Processing agreements: when you need one — and what it does not do

Processing agreements: when you need one — and what it does not do

8 min read

As soon as a service provider processes personal data for you, there has to be a contract about it. That is the case more often than most businesses assume — and the contract does less than its reputation promises.

Customer data in one place, not four lists

With everything in one system an access request takes minutes, and what should go, goes. Hosted in Germany.

See the products

Article 28 GDPR governs a simple arrangement: you decide what data is processed for and by what means, somebody else carries that out for you. You are then the controller (Article 4(7)), the other party is the processor (Article 4(8)). For that relationship the Regulation requires a contract with a prescribed content — in English usually called a data processing agreement, or DPA.

The contract is not a form you file and forget, but it is not a project either. Reputable providers keep it ready and it is concluded in ten minutes. The effort lies elsewhere: knowing who you need one with at all. This article answers that in order, and stays orientation — where a particular provider sits can in case of doubt only be settled by your supervisory authority or a lawyer.

1. Who is processing for whom here?

The distinction is the whole question. A controller is whoever decides on the purposes and means of the processing. A processor is whoever processes personal data on the controller's behalf — that is, on instructions and with no purposes of their own.

The test sentence is short: who determines what the data is for? If you determine it and the other party carries it out, it is processing on your behalf. If the other party pursues purposes of their own, laid down by law or by professional rules, they are a controller themselves — and then there are two controllers in sequence and no DPA.

Article 28(10) draws a clear line behind that: a processor who, contrary to the Regulation, determines the purposes and means themselves is considered a controller in respect of that processing. Anyone using your customer data for analysis of their own is therefore no longer a processor, whatever the contract says. Which is also why a DPA is not the paper that fixes the role — it only describes it.

Not every disclosure is processing on your behalf. Pass data to somebody who needs it on their own responsibility and that is a transfer with a legal basis of its own — for which you need a ground under Article 6(1), not a contract under Article 28.

A processing agreement does not make a processing operation lawful. It only settles who may do what.

2. Where processing hides in a small business

The list is longer than it feels, because most entries are not called “data processing”.

Service providerClassification
Cloud appointment, till or trade softwareprocessor
Newsletter and text message sendingprocessor
Web hosting and email accountsprocessor
External IT support with access to systemsprocessor
External payroll or bookkeeping as a pure serviceprocessor
Confidential document destruction by a specialist firmprocessor
Accountancy practice acting under its professional rulescontested, usually a controller of its own
Bank, insurer, public authoritycontroller of its own

The second-to-last row is the one genuinely argued over. Where a practice discharges professional duties of its own and does not work on instructions, it is predominantly classified as a controller in its own right; where the same provider also carries out pure execution work alongside that, the classification can come out differently. Supervisory authorities take different views on this from one member state to the next — ask the provider how they see themselves, and get the answer in writing.

With software, by contrast, there is no argument. Anyone storing your customer data for you is a processor and has to keep a contract ready. If it is missing, or only obtainable on request and after several weeks, that is a finding about the provider. The salon software, for instance, makes it available as any provider of that kind should — the question belongs with the five questions you settle before the first demo, not in the week after signing.

3. What has to be in it

Before the contract comes a duty that is easily read past. Article 28(1) requires you to use only processors providing sufficient guarantees — that is, to make a selection decision before you sign. A contract with an unsuitable provider does not cure their unsuitability.

Article 28(3) names the headline details first: the subject matter and duration, the nature and purpose of the processing, the type of data, the categories of data subject, and the rights and obligations of the controller. After that come eight points the contract has to provide for:

  1. processing only on documented instructions, including for transfers to a third country;
  2. a confidentiality commitment from the people involved;
  3. implementation of the security measures under Article 32;
  4. compliance with the conditions for engaging further processors;
  5. assistance with data subject requests, that is with access, rectification and erasure;
  6. assistance with security, breach notification and impact assessment (Articles 32 to 36);
  7. deletion or return of all data after the end of the service, including existing copies;
  8. making available evidence and allowing audits.

Points five and seven are the ones you genuinely need day to day — the first when somebody asks for access, the second when you change provider. Read them before signing and not on the day you need them.

On form: under Article 28(9) the contract is to be in writing, and electronic form is expressly enough. It may rest wholly or partly on standard contractual clauses laid down by the Commission or a supervisory authority (paragraphs 6 to 8) — which is why different providers' contracts resemble each other so closely.

4. What the contract does not do

Here lies the commonest misunderstanding. A DPA does not make the processing lawful. It governs the relationship between you and the service provider, and nothing else.

Lawfulness still comes solely from Article 6(1) — and it sits with you. Collect addresses without a basis and then send to them through a provider with an impeccable DPA, and you have a clean contract covering an unlawful processing operation. The contract does not move the responsibility: towards the data subjects you remain the controller.

Three further things it does not do:

  • It does not replace informing the data subjects. That you use a service provider belongs in your privacy information, as a recipient or category of recipient.
  • It does not replace your selection decision — see Article 28(1).
  • It does not replace your own record. Article 30 requires one from you as controller; the processor keeps its own under paragraph 2, and that one does not replace yours.

What it very much does do: it gives you an enforceable claim to cooperation. If somebody asks for access tomorrow and the data sits with the provider, the duty to assist under paragraph 3(e) is your lever — rather than a hope of goodwill.

5. Sub-processors and the question of where

Almost every provider engages service providers of their own: a data centre, backups, a delivery route, a support tool. Article 28(2) requires your prior authorisation for that — either specific or general. With a general authorisation the provider has to inform you of any intended change so that you can object.

In practice that means: there is a list, and the list changes. Check once where it sits and how changes are announced. Under Article 28(4) the same data protection obligations have to be imposed on further processors, and the first processor remains liable to you for their compliance — so the chain does not break.

The second question is where. As soon as data is processed outside the EU and the EEA, Articles 44 ff. GDPR apply on top. A transfer then needs a basis of its own: an adequacy decision by the Commission for the country concerned, or appropriate safeguards under Article 46, in practice usually standard contractual clauses.

For you that is not a legal examination but a question to the provider, and it runs: where does the data sit, and who can reach it from where? Support access from a third country is a transfer too. The answer belongs in your records — it is also one of the details Article 30(1) requires for the record.

Go through a year of invoices once and mark every service provider that comes into contact with customer data. For each of them one of two answers applies: a controller in their own right — in which case you need a basis for the transfer — or a processor, in which case you need the contract. That list is finished in an hour and almost always turns up two or three entries nobody had thought of. What happens to the data when the contract ends belongs in the deletion policy; which data may leave your business at all is settled by Which customer data you may store.

Customer data in one place, not four lists

With everything in one system an access request takes minutes, and what should go, goes. Hosted in Germany.