# Entrusting your data to a service provider without losing control

URL : https://skillrung.com/en/courses/data-compliance/sharing-data-with-providers
Topic: Compliance & personal data · Duration: 20-30 min · Updated on 2026-09-15

## In brief

Outsourcing processing does not move responsibility: it adds a written obligation. Each party's role is read in the facts, who decides the use and who carries it out, not in what the contract proclaims. Article 28 of the GDPR requires a written contract, which is worth exactly the concrete measures it describes. Two questions remain before signing: where your data will be processed, and which law that supplier is subject to.

## Programme

- 1. Before you hand your data to someone else : Place your own responsibility when a third party processes data on your behalf
- 2. Sharing, outsourcing, hosting elsewhere : Check what a service provider does with your data before entrusting it to them
- 3. Your action plan : Go back over, one by one, the providers that already hold your data

1 content sections, each with its quiz. Three level quizzes: Beginner, Intermediate, Expert.

## Free preview (first 4 slides)

### 1. The tool is theirs, the responsibility stays yours

Count the service providers that touch the data of your structure: the vendor of your business software, the host, the file-sharing service, the accountancy firm. You wrote none of those tools and you administer none of those servers. But the person whose information is circulating knows only you. This course starts from there: what moves to a provider is the work, never the responsibility.

### 2. What you will be able to do next

- Tell a controller from a processor on the basis of the facts
- Spot what is missing from a processing contract
- Question a supplier about the place of processing and the applicable law

### 3. The four checks you will be able to carry out

Four points to go back over for every provider already in place, and for every tool you are about to adopt.
- Each party's real role, read in the facts
- The content of the written contract, security measures included
- The place of processing and the law applicable to the supplier
- A change of sub-processor announced along the way

### 4. Where do you stand?

One question before you start, to see where you stand. Nobody marks your answer.
_Self-assessment of 1 questions in the player._

## Access

The first four slides of every course and the Beginner-level quiz are free, with no account. From the fifth slide onwards a subscription is required: €29.99/month incl. VAT, no commitment, cancellable online. skillrung is not a French training body certified under the Qualiopi scheme; its content is not eligible for the French CPF, OPCO or DPC schemes.

## Frequently asked questions

### Is a written contract really mandatory with a service provider?

Yes. Article 28 of the GDPR requires a written contract between the controller and its processor. But a document that merely refers back to the Regulation is not enough: it must name the subject matter, the duration, the purpose and the categories of data, describe concrete security measures, provide for the assistance expected and settle what happens to the data at the end.

### My provider is established in Europe: does that settle the question of transfers?

Not necessarily. What has to be checked is where your data is actually processed and which law applies to the supplier and to its own sub-processors. European servers can be administered from a third country, and a subsidiary belonging to a foreign group can be exposed to the law of its parent company. A transfer outside the European Union must be framed by one of the legal tools provided for by the Regulation.

### My provider announces that it is entrusting part of the work to another company: what do I do?

You examine it, you do not file it away. Even when provided for in the contract, a general authorisation to use sub-processors takes nothing away from you: it obliges the provider to notify you of every addition or replacement, precisely so that you can object. Look at the new access to the data, at what frames processing from a third country, and at what your contract says about the objection period. Then record the decision and update your record of processing activities.

## Sources

- Règlement (UE) 2016/679 du Parlement européen et du Conseil du 27 avril 2016 (RGPD) : EUR-Lex, Union européenne, 2016-04-27, https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32016R0679
- Le registre des activités de traitement : CNIL, 2026-09-11, https://www.cnil.fr/fr/RGPD-le-registre-des-activites-de-traitement
- Les bases légales d'un traitement de données personnelles : CNIL, 2026-09-11, https://www.cnil.fr/fr/les-bases-legales
- Les durées de conservation des données : CNIL, 2026-09-11, https://www.cnil.fr/fr/passer-laction/les-durees-de-conservation-des-donnees
- Professionnels : comment répondre à une demande de droit d'accès ? : CNIL, 2026-09-11, https://www.cnil.fr/fr/repondre-une-demande-de-droit-dacces
- Travailler avec un sous-traitant : CNIL, 2026-09-11, https://www.cnil.fr/fr/sous-traitant
- Notifier une violation de données personnelles : CNIL, 2026-09-11, https://www.cnil.fr/fr/services-en-ligne/notifier-une-violation-de-donnees-personnelles
- Transférer des données hors de l'Union européenne : CNIL, 2026-09-11, https://www.cnil.fr/fr/les-outils-de-la-conformite/transferer-des-donnees-hors-de-lue
