Hi Simon,
I think the issue is whether the third party is processing data on the data controllers behalf. The fact that it is 'voluntary' (?), does not affect the DC - DP relationship, so I would agree with you per your last paragraph.
Carrying out a PIA where a third party may be processing data is obviously good practice in any case.
I hope that helps with your further 'discussions' :)
Cheers,
Jackie.
Jackie Milne | Legal Information Specialist | JISC Legal | T 0141 548 4939 | E [log in to unmask]
Visit our website: www.jisclegal.ac.uk
Subscribe to our newsletter: www.jisclegal.ac.uk/newsletter
Follow us on Twitter: twitter.com/jisclegal
Tune in via Vimeo: vimeo.com/jisclegal
Linkedin: www.linkedin.com/company/jisc-legal
JISC Legal is hosted by the University of Strathclyde, a charitable body, registered in Scotland, with registration number SC015263
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
All archives of messages are stored permanently and are
available to the world wide web community at large at
http://www.jiscmail.ac.uk/lists/data-protection.html
If you wish to leave this list please send the command
leave data-protection to [log in to unmask]
All user commands can be found at http://www.jiscmail.ac.uk/help/commandref.htm
Any queries about sending or receiving messages please send to the list owner
[log in to unmask]
Full help Desk - please email [log in to unmask] describing your needs
To receive these emails in HTML format send the command:
SET data-protection HTML to [log in to unmask]
(all commands go to [log in to unmask] not the list please)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
|