The easy way is a Data Processing Agreement, which has to precisely list what data is processed which way.
This is of course a legal document and the implementation may do something else.
This is of course a legal document and the implementation may do something else.
So the question to answer is how can we ensure an interoperable contract for data between systems/services - that requires an ontology for privacy that makes enforcement easy(er).
It is possible to make privacy definitions a declarative and low effort part of development for engineers - then code becomes the enforcing layer instead of legal agreements.