Processors should participate in coalitions and industry platforms to stay informed about regulatory interpretations and best practices. Strategic advantage arises when a Processor acts as a trusted partner for regulators, contributing to consultation documents and pilot projects for new privacy technologies, thereby projecting a proactive and transparent stance.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-785a3fd elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"785a3fd\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-190ebf8\" data-id=\"190ebf8\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-68ec59a elementor-widget elementor-widget-spacer\" data-id=\"68ec59a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-796b85f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"796b85f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-f503296\" data-id=\"f503296\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b457e68 elementor-widget elementor-widget-post-grid\" data-id=\"b457e68\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"post-grid.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\r\n\r\n<div class=\"blog-container blog-container-grid\">\r\n    \r\n    <div class=\"wi-blog fox-blog blog-grid fox-grid blog-card-has-shadow blog-card-normal column-3 spacing-normal\">\r\n    \r\n    \n<article class=\"wi-post post-item post-grid fox-grid-item post-align- post--thumbnail-before post-10351 post type-post status-publish format-standard has-post-thumbnail hentry category-role-of-the-attorney\" itemscope itemtype=\"https:\/\/schema.org\/CreativeWork\">\n\n    <div class=\"post-item-inner grid-inner post-grid-inner\">\n        \n                \n            \r\n<figure class=\"wi-thumbnail fox-thumbnail post-item-thumbnail fox-figure  grid-thumbnail thumbnail-acute  hover-none\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\">\r\n    \r\n    <div class=\"thumbnail-inner\">\r\n    \r\n                \r\n        <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/prevention\/\" class=\"post-link\">\r\n            \r\n        \r\n            <span class=\"image-element\">\r\n\r\n                <img fetchpriority=\"high\" decoding=\"async\" width=\"480\" height=\"384\" src=\"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-content\/uploads\/sites\/13\/2022\/07\/d21d9526-0130-457b-967f-eb3e6e84fb3e-480x384.png\" class=\"attachment-thumbnail-medium size-thumbnail-medium\" alt=\"\" \/>\r\n            <\/span><!-- .image-element -->\r\n\r\n            \r\n            \r\n                    \r\n        <\/a>\r\n        \r\n                \r\n    <\/div><!-- .thumbnail-inner -->\r\n    \r\n    \r\n<\/figure><!-- .fox-thumbnail -->\r\n\r\n\n<div class=\"post-body post-item-body grid-body post-grid-body\">\n\n    <div class=\"post-body-inner\">\n\n        <div class=\"post-item-header\">\r\n<h2 class=\"post-item-title wi-post-title fox-post-title post-header-section size-small\" itemprop=\"headline\">\r\n    <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/prevention\/\" rel=\"bookmark\">        \r\n        Prevention\r\n    <\/a>\r\n<\/h2><\/div>\n    <\/div>\n\n<\/div><!-- .post-item-body -->\n\n\n        \n    <\/div><!-- .post-item-inner -->\n\n<\/article><!-- .post-item -->\n<article class=\"wi-post post-item post-grid fox-grid-item post-align- post--thumbnail-before post-10353 post type-post status-publish format-standard has-post-thumbnail hentry category-role-of-the-attorney\" itemscope itemtype=\"https:\/\/schema.org\/CreativeWork\">\n\n    <div class=\"post-item-inner grid-inner post-grid-inner\">\n        \n                \n            \r\n<figure class=\"wi-thumbnail fox-thumbnail post-item-thumbnail fox-figure  grid-thumbnail thumbnail-acute  hover-none\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\">\r\n    \r\n    <div class=\"thumbnail-inner\">\r\n    \r\n                \r\n        <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/detection\/\" class=\"post-link\">\r\n            \r\n        \r\n            <span class=\"image-element\">\r\n\r\n                <img decoding=\"async\" width=\"480\" height=\"384\" src=\"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-content\/uploads\/sites\/13\/2022\/07\/1902bfee-280a-4164-9a31-a644cd739ad7-480x384.png\" class=\"attachment-thumbnail-medium size-thumbnail-medium\" alt=\"\" \/>\r\n            <\/span><!-- .image-element -->\r\n\r\n            \r\n            \r\n                    \r\n        <\/a>\r\n        \r\n                \r\n    <\/div><!-- .thumbnail-inner -->\r\n    \r\n    \r\n<\/figure><!-- .fox-thumbnail -->\r\n\r\n\n<div class=\"post-body post-item-body grid-body post-grid-body\">\n\n    <div class=\"post-body-inner\">\n\n        <div class=\"post-item-header\">\r\n<h2 class=\"post-item-title wi-post-title fox-post-title post-header-section size-small\" itemprop=\"headline\">\r\n    <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/detection\/\" rel=\"bookmark\">        \r\n        Detection\r\n    <\/a>\r\n<\/h2><\/div>\n    <\/div>\n\n<\/div><!-- .post-item-body -->\n\n\n        \n    <\/div><!-- .post-item-inner -->\n\n<\/article><!-- .post-item -->\n<article class=\"wi-post post-item post-grid fox-grid-item post-align- post--thumbnail-before post-10355 post type-post status-publish format-standard has-post-thumbnail hentry category-role-of-the-attorney\" itemscope itemtype=\"https:\/\/schema.org\/CreativeWork\">\n\n    <div class=\"post-item-inner grid-inner post-grid-inner\">\n        \n                \n            \r\n<figure class=\"wi-thumbnail fox-thumbnail post-item-thumbnail fox-figure  grid-thumbnail thumbnail-acute  hover-none\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\">\r\n    \r\n    <div class=\"thumbnail-inner\">\r\n    \r\n                \r\n        <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/investigation\/\" class=\"post-link\">\r\n            \r\n        \r\n            <span class=\"image-element\">\r\n\r\n                <img decoding=\"async\" width=\"480\" height=\"384\" src=\"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-content\/uploads\/sites\/13\/2022\/07\/4f08ce4d-8092-4fdf-bd8a-ecd11c58cf98-480x384.png\" class=\"attachment-thumbnail-medium size-thumbnail-medium\" alt=\"\" \/>\r\n            <\/span><!-- .image-element -->\r\n\r\n            \r\n            \r\n                    \r\n        <\/a>\r\n        \r\n                \r\n    <\/div><!-- .thumbnail-inner -->\r\n    \r\n    \r\n<\/figure><!-- .fox-thumbnail -->\r\n\r\n\n<div class=\"post-body post-item-body grid-body post-grid-body\">\n\n    <div class=\"post-body-inner\">\n\n        <div class=\"post-item-header\">\r\n<h2 class=\"post-item-title wi-post-title fox-post-title post-header-section size-small\" itemprop=\"headline\">\r\n    <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/investigation\/\" rel=\"bookmark\">        \r\n        Investigation\r\n    <\/a>\r\n<\/h2><\/div>\n    <\/div>\n\n<\/div><!-- .post-item-body -->\n\n\n        \n    <\/div><!-- .post-item-inner -->\n\n<\/article><!-- .post-item -->\n<article class=\"wi-post post-item post-grid fox-grid-item post-align- post--thumbnail-before post-10357 post type-post status-publish format-standard has-post-thumbnail hentry category-role-of-the-attorney\" itemscope itemtype=\"https:\/\/schema.org\/CreativeWork\">\n\n    <div class=\"post-item-inner grid-inner post-grid-inner\">\n        \n                \n            \r\n<figure class=\"wi-thumbnail fox-thumbnail post-item-thumbnail fox-figure  grid-thumbnail thumbnail-acute  hover-none\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\">\r\n    \r\n    <div class=\"thumbnail-inner\">\r\n    \r\n                \r\n        <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/response\/\" class=\"post-link\">\r\n            \r\n        \r\n            <span class=\"image-element\">\r\n\r\n                <img loading=\"lazy\" decoding=\"async\" width=\"480\" height=\"384\" src=\"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-content\/uploads\/sites\/13\/2022\/07\/9789a4d1-acac-4e1a-8253-5b8c0b32469a-480x384.png\" class=\"attachment-thumbnail-medium size-thumbnail-medium\" alt=\"\" \/>\r\n            <\/span><!-- .image-element -->\r\n\r\n            \r\n            \r\n                    \r\n        <\/a>\r\n        \r\n                \r\n    <\/div><!-- .thumbnail-inner -->\r\n    \r\n    \r\n<\/figure><!-- .fox-thumbnail -->\r\n\r\n\n<div class=\"post-body post-item-body grid-body post-grid-body\">\n\n    <div class=\"post-body-inner\">\n\n        <div class=\"post-item-header\">\r\n<h2 class=\"post-item-title wi-post-title fox-post-title post-header-section size-small\" itemprop=\"headline\">\r\n    <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/response\/\" rel=\"bookmark\">        \r\n        Response\r\n    <\/a>\r\n<\/h2><\/div>\n    <\/div>\n\n<\/div><!-- .post-item-body -->\n\n\n        \n    <\/div><!-- .post-item-inner -->\n\n<\/article><!-- .post-item -->\n<article class=\"wi-post post-item post-grid fox-grid-item post-align- post--thumbnail-before post-10359 post type-post status-publish format-standard has-post-thumbnail hentry category-role-of-the-attorney\" itemscope itemtype=\"https:\/\/schema.org\/CreativeWork\">\n\n    <div class=\"post-item-inner grid-inner post-grid-inner\">\n        \n                \n            \r\n<figure class=\"wi-thumbnail fox-thumbnail post-item-thumbnail fox-figure  grid-thumbnail thumbnail-acute  hover-none\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\">\r\n    \r\n    <div class=\"thumbnail-inner\">\r\n    \r\n                \r\n        <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/advising\/\" class=\"post-link\">\r\n            \r\n        \r\n            <span class=\"image-element\">\r\n\r\n                <img loading=\"lazy\" decoding=\"async\" width=\"480\" height=\"384\" src=\"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-content\/uploads\/sites\/13\/2022\/07\/7e27c4a1-7417-49b7-a998-789b81356960-480x384.png\" class=\"attachment-thumbnail-medium size-thumbnail-medium\" alt=\"\" \/>\r\n            <\/span><!-- .image-element -->\r\n\r\n            \r\n            \r\n                    \r\n        <\/a>\r\n        \r\n                \r\n    <\/div><!-- .thumbnail-inner -->\r\n    \r\n    \r\n<\/figure><!-- .fox-thumbnail -->\r\n\r\n\n<div class=\"post-body post-item-body grid-body post-grid-body\">\n\n    <div class=\"post-body-inner\">\n\n        <div class=\"post-item-header\">\r\n<h2 class=\"post-item-title wi-post-title fox-post-title post-header-section size-small\" itemprop=\"headline\">\r\n    <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/advising\/\" rel=\"bookmark\">        \r\n        Advising\r\n    <\/a>\r\n<\/h2><\/div>\n    <\/div>\n\n<\/div><!-- .post-item-body -->\n\n\n        \n    <\/div><!-- .post-item-inner -->\n\n<\/article><!-- .post-item -->\n<article class=\"wi-post post-item post-grid fox-grid-item post-align- post--thumbnail-before post-21734 post type-post status-publish format-standard has-post-thumbnail hentry category-role-of-the-attorney\" itemscope itemtype=\"https:\/\/schema.org\/CreativeWork\">\n\n    <div class=\"post-item-inner grid-inner post-grid-inner\">\n        \n                \n            \r\n<figure class=\"wi-thumbnail fox-thumbnail post-item-thumbnail fox-figure  grid-thumbnail thumbnail-acute  hover-none\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\">\r\n    \r\n    <div class=\"thumbnail-inner\">\r\n    \r\n                \r\n        <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/litigating\/\" class=\"post-link\">\r\n            \r\n        \r\n            <span class=\"image-element\">\r\n\r\n                <img loading=\"lazy\" decoding=\"async\" width=\"480\" height=\"384\" src=\"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-content\/uploads\/sites\/13\/2022\/07\/74acf7f2-3c49-4e86-970c-545db00a08d7-480x384.png\" class=\"attachment-thumbnail-medium size-thumbnail-medium\" alt=\"\" \/>\r\n            <\/span><!-- .image-element -->\r\n\r\n            \r\n            \r\n                    \r\n        <\/a>\r\n        \r\n                \r\n    <\/div><!-- .thumbnail-inner -->\r\n    \r\n    \r\n<\/figure><!-- .fox-thumbnail -->\r\n\r\n\n<div class=\"post-body post-item-body grid-body post-grid-body\">\n\n    <div class=\"post-body-inner\">\n\n        <div class=\"post-item-header\">\r\n<h2 class=\"post-item-title wi-post-title fox-post-title post-header-section size-small\" itemprop=\"headline\">\r\n    <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/litigating\/\" rel=\"bookmark\">        \r\n        Litigating\r\n    <\/a>\r\n<\/h2><\/div>\n    <\/div>\n\n<\/div><!-- .post-item-body -->\n\n\n        \n    <\/div><!-- .post-item-inner -->\n\n<\/article><!-- .post-item -->\n<article class=\"wi-post post-item post-grid fox-grid-item post-align- post--thumbnail-before post-21740 post type-post status-publish format-standard has-post-thumbnail hentry category-role-of-the-attorney\" itemscope itemtype=\"https:\/\/schema.org\/CreativeWork\">\n\n    <div class=\"post-item-inner grid-inner post-grid-inner\">\n        \n                \n            \r\n<figure class=\"wi-thumbnail fox-thumbnail post-item-thumbnail fox-figure  grid-thumbnail thumbnail-acute  hover-none\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\">\r\n    \r\n    <div class=\"thumbnail-inner\">\r\n    \r\n                \r\n        <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/negotiating\/\" class=\"post-link\">\r\n            \r\n        \r\n            <span class=\"image-element\">\r\n\r\n                <img loading=\"lazy\" decoding=\"async\" width=\"480\" height=\"384\" src=\"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-content\/uploads\/sites\/13\/2022\/07\/ab01545d-d89f-4eba-a774-b7b81e7cc3bd-480x384.png\" class=\"attachment-thumbnail-medium size-thumbnail-medium\" alt=\"\" \/>\r\n            <\/span><!-- .image-element -->\r\n\r\n            \r\n            \r\n                    \r\n        <\/a>\r\n        \r\n                \r\n    <\/div><!-- .thumbnail-inner -->\r\n    \r\n    \r\n<\/figure><!-- .fox-thumbnail -->\r\n\r\n\n<div class=\"post-body post-item-body grid-body post-grid-body\">\n\n    <div class=\"post-body-inner\">\n\n        <div class=\"post-item-header\">\r\n<h2 class=\"post-item-title wi-post-title fox-post-title post-header-section size-small\" itemprop=\"headline\">\r\n    <a href=\"https:\/\/vanleeuwenlawfirm.eu\/en\/about\/role-of-the-attorney\/negotiating\/\" rel=\"bookmark\">        \r\n        Negotiating\r\n    <\/a>\r\n<\/h2><\/div>\n    <\/div>\n\n<\/div><!-- .post-item-body -->\n\n\n        \n    <\/div><!-- .post-item-inner -->\n\n<\/article><!-- .post-item -->        \r\n            \r\n    <\/div><!-- .fox-blog -->\r\n    \r\n        \r\n<\/div><!-- .fox-blog-container -->\r\n\r\n    \t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Data Processors operate in the shadow of the Controller but bear a set of strict obligations to ensure the confidentiality, integrity, and availability of personal data. This role not only involves following documented instructions but also actively supporting the Controller in complying with complex GDPR obligations. Operational processes must be designed in such a way that every step in the data processing chain is verifiable, from data intake and processing to archiving and deletion. Technical measures\u2014such as encryption, access management, and logging\u2014must never be considered in isolation from organizational controls, such as training, contract management, and incident response organizations. At<\/p>\n","protected":false},"author":3,"featured_media":28997,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[515],"tags":[],"class_list":["post-480","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-privacy-data-and-cybersecurity"],"acf":[],"_links":{"self":[{"href":"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-json\/wp\/v2\/posts\/480","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-json\/wp\/v2\/comments?post=480"}],"version-history":[{"count":12,"href":"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-json\/wp\/v2\/posts\/480\/revisions"}],"predecessor-version":[{"id":29354,"href":"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-json\/wp\/v2\/posts\/480\/revisions\/29354"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-json\/wp\/v2\/media\/28997"}],"wp:attachment":[{"href":"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-json\/wp\/v2\/media?parent=480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-json\/wp\/v2\/categories?post=480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vanleeuwenlawfirm.eu\/en\/wp-json\/wp\/v2\/tags?post=480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}