The situation
A Dutch datacenter with two locations serves over 200 clients with colocation, managed hosting and cloud services. Clients range from small webshops to financial institutions and government organisations.
The datacenter itself uses external services:
- Network: upstream providers, DDoS mitigation service, peering partners
- Monitoring: network monitoring, environmental monitoring, CCTV systems
- Security: physical access control service, fire detection, emergency power maintenance
- Management: ticketing system, client portal, invoicing software
- Certification: ISO 27001 auditors, security advisors
The challenges
DPAs with hundreds of clients
Every client processing personal data on the datacenter's infrastructure is entitled to a DPA. With 200+ clients, this means hundreds of agreements that must stay current.
Complex chain responsibility
The datacenter is a processor, but its clients may themselves be processors on behalf of their own clients. These chains make it difficult to delineate responsibilities clearly.
Demonstrating physical and logical security
Clients want proof of security measures: ISO 27001 certificate, SOC 2 report, pentest report, physical security measures. This must be centrally available.
Communicating sub-processor changes
When switching a DDoS mitigation service or upstream provider, all clients must be informed. With 200+ clients, a manual process is costly and error-prone.
The approach
Step 1: Standard DPA
The datacenter creates a standard DPA compliant with Art. 28, with technical and organisational measures as an annex referencing current certifications.
Step 2: Digital signing
New clients receive and sign the DPA digitally via the platform. Existing clients are migrated in phases.
Step 3: Certificate vault
All certificates and reports are stored centrally with expiry dates and automatic renewal reminders. Clients can access them via the platform.
Step 4: Sub-processor register and notifications
The sub-processor register is maintained in the platform. Changes trigger automatic notifications to all clients with an objection period.
Step 5: Processing register
The processor register (Art. 30(2)) is automatically generated from client agreements and service categories.
The result
- 200+ DPAs managed digitally with current security annexes
- 70% faster client onboarding through digital signing
- Certificates always available for client audits without manual delivery
- Sub-processor changes automatically communicated to all clients
- Processing register always current and directly available for auditors
- Reduced burden on the legal department
Lessons learned
- Datacenters are often overlooked as processors, but the GDPR is clear: if you provide infrastructure on which personal data is processed, you are a processor
- A standard DPA with modular annexes works better than bespoke agreements per client
- Clients increasingly expect a self-service portal for certificates and compliance information
- Physical security measures belong in the DPA as technical measures
- Invest in automated sub-processor notification: it saves hours of work per change