{"id":9039,"date":"2022-02-01T17:54:33","date_gmt":"2022-02-01T16:54:33","guid":{"rendered":"https:\/\/www.cabinetbouchara.com\/sous-traitant\/"},"modified":"2026-02-10T08:57:14","modified_gmt":"2026-02-10T07:57:14","slug":"subcontractor","status":"publish","type":"page","link":"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/subcontractor\/","title":{"rendered":"Subcontractor"},"content":{"rendered":"<p><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/\">Lexicon<\/a> <span style=\"color: #F5B63F\">&gt; <span style=\"color: #F5B63F\"><span><b>Subcontractor<\/b><\/span><\/span><\/span><\/p>\n<p>IT Glossary<\/p>\n<p style=\"text-align: justify\">The processor is the natural or legal person who processes <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/personal-data\/\" target=\"_blank\" rel=\"noopener noreferrer\">personal data<\/a> on behalf of the <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/person-in-charge-of-the-treatment\/\" target=\"_blank\" rel=\"noopener noreferrer\">controller<\/a>.<\/p>\n<p style=\"text-align: justify\">The processor must serve the interest of the controller by performing a specific task and following the instructions given by the controller, at least with regard to the <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/purpose\/\" target=\"_blank\" rel=\"noopener noreferrer\">purpose<\/a> and the essential elements of the means.<\/p>\n<p style=\"text-align: justify\">The processor may, however, enjoy a certain degree of autonomy in carrying out the outsourced processing and thus define the non-essential elements of the <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/data-processing\/\" target=\"_blank\" rel=\"noopener noreferrer\">processing<\/a> operation.<\/p>\n<p style=\"text-align: justify\">However, when a subcontractor acts contrary to the instructions of the <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/person-in-charge-of-the-treatment\/\" target=\"_blank\" rel=\"noopener noreferrer\">responsible for<\/a> the processing, including making decisions about the purpose and the essential elements of the means of processing, it may then be reclassified as a controller and thus subject to the obligations of the latter enshrined in the <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/gdrp\/\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR<\/a>.<\/p>\n<p style=\"text-align: justify\">The controller may only use a processor who provides sufficient guarantees that appropriate technical and organizational measures have been implemented so that the processing meets the requirements of the GDPR and ensures the protection of the data subject.<\/p>\n<p style=\"text-align: justify\">This includes considering the outsourcer&#8217;s expertise, reliability, and resources before outsourcing the processing.<\/p>\n<p style=\"text-align: justify\">In any case, the processing carried out by the processor must be governed by a legal act such as a contract that binds the processor to the controller defining in particular:<\/p>\n<ul>\n<li style=\"text-align: justify\">Purpose of treatment;<\/li>\n<li style=\"text-align: justify\">Duration of treatment;<\/li>\n<li style=\"text-align: justify\">The nature of the treatment;<\/li>\n<li style=\"text-align: justify\">The <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/purpose\/\" target=\"_blank\" rel=\"noopener noreferrer\">purpose of<\/a> the processing;<\/li>\n<li style=\"text-align: justify\">The type of personal data used;<\/li>\n<li style=\"text-align: justify\">Categories of people involved;<\/li>\n<li style=\"text-align: justify\">The obligations and rights of the data controller.<\/li>\n<\/ul>\n<p style=\"text-align: justify\">This act must also specify that the subcontractor does not process <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/personal-data\/\" target=\"_blank\" rel=\"noopener noreferrer\">personal data<\/a> only upon documented instruction from the <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/person-in-charge-of-the-treatment\/\" target=\"_blank\" rel=\"noopener noreferrer\">responsible for the processing<\/a>, that it ensures that the persons authorized to process personal data undertake to respect the <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/privacy\/\" target=\"_blank\" rel=\"noopener noreferrer\">confidentiality<\/a>, that it complies with the conditions for recruiting another processor, that it takes into account the nature of the processing and that it assists the controller in fulfilling its obligation to respond to requests from data subjects.<\/p>\n<h2>GDPR focus<\/h2>\n<p style=\"text-align: justify\"><span>&#8220;<\/span><i><span>In order to ensure that the requirements of this Regulation are met in the context of processing carried out by a processor on behalf of the controller, where the controller entrusts processing activities to a processor, the controller should only use processors providing sufficient guarantees, in particular in terms of expertise, reliability and resources, for the implementation of technical and organisational measures that will meet the requirements of this Regulation, including security of processing. A processor&#8217;s application of an approved code of conduct or certification scheme may be used to demonstrate compliance with the controller&#8217;s obligations.<\/span><\/i><span>&#8221; <\/span><\/p>\n<p style=\"text-align: justify\"><span>Recital 81 of the GDPR<\/span><\/p>\n<h2 style=\"text-align: justify\">Case law focus\u00a0<\/h2>\n<p style=\"text-align: justify\"><span>The CNIL points out that <\/span><i><span>&#8220;Article 28 of the GDPR provides various concrete guarantees in terms of data protection, for example by providing for the implementation of security measures or the assistance that must be provided by the processor to the data controller in exercising its rights.<\/span><\/i><span>&#8220;<\/span><\/p>\n<p style=\"text-align: justify\"><span>CNIL, July 16, 2021, N\u00b0 SAN-2021-012<\/span><\/p>\n<p style=\"text-align: justify\">The Bouchara firm assists you in particular in :<\/p>\n<ul style=\"text-align: justify\">\n<li>Making your organization <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/gdrp\/\" target=\"_blank\" rel=\"noopener noreferrer\">GDPR<\/a>\u00a0compliant;<\/li>\n<li>The drafting of data protection policies (privacy policy, computer charter &#8230;);<\/li>\n<li>Documentation of your processing (register of processing activities, register of violations, privacy <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/data-privacy-impact-assessment-dpa\/\" target=\"_blank\" rel=\"noopener noreferrer\">impact analysis<\/a>, prior consultation&#8230;);<\/li>\n<li>Obtaining certifications and adhering to <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/code-of-conduct\/\" target=\"_blank\" rel=\"noopener noreferrer\">codes of conduct<\/a>;<\/li>\n<li>The study of the legal feasibility of the implementation of a new <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/data-processing\/\" target=\"_blank\" rel=\"noopener noreferrer\">personal data processing<\/a>;<\/li>\n<li>The drafting and transmission of your codes of conduct to the <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/national-commission-for-information-technology-and-civil-liberties-cnil\/\" target=\"_blank\" rel=\"noopener noreferrer\">CNIL<\/a> for approval;<\/li>\n<li>Legal analysis of the compliance of your data processing, including data transfers outside the European Economic Area;<\/li>\n<li>Drafting and negotiating your data processing agreements (DPA);<\/li>\n<li>Drafting your Binding Corporate Rules (BCR) and Codes of Conduct;<\/li>\n<li>Training and awareness of your employees.<\/li>\n<\/ul>\n<p style=\"text-align: justify\">We are also the external <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/data-protection-officer-dpo\/\" target=\"_blank\" rel=\"noopener noreferrer\">Data Protection Officer<\/a> of many data <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/person-in-charge-of-the-treatment\/\" target=\"_blank\" rel=\"noopener noreferrer\">processors<\/a> and <a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/subcontractor\/\" target=\"_blank\" rel=\"noopener noreferrer\">subcontractors<\/a>.<\/p>\n<h2>Other definitions<\/h2>\n<h3><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/brand\/\">Trademark<\/a><\/h3>\n<p><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/brand\/\">A trademark is a distinctive sign allowing its owner (natural or legal person) to differentiate its products and services&#8230;<\/a><\/p>\n<h3><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/gdrp\/\">GDPR<\/a><\/h3>\n<p><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/gdrp\/\">The GDPR refers to Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals&#8230;<\/a><\/p>\n<h3><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/renowned-or-well-known-trademark\/\">Well-known trademark<\/a><\/h3>\n<p><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/renowned-or-well-known-trademark\/\">The concepts of reputed and well-known trademarks have been defined by the jurisprudence and designate a trademark that is widely known by the public&#8230;<\/a><\/p>\n<h3><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/wipo\/\">WIPO<\/a><\/h3>\n<p><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/wipo\/\">The World Intellectual Property Organization (WIPO) is an international institution of the United Nations, located in Geneva&#8230;<\/a><\/p>\n<p><a href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/\">See the lexicon<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.cabinetbouchara.com\/wp-content\/uploads\/2021\/12\/Fichier-24.svg\" width=\"25\" height=\"25\" alt=\"\" class=\"wp-image-1012 alignnone size-medium\" style=\"margin-left: 15px;margin-bottom: -6px\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lexicon &gt; Subcontractor IT Glossary The processor is the natural or legal person who processes personal data on behalf of the controller. The processor must serve the interest of the controller by performing a specific task and following the instructions given by the controller, at least with regard to the purpose and the essential elements &#8230; <a title=\"Subcontractor\" class=\"read-more\" href=\"https:\/\/www.cabinetbouchara.com\/en\/lexicon\/subcontractor\/\" aria-label=\"Read more about Subcontractor\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":9175,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-9039","page","type-page","status-publish"],"_links":{"self":[{"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/pages\/9039","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/comments?post=9039"}],"version-history":[{"count":6,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/pages\/9039\/revisions"}],"predecessor-version":[{"id":19550,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/pages\/9039\/revisions\/19550"}],"up":[{"embeddable":true,"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/pages\/9175"}],"wp:attachment":[{"href":"https:\/\/www.cabinetbouchara.com\/en\/wp-json\/wp\/v2\/media?parent=9039"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}