A processing activity has been transferred from my Service to another Controlling Service. What should be done with the corresponding Privacy Notice?

When an activity involving the processing of personal data is transferred to another Controlling Service, the new Controlling Service must publish a Privacy Notice covering the relevant processing activities.

To facilitate the creation of the new Privacy Notice, the receiving Service may clone the existing Privacy Notice into its Service Element. If the Service does not yet have a Service Element, one must be created first. The cloned Privacy Notice should then be adapted to the Service's specific needs and published with the assistance of the ODP.

The former and the new Controlling Service should coordinate their respective activities to ensure a smooth and timely transition of personal data, processing activities, and associated responsibilities.

Once the transfer of the personal data and the associated responsibilities has been completed, and the new Privacy Notice has been published, the former Controlling Service should retire the corresponding Privacy Notice, after ensuring that it has ceased the processing activities documented in that notice.

Practical guidance on this procedure is available in the Admin e-guide: Records of Processing Operations and Privacy Notices