Who is responsible for complying with data protection legislation (including the POPI Act in South Africa and the GDPR) where you process personal information together with someone else? Most organisations have many relationships where they process personal information together with other organisations, including customer-service-provider, vendor-buyer, and contractor-client relationships.

POPI distinguishes between the ‘responsible party’ and the ‘operator’, while the GDPR distinguishes between the ‘data controller’ and the ‘data processor’. We will refer to them simply as the ‘responsible party’ and the ‘operator’. The ‘responsible party’ decides the purpose or ‘way’ of processing the personal information and the ‘operator’ processes the personal information on behalf of a responsible party without being directly controlled by them. The responsible party carries most of the responsibility, while the operator carries much less.

Where you process personal information together with someone else, whether you are the responsible party or the operator depends on your relationship with them.

What different types of relationships are there?

Organisations often instruct other organisations to process personal information on their behalf or are instructed to do so by them. In a relationship between a client and a service provider, the customer generally instructs the service provider. But, the organisation doing the instructing isn’t always the responsible party and the organisation being instructed isn’t always the operator. It can be difficult to pinpoint who is playing which role. We will see this by examining the three different types of relationships: authority, liberty, and equality. Please click through the tabs to read about them.

We can help you to understand your relationships and responsibilities under data protection legislation with a Data Protection Responsibility Assessment.

Your relationships and working out who is responsible

Most relationships are more complicated than these examples and fall somewhere between these three categories. They may also shift categories from one activity to another.

With a Data Protection Responsibility Assessment, we can help you understand your relationships and responsibilities under data protection legislation.

Interested?

If you are interested, please complete the form on the right or enquire now. We will contact you to find out more about your requirements and give you a quote.