This blog post is written for informational purposes only. It does not constitute legal advice, and should not be used as such.
Based on a quick search on Google, not a lot has been written on the topic of expert networks and GDPR. In an industry that has been plagued by insider trading scandals, and where robust compliance processes are a primary selling point, this is a bit surprising.
We at Inex One decided to do a bit of digging and look closer at the state of GDPR compliance for expert calls. We will introduce our findings in a series of blog posts throughout January, starting today by looking at expert networks and GDPR.
A. What responsibilities do expert networks have under the GDPR?
We will look at the responsibilities of the expert networks in a minute, but let’s first take a step back and decode some of the definitions under the GDPR (definitions are simplified for the purpose of this article):
Personal data: any information relating to an identified or identifiable natural person.
Data Subject: a natural person who can be identified, directly or indirectly.
Data Controller: the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Data Processor: a natural or legal person which processes personal data on behalf of the controller.
Sub-processor: a third party data processor engaged by a processor.
Recipient: a natural or legal person, to which the personal data are disclosed, whether a third party or not (depending on the circumstances, the recipient may also be a controller or processor).
As we’ve already established, not a lot has been written on the topic of GDPR and expert calls. But don’t despair. There’s another closely related industry that can be used as an analogy; headhunting and recruitment. After all, expert networks are acting as headhunting firms, chasing the best candidates for very short job assignments.
When it comes to recruitment, most sources seem to agree; the job candidate is a data subject, and the recruitment firm is a data controller in relation to the processing of the candidate’s personal data.
Is this also true for expert calls? Let’s look at a basic scenario: A client uses an expert network to engage with an expert. For simplicity, all parties are based in the EU. Remember that the definition of personal data is rather broad, and that it includes any information that can be used to identify a natural person, even if it needs to be combined with other data. Career history for example qualifies as personal data, even if a person’s name has been removed from the resumé.
If we map how the personal data related to experts would flow in this scenario, it would look like this:

In this scenario, the expert is the data subject. The expert network determines the purpose and the means of the processing of the personal data, and hence acts as data controller.
The role of the data controller is connected to a list of obligations and responsibilities. We will take a closer look at two of them: legal basis for processing and data storage limitation.
What does ‘legal basis for processing’ mean?
No matter if the expert network is processing personal data in the sourcing stage of a project or after an expert has been contracted, it needs to define a legal basis for each processing activity it’s undertaking. While the GDPR defines six different legal bases that organizations can gather personal data under, consent and legitimate interest are the ones most often discussed in relation to recruitment.
Consent vs. legitimate interest
Consent means that the data subject has agreed to the processing. Under the GDPR, a consent must be freely given, and specific to each processing activity. General consent that covers multiple processing activities or implied consent by pre-ticked boxes are no longer sufficient.
Legitimate interest means that the organization can prove that it has a legitimate interest to perform the processing (except where such interests are overridden by the interests or fundamental rights of the data subject). Legitimate interest is the most flexible of the legal bases, but it can’t mechanistically be used to motivate just any kind of processing. The expert network needs to be able to demonstrate that it’s using the expert’s personal data in a way that he or she would reasonably expect, and where there is a valid justification for the data being processed.
No matter if the expert network relies on consent, legitimate interest or one of the other legal bases, it should be clearly stated in its privacy statement or privacy policy.
What about when expert networks source experts online?
Anyone who has worked with recruiting experts for expert calls knows that it’s a task performed under constant time pressure. Deadlines are tight, and you want to get to the expert before any of your competitors do. Time pressure combined with the detailed information about individuals’ professional history that’s publicly available online opens up for shortcuts. Every now and then, an expert network will introduce an expert profile to a client before the expert has been contracted. Or the recruiter will come across an interesting profile and save it on a hard drive or in an internal system just in case it becomes relevant later on.
In these cases, the expert network will collect personal data from publicly available sources, but process it for its own purposes. As soon as the processing starts, the expert network gets the status (and responsibilities) of a data controller.
Where personal data have not been obtained directly from the data subject, the controller is responsible to get in touch with the data subject and inform him or her about the processing. The information should contain details about which purposes the data is processed for, the legal basis for the processing, the data retention period, and other relevant information. The expert network must contact the (prospective) expert in a reasonable period after obtaining the personal data, but at the latest within one month.
What does ‘storage limitation’ mean?
A principle under GDPR that clearly affects the expert networks is data retention and storage limitation. GDPR states that data should be stored “no longer than is necessary for the purposes for which the personal data are processed”. This means that a data controller cannot motivate that it’s storing data for another purpose than it was first collected for. The principle on storage limitation can be interpreted differently, but it’s clear that databases with hundreds of thousands of candidates can become a liability rather than an asset under the new stricter privacy legislation.
The GDPR also puts an emphasis on data minimisation. Not only should the retention time be kept short, a data controller should also refrain from collecting any data points that are not needed to fulfil the purpose of the processing.
So how well do the expert networks live up to the requirements of the GDPR?
We have looked closely at the privacy documentation of the leading expert networks, and it turns out they interpret the law quite differently. Most of the expert networks identify themselves as data controllers, whereas a few put that responsibility on the expert and reduce their own role to that of a data processor. By doing so they put the expert in a very peculiar position. Very few individuals realise that they by taking the role as data controller let the expert network off the hook when it comes to a lot of the responsibilities related to data processing.
It’s highly doubtful that arrangements in which the expert acts as data controller and the expert network acts as data processor (for the processing of the expert’s personal data) would hold up in a court of law. The legal relationship between two parties is defined by the processing activities that take place, and not by contract.

As a client of expert calls, it’s crucial to work with partners that comply with the GDPR. A data breach or a lawsuit where an expert network is found to misuse personal data can severely damage the brand of its clients. Our general advice is to ask your expert network how they handle the requirements of the GDPR, and which responsibility they take in the processing of expert personal data. Which processes do they have in place to keep expert database up to date, and which legal basis are they relying on when processing personal data?
B. Conducting expert calls under GDPR – the responsibilities of the client
Expert networks generally determine the purposes and means of processing of the expert’s personal data when recruiting individuals for expert calls, and hence act as a Data Controllers (if you need a recap on the definitions under GDPR, please read our first blog post). The expert, on the other hand, is the natural person whose data is being processed, and hence takes the role of a Data Subject.
But where does this leave the client?

From a first look at the definitions, it’s easy to think that the client is just a recipient. But is it true that it’s only the expert network that processes expert data, and that the client merely receives anonymized expert profiles?
Well, reality is a bit more complex than that. As soon as the client accesses the data and starts processing it for its own purposes, it actually becomes a data controller in its own right. Processing is a wide concept under GDPR, and everything from saving a CV on a hard drive to compiling expert profiles in excel sheets counts as processing. So what makes the client a controller and not a processor? Is it fair that the client has the same level of responsibility for its handling of the expert personal data as the expert network does?
Let’s revisit the definitions. A data processor is “a natural or legal person which processes personal data on behalf of the controller”. In order for the client to act as a data processor, it would need to process the data on behalf of and as instructed by the expert network. As soon as the client makes its own decisions regarding the processing, it becomes a data controller. (Theoretically, a client could of course receive a fully anonymized expert profile or conduct a call with the expert without receiving any personal data, and in those cases the processing would not be restricted by the GDPR).

GDPR introduces the concept of joint-controllers, when two controllers jointly determine the purpose of the processing. That is not the case in this situation though: instead the parties act as separate and independent controllers and each party is responsible for its own processing of the data.
So what does this mean in practice? Well, it actually means that the client is bound to the same set of responsibilities as the expert network. Just as the expert network, the client needs to define a legal basis for its processing, as well as set up processes around data retention and storage limitation.
So now we know that the expert is a data subject, and that both the expert network and the client act as data controllers. But where does this leave Inex One? What responsibility do we have for the processing of personal data, and how can we help our clients comply with GDPR?
C. Which role does Inex One take in the processing of expert personal data?

The supply chain is rarely this clean. What happens if one or several of the parties engage with a data processor? Which responsibilities do data processors have, and to which extent is the controller responsible for the processing performed by its processors?
Most expert networks use some sort of Recruitment Management System in which they handle expert profiles. Email is used as the primary tool for communication between the expert network and the expert, as well as between the expert network and the client. The client team often compiles expert profiles in an excel sheet to distribute to colleagues in the internal team. All of these services ‘process personal data on behalf of the controller’ and hence act as data processors.

Inex One replaces the need of using an email program to communicate with expert networks, and the need of using MS Excel or other softwares to compile and administer expert profiles. We act as a data processor in relation to both the expert network and the client, just as an email program or a Recruitment Management System.

A data processor has several responsibilities to the data controller that it’s acting on behalf of.
Amongst other things, it should:
– only act on behalf of, and as instructed by, the data controller.
– implement appropriate technical and organisational measures in such a manner that processing will meet the requirements of the GDPR and ensure the protection of the rights of the data subject.
– not engage another processor (sub-processor) without prior authorisation of the controller.
The processing performed by a data processor shall be governed by a contract that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. Such a contract is referred to as a Data Processing Agreement (DPA). The DPA is part of Inex One’s legal documentation for clients and partners.
How can Inex One support clients in their GDPR Compliance efforts?
As a data controller, the client has several responsibilities towards the data subject whose personal data it’s processing. One of them is to follow the principle about storage limitation. A data controller should not store personal data “longer than is necessary for the purposes for which the personal data are processed”. In practice this means that when a project has ended and the expert data is not needed anymore, it should be deleted or anonymised. And this is not only true for directly identifiable personal data like name and phone number, but also indirectly identifiable data like career history.
Most clients today find it hard to live up to this requirement. The way that the sourcing of experts is handled, personal data quickly spreads from email servers to excel sheets, and then on to notepads, word documents and other systems. Even if there are internal processes in place around how to handle personal data, they are not always followed by individual employees whose focus is on the project.
Inex One was built according to the principles of privacy by design, and has a built-in functionality for storage limitation. We automatically anonymise any personal data related to experts 12 months after a project has ended, or at the client’s request. When using Inex One, there is no need to compile and distribute information about experts in excel sheets to colleagues, or to use email to communicate, instead all data is processed within the closed ecosystem of the platform.
The GDPR has given individuals certain rights to empower them to take control of how their personal data is being processed. It provides individuals with eight different rights, out of which the “right to erasure” or “right to be forgotten” is probably the most well known. Individuals have the right to have their personal data erased if it’s no longer necessary for the purpose it was originally collected or processed for (e.g. when a project has finished), if the original consent is withdrawn, or if you as the data controller are relying on legitimate interest as your basis for processing and the individual objects to the processing.
If a request for erasure is made by an expert to a client that has processed that expert’s personal data, the client has one month to respond and act upon the request. This means that within one month, the client must identify and delete all personal data related to that individual expert in email systems, on hard drives, on local servers, cloud services etc. These kind of requests can easily become an administrative nightmare, as many companies still don’t have appropriate processes and methods in place to identify and delete personal data related to expert calls. With Inex One, this will no longer be a problem. Our strict data retention schedule ensures that you do not hold expert personal data longer than necessary, and if you would receive a request for erasure for data that has not already been anonymised, we have robust processes in place to have it deleted for you.
Do you want to know more about Inex One and how we can support your organization’s GDPR efforts? Read more in our eBook “Conducting Expert Calls under GPDR” or contact us here.