HomeAnalytics › Jurisdiction: What data protection basis applies – supply risk

Jurisdiction: What data protection basis applies – supply risk

The data protection legal basis that applies to a given supply chain relationship depends on the jurisdiction where processing takes place. The role each party plays (controller or processor), the category of data involved. Additionally, the specific purpose of processing. For most commercial supply relationships operating within the European Economic Area, the General Data Protection Regulation (GDPR) sets the governing framework. outside the EEA. An overlapping patchwork of national laws, adequacy decisions. Additionally, sector-specific regulations determines compliance obligations. Getting this wrong at the contracting stage creates enforcement exposure, contractual voidability risk, and – in cross-border chains – parallel regulatory liability across multiple authorities simultaneously.

Why Jurisdiction Determines the Legal Basis

Data protection law does not follow the governing law clause of a commercial contract. It follows the location of processing, the establishment of the data controller. Additionally. The habitual residence of the data subjects. criteria that can point to entirely different legal orders than the law chosen by the parties for their supply agreement. This jurisdictional mismatch is the single most common compliance gap identified in supply chain due diligence exercises.

Within the EEA, the GDPR applies whenever a controller or processor is established in a Member State, regardless of where the actual data processing servers are located. It also applies to controllers outside the EEA if they process personal data of individuals who are in the EEA in connection with offering goods or services or monitoring their behaviour. A supplier headquartered in a non-EEA country that receives employee or customer data from an EEA-based buyer is therefore subject to the GDPR – a fact frequently overlooked in inbound supply contract negotiations.

Outside the EEA, the applicable framework shifts dramatically. The United Kingdom's UK GDPR and the Data Protection Act 2018 largely mirror the EEA regime post-Brexit, but divergences are accumulating. In the United States, there is no single federal framework: sector laws (HIPAA for health data, GLBA for financial data. FERPA for education records) and a growing body of state privacy laws. most significantly California's CCPA/CPRA. apply in parallel, with no single supervisory authority. Brazil's Lei Geral de Proteção de Dados (LGPD) introduced a unified framework modelled on the GDPR. Across Southeast Asia, ASEAN member states have varying national laws. In the Gulf, both the UAE and Saudi Arabia have enacted recent data protection legislation at the federal or sector level.

The Six Legal Bases Under GDPR – and How They Apply to Supply Relationships

For any supply relationship subject to the GDPR. The controller (typically the buyer or the party that determines the purpose and means of processing) must identify a valid legal basis for each processing activity before processing begins. There are six possible bases:

Consent is rarely the appropriate basis in commercial supply chains involving employee data, because consent must be freely given and is difficult to demonstrate when there is a power imbalance between employer and employee. Using consent for employee data processing is therefore high-risk in an enforcement context.

Contract performance covers processing that is strictly necessary to perform the contract to which the data subject is a party. This basis is narrowly construed: it does not extend to processing that is merely convenient for the supplier or that serves the controller's broader commercial interests.

Legal obligation applies when processing is required to comply with an EU or Member State law. Anti-money laundering checks, export control screening of sub-suppliers, and mandatory reporting to tax authorities are common examples in a supply context.

Vital interests applies only in emergency situations involving risk to life and has very limited relevance to standard commercial supply chains.

Public task applies to public authorities and entities exercising official authority. It is not available to private commercial parties.

Legitimate interests is the basis most frequently invoked in business-to-business supply relationships where no other basis fits. It requires a three-part balancing test: the controller must demonstrate a legitimate interest, that the processing is necessary to achieve it, and that the interest is not overridden by the data subject's rights and freedoms. The outcome of this balancing test is not predetermined and must be documented in a Legitimate Interests Assessment (LIA). Reliance on legitimate interests without a documented LIA is itself a compliance failure.

Special Categories of Data in Supply Chains

If the supply relationship involves processing of special category data. health data, biometric data, trade union membership, racial or ethnic origin. Religious belief, political opinion, genetic data, sexual orientation. Alternatively, data on criminal convictions and offences. no ordinary legal basis is sufficient. An additional condition under Article 9 GDPR (or its national equivalents) must also be met. The most frequently applicable conditions in a supply context are:

Explicit consent of the data subject (subject to the same power-imbalance concerns described above), processing necessary for employment law obligations (e.g., occupational health data for workplace safety compliance). processing necessary for the establishment, exercise. Alternatively, defence of legal claims. Additionally, substantial public interest under Member State law. The last condition requires a specific national legislative basis and cannot be self-certified by the controller.

In practical supply chain terms, health data arises most often in the context of sub-contractor workforce management, access control systems using biometric authentication, and medical screening requirements at certain industrial facilities. Each of these use cases must be assessed against both the standard legal basis and the Article 9 additional condition.

Controller, Processor, and Joint Controller: Getting the Roles Right

The legal basis question cannot be answered without first establishing who is the controller and who is the processor in each processing activity. This determination is not contractual – it follows from the factual reality of who determines the purpose and means of processing. A supplier that merely processes personal data on behalf of the buyer, following the buyer's instructions, is a processor. A supplier that independently decides how to use that data – even data initially provided by the buyer – acts as a controller for that activity and must identify its own legal basis.

Joint controllership arises when two or more parties jointly determine the purposes and means of processing. This is common in integrated supply chain platforms, shared logistics systems, and joint marketing arrangements where both parties derive independent benefit from the same dataset. Joint controllers must enter into a transparent arrangement governing their respective responsibilities, and the essential terms of that arrangement must be made available to data subjects.

Mischaracterising a controller as a processor (or vice versa) in a Data Processing Agreement (DPA) does not cure the underlying compliance failure. Supervisory authorities look to the factual substance of the relationship, not the contractual label.

Cross-Border Transfers in the Supply Chain

Every transfer of personal data from an EEA entity to a recipient in a country outside the EEA requires either an adequacy decision covering that country. appropriate safeguards (the most common being Standard Contractual Clauses. Alternatively, SCCs, issued by the European Commission). Alternatively, reliance on a narrow derogation. The SCCs adopted in 2021 include specific module combinations for controller-to-processor and controller-to-controller transfers, and for processor-to-processor and processor-to-controller transfers – covering the main permutations found in multi-tier supply chains.

Transfers to the United Kingdom currently rely on the EU-UK adequacy decisions adopted in 2021, which are subject to periodic review and carry an expiry mechanism. Transfers to the United States may rely on the EU-US Data Privacy Framework, following the adequacy decision adopted in 2023. However. Only for US organisations that have self-certified under that framework. the self-certification status of individual US suppliers must be verified at the time of contracting and monitored for ongoing validity.

Sub-processing – the practice of a processor engaging a further sub-processor – requires prior specific or general written authorisation from the controller. In supply chains with multiple tiers, this requirement cascades down the chain. A DPA that grants general authorisation for sub-processing typically also requires the processor to notify the controller of any intended changes and to give the controller the opportunity to object.

Identifying and Documenting the Legal Basis: Practical Steps Before Contracting

Map the data flows before drafting the DPA. Without knowing what personal data moves between which entities. For what purpose. Additionally, to which countries, it is impossible to select the correct legal basis or the appropriate transfer mechanism. Data flow mapping should be conducted as part of commercial due diligence, not left to the compliance team after signature.

Document the legal basis in the Record of Processing Activities (RoPA). Article 30 GDPR requires controllers and processors meeting the threshold criteria to maintain a RoPA. The RoPA must record the legal basis for each processing activity. In a supply chain context, this means the buyer's RoPA should document the processing carried out by suppliers acting as processors on its behalf, alongside the buyer's own processing as controller.

Conduct a Transfer Impact Assessment (TIA) for non-adequate third countries. Where SCCs are used as the transfer mechanism. The European Data Protection Board's guidance requires the exporter to assess whether the legal order of the destination country provides essentially equivalent protection to that guaranteed within the EEA. A TIA is required even if SCCs are in place. The assessment must be documented and must specifically address government access powers in the destination country.

Review supplier privacy notices. Where the supplier processes data directly with data subjects (e.g., in direct-to-consumer logistics, warranty registration, or after-sales service), its privacy notice must accurately describe the legal basis used. A privacy notice that lists the wrong legal basis – or omits a processing activity altogether – is a standalone violation independent of any underlying contractual failure.

Build review triggers into the supply agreement. The legal basis landscape changes: adequacy decisions are reviewed, national implementing laws are amended, and supervisory authority guidance refines the interpretation of established concepts. A supply agreement that locks in a static compliance posture without change-management provisions will be out of date within its own term in most active jurisdictions.

Enforcement Patterns and Supply Chain Risk

Supervisory authority enforcement increasingly targets supply chains directly rather than limiting action to the buyer-controller. Processors have been fined in their own right for failing to process only on documented controller instructions, for engaging sub-processors without authorisation, and for implementing inadequate technical and organisational measures. In cross-border supply chains, the GDPR's one-stop-shop mechanism determines which lead supervisory authority handles complaints and investigations. However. Authorities in affected Member States retain concurrent powers in certain circumstances. meaning a single supply chain failure can attract parallel regulatory attention from multiple national authorities.

The exposure profile is asymmetric: the cost of a documented compliance programme implemented at contracting stage is small relative to the potential cost of an enforcement action. Contractual indemnity claim. Alternatively, reputational damage arising from a notifiable data breach originating in a supplier's systems. Under the GDPR, a personal data breach affecting data processed by a processor must be notified to the controller without undue delay. the controller then determines whether the breach must be notified to the supervisory authority and. If it poses a high risk to data subjects, to the data subjects themselves. Supply chain breaches are almost always multi-party events, and the contractual allocation of notification obligations and costs must be addressed in the DPA before an incident occurs.

When to Seek Legal Advice

The legal basis determination for a cross-jurisdictional supply relationship is not a compliance checkbox. It is a legal analysis that must account for the applicable law in each processing location, the factual structure of the supply relationship, the categories of data involved, and the transfer mechanisms in use. A mistaken legal basis selection – particularly the over-reliance on consent or contract performance where neither is properly applicable – can invalidate the entire processing operation and expose the controller to enforcement action.

Organisations that are restructuring their supply chains, onboarding suppliers in new jurisdictions. Alternatively. Reviewing legacy DPAs in light of updated SCCs or changed adequacy decisions should treat the legal basis review as a priority legal task rather than a back-office compliance formality. The consequences of getting it wrong are operational (processing must cease), financial (administrative fines), and reputational (mandatory public reporting of certain enforcement decisions by supervisory authorities).

For assistance with data protection legal basis analysis across jurisdictions in the context of supply chain contracting or due diligence, contact Ferraz & Whitmore at info@ferrazwhitmore.com or visit our contacts page.

Disclaimer: This article is provided for informational purposes only and does not constitute legal advice. The analysis reflects the state of applicable law and regulatory guidance as understood at the publication date. Data protection law is subject to frequent legislative amendment, supervisory authority guidance updates, and court decisions that may alter the conclusions set out above. Readers should seek independent legal advice tailored to their specific circumstances before acting on any information contained in this article. No attorney-client relationship is created by accessing or reading this content.

Reviewed by
Legal Analyst · Western Europe