Employee excess and GDPR: No liability of the client
Employee excess and GDPR: No liability of the client
In the event of an employee excess at the processor, according to Article 82 of the GDPR, the customer is not liable, but the person who carries out the data processing himself. This legal principle protects the client from disproportionate liability claims, provided that he has properly monitored and controlled the processing of personal data by a third party.
The employee excess can occur, for example, in the context of data processing if an employee passes on the data of the customer unauthorized or breaks into the data. In such cases, the processor shall bear the responsibility provided that it carries out the data processing itself. The customer is only liable if he has not properly monitored the processing or has not appropriately chosen the security measures.
The GDPR stipulates that the client regulates the processing of personal data by a third party by a contracting community. It is important that the client checks the processing by the processor and checks the security measures. If the processing is carried out correctly, the client is not liable.
## What does this mean for your company? If an employee passes on the data of the customer without authorization or breaks into the data, the customer is not liable, but the person who carries out the data processing. It is therefore important to properly monitor the processing of the data by a third party and to check the security measures. This allows you to protect yourself against disproportionate liability claims.
## How ISN/xyn,ap supports this xynap’s infrastructure and AI tools help you make data processing secure and transparent. With these modules, you can monitor the processing of data by third parties and check the security measures to protect yourself against disproportionate liability claims.