Whoever works on your data brings a processing agreement
Anyone who gets access to your systems processes personal data on your behalf. Why a processing agreement belongs on the table before the first login.
A BI project usually starts with a request for access. To your accounting, your ERP, your till, sometimes your payroll provider. That access gets handed over quickly, because you want to move on.
What rarely sits next to it is a data processing agreement. And it should be there, before the first login.
Why it is needed
As soon as someone processes personal data on your behalf, GDPR calls them a processor. That is not a grey zone. Your sources almost always contain personal data: customer names, contact people at suppliers, the pay and absence of your staff.
GDPR then requires a written agreement. You remain responsible for that data, even when someone else is working on it. The agreement is how you live up to that responsibility.
What belongs in it
Not thirty pages of legal language. A handful of agreements:
- What for: which data, about whom, and for what purpose. No more than the project needs.
- Only on instruction: the processor uses your data for your assignment and for nothing else.
- Security: how access is arranged, where the data is stored and how it is protected.
- Who else touches it: the cloud services your partner uses are processors too. You should know which ones they are and where their servers are.
- Leaks: how quickly you are told when something goes wrong. You have to report a leak to the data protection authority within 72 hours, so your partner has to be faster.
- The end: what happens to your data when the collaboration stops.
The questions you ask
You do not need to be a lawyer to see whether a partner takes this seriously. Ask:
- Do you have a standard processing agreement?
- Which services do you use to store or process my data?
- Is that data inside the EU?
- Do you only get read access to my systems?
- What happens to my data when we stop?
Whoever answers those smoothly has already thought about it. Whoever has to go looking, has not yet.
What GDPR asks of your reports themselves is covered in GDPR and your dashboards.
The signal it sends
A partner who brings a processing agreement without being asked is telling you something about how they work. They know which data they need, where it ends up and how long it stays. Those are the same questions a good data model answers.
The claim
The processing agreement is not a formality after the project. It is the first question you ask whoever gets your keys.