The GDPR broadens and deepens the rules between data controllers and data processors for processing of personal data and for the first time, directly enforceable obligations are imposed on processors as well as controllers.
The GDPR also requires that controllers and processors enter into written contracts (“C2P Clauses”). Practical Law recently published its data processing clauses (GDPR version), designed by the writer and colleagues, to assist with this requirement. This blog post seeks to provide background to the many considerations behind the development of these clauses which will help the user understand their crucial compliance role. Continue reading







