Appendix: Data Processor Agreement

The data controller must have a Data Processor Agreement with any third party with whom the data controller shares video surveillance media except for sharing video surveillance media with law enforcement.

If an organization outsources all or part of its video surveillance activities to a third party (a data processor), it remains liable for compliance with GDPR as a data controller. For example, security guards monitoring live surveillance video in the reception area of an organization working for a private company to whom the organization outsourced the task of live monitoring. In this case, the organization must ensure that the security guards carry out their activities in compliance with the provisions of the GDPR.

For a sample template of a Data Processor Agreement, see the Milestone Data Processor Agreement template.

Disclaimer: The sample Data Processor Agreement must be checked by the data controller. GDPR compliance using this sample is his area of responsibility.