A third party can view or manage the footage, and no agreement is recorded
A monitoring company, a vendor cloud, a landlord or another group company that views or holds your footage is not a processor by default. It may be a processor (GDPR and UK GDPR Art. 28: a written contract with set terms), a joint controller (Art. 26: an arrangement allocating responsibilities), an independent controller or a recipient. The CCPA asks for a written contract with a service provider or contractor; for face matching in Illinois, BIPA 15(d) treats handing biometric data to a vendor as a disclosure that needs consent.
- When it is raised
- Raised when who can view names a vendor, monitoring or security company, landlord, integrator or other entity, or the footage is stored in a vendor cloud, and the processor terms column is blank or no.
- The question
- What is this party's role (processor, joint controller, independent controller or recipient), and which agreement governs it?
- For
- your privacy lead
- The column that settles it
- processor terms
- On the row
- a numbered delta and the words "third party role" in small capitals; an outlined delta where it rests on a blank column
Clauses by regime
GDPR (the EU General Data Protection Regulation)
GDPR Art. 28ProcessorProcessor. Use only processors providing sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the Regulation's requirements and protects the rights of the data subject. A processor must not engage another processor without the controller's prior specific or general written authorisation, and under a general authorisation must inform the controller of intended additions or replacements so the controller can object. The processing must be governed by a written contract or other legal act binding the processor to the controller, setting out the subject matter and duration, the nature and purpose, the type of personal data, the categories of data subjects and the controller's obligations and rights, and stipulating that the processor processes only on documented controller instructions including as to transfers, ensures persons authorised to process are under a duty of confidentiality, takes all Article 32 measures, respects the sub-processor conditions, assists the controller in responding to data subject rights requests, assists with Articles 32 to 36, deletes or returns all personal data at the controller's choice at the end of the service and deletes existing copies unless law requires retention, and makes available all information needed to demonstrate compliance and allows for and contributes to audits and inspections. The processor must immediately inform the controller if it considers an instruction infringes data protection law. The same obligations must be imposed on any sub-processor, and the initial processor remains fully liable for the sub-processor's performance. A processor that determines purposes and means is a controller for that processing.
GDPR Art. 26Joint controllersJoint controllers. Where two or more controllers jointly determine the purposes and means of processing, determine their respective responsibilities for compliance in a transparent manner by an arrangement between them, unless those responsibilities are already determined by Union or Member State law, covering in particular the exercise of the data subject's rights and each party's duty to provide the Article 13 and 14 information. The arrangement may designate a contact point for data subjects. It must duly reflect the parties' respective roles and relationships towards data subjects, and its essence must be made available to the data subject. Irrespective of the terms of the arrangement, a data subject may exercise their rights in respect of and against each of the controllers.
UK GDPR
UK GDPR Art. 28ProcessorArticle 28 Processor. A controller may use only processors giving sufficient guarantees of appropriate measures. A processor may not engage a sub-processor without prior specific or general written authorisation, and under general authorisation must notify changes so the controller can object. Processing must be governed by a written contract or legal act setting out the subject matter, duration, nature, purpose, data types, data subjects and the controller's rights and obligations, and requiring the processor to act only on documented instructions (including on transfers), bind its staff to confidentiality, take Article 32 measures, respect sub-processing conditions, assist with rights requests and with Articles 32 to 36, delete or return data at the end, and provide information and allow audits, informing the controller if an instruction infringes the law. Sub-processors carry the same obligations and the processor stays liable for them. The Commissioner may adopt standard contractual clauses; a processor that determines purposes and means is treated as a controller.
UK GDPR Art. 26Joint controllersArticle 26 Joint controllers. Joint controllers must determine their respective responsibilities, in particular for data subject rights and the information duties, by an arrangement that reflects their roles and relationships, may designate a contact point, and must make the essence of the arrangement available to data subjects, who may exercise their rights against each of them.
California Consumer Privacy Act (CCPA, as amended by the CPRA)
CCPA s. 1798.100(d)Contractual Requirements for Third Parties, Service Providers, and ContractorsContractual Requirements for Third Parties, Service Providers, and Contractors. A business that collects PI and sells/shares it with a third party or discloses it to a service provider or contractor must enter into a written contract that specifies purposes, prohibits selling/sharing/retaining/using/disclosing PI for any purpose other than those specified, prohibits combining with PI from other sources except as permitted, requires same level of protection, grants the business audit/inspection rights, and requires notification if recipient can no longer meet obligations.
Illinois Biometric Information Privacy Act (BIPA)
BIPA s. 15(d)No disclosure, redisclosure or dissemination except on four groundsNo disclosure, redisclosure or dissemination except on four grounds. No private entity in possession of a biometric identifier or biometric information may disclose, redisclose or otherwise disseminate a person's or customer's biometric identifier or biometric information unless the subject or the subject's legally authorized representative consents to the disclosure or redisclosure; or the disclosure completes a financial transaction requested or authorized by the subject or representative; or the disclosure is required by State or federal law or municipal ordinance; or the disclosure is required by a valid warrant or subpoena issued by a court of competent jurisdiction. Transfer to a vendor or cloud provider is a disclosure that needs consent. Under section 20(c) as amended in 2024, repeated disclosure of the same identifier from the same person to the same recipient by the same method is a single violation with at most one recovery.