Freelancers and Data Protection

Last updated:
09.04.2021
Determining the data protection status of freelancers can often be tricky. We will show you how to clarify exactly what data protection requirements apply to "your" freelancers.
Freelancers and Data Protection
Key Takeaways
  • Freelancer relationships require clarification regarding data processing and accountability.
  • Distinction: Freelancer as an employee, data processor, or controller.
  • A data processing agreement is necessary if the freelancer processes personal data as part of their core tasks.
  • Freelancers must be trained in data protection and bound to confidentiality.
  • Data minimization facilitates the compliant engagement of freelancers.

Working with freelancers is a popular choice for businesses. From startups to established companies, freelancers provide flexible support to permanent teams with their expertise. However, this type of working relationship comes with various requirements regarding labor law and data protection. What does data protection law require when it comes to freelancers?

Data protection when hiring freelancers

From a data protection perspective, the scope of the freelancer's data processing is the most important factor: is the processing of personal data the core of the freelancer's activity? This will help you determine whether a Data Processing Agreement (DPA) is required for this working relationship. Other key points you need to clarify in this context include:

  • The freelancer's level of responsibility
  • The freelancer's level of subordination
  • The freelancer's location requirements.

Data protection status of freelancers under the GDPR

The points mentioned above will help you engage freelancers appropriately from a GDPR perspective. There are three main distinctions to be made (excluding special cases):

Freelancer as a quasi-employee

  • It is important to determine when, where, and with what hardware the freelancer is working. If they are working on company-owned hardware at set times from a dedicated workspace within your company, they are considered a quasi-employee. In this case, a DPA is generally not required, as the freelancer is treated as an employee for data protection purposes and is considered a person under your authority as the controller (cf. Art. 29 GDPR).
  • Important: Even in this scenario, the freelancer must be properly briefed if they are working with personal data. The specific requirements for this are usually set out in the main contract. Furthermore, freelancers must be appropriately instructed and trained in data protection. They must also be bound to data protection confidentiality, and a non-disclosure agreement should be signed.

Freelancer as a data processor

  • If freelancers can independently determine their working hours and location, they are generally considered external service providers or self-employed individuals. They use their own hardware and are not bound by the company's working hours or physical workspace. In this case, the person responsible can only exercise limited control over the conditions under which the freelancer processes personal data. To ensure compliance, a Data Processing Agreement (DPA) under Art. 28 GDPR may need to be concluded to ensure that the freelancer processes personal data according to your instructions. If the core of the activity involves the processing of personal data, the freelancer is generally considered a data processor under Art. 4 (7) GDPR, with you acting as the controller.
  • Whether the core of the activity involves the processing of personal data and thus necessitates a DPA should be assessed on a case-by-case basis with your Data Protection Officer.
  • Practical tip: The transfer of personal data to freelancers is covered by the DPA if the requirements of Art. 28 GDPR are met.

Freelancers as Controllers

  • The final scenario is as follows: The freelancer has a free hand and is permitted to determine the means and purposes of processing the personal data provided by your company. Consequently, the work is not performed under strict instructions from the company. In theory, the freelancer must independently fulfill GDPR obligations (such as managing data subject requests or complying with information requirements) unless further agreements are made.
  • To protect all parties involved, written agreements regarding purpose limitation and confidentiality should be established.
  • Incidentally, even in this scenario, a legal basis under data protection law is required for the transfer of your company's personal data to the freelancer. In certain cases, the legitimate interest under Art. 6 (1) (f) GDPR may suffice as a legal basis. However, whether a legitimate interest exists must be assessed on a case-by-case basis! Therefore, no general statement can be made as to whether this legal basis is sufficient for data processing. The interests of the data subject(s) might override your own. In this configuration, there may also be joint controllership under Art. 26 GDPR between the parties. The details regarding data processing and transfer should be precisely regulated by contract to avoid any violations of data protection requirements.

Engaging Freelancers in Compliance with Data Protection

To engage freelancers in accordance with GDPR guidelines, you must first clarify their tasks and the framework conditions. The most important indicator for classification is the degree of instruction. Therefore, it is definitely advisable to act according to one of the most important principles of the GDPR: data minimization. In short, from a data protection perspective, the less personal data a freelancer processes, the easier it is to engage them.

Do you know which other data protection points must be observed in marketing? In our guide to data protection in marketing, we provide comprehensive information on the need for action and improvement in the marketing sector.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in