This is the second in our series of posts on the draft Guidelines 07/2020 on the concepts of controller and processor in the GDPR (the “draft Guidelines”) issued on 7 September 2020 by the European Data Protection Board (“EDPB”). This post focuses on the updates to the concept of controller. See our previous post regarding the concept of processors here. Upcoming posts will address joint controllers, “third parties” and “recipients.”
Please note that the EDPB has invited businesses to provide their feedback on the draft Guidelines by 19 October 2020.