Controller versus processor
The GDPR distinguishes between two roles in the processing of personal data. The controller determines the purpose and means of processing. The processor processes personal data on behalf of the controller.
If you use a payroll provider to run your payroll, you are the controller and the payroll provider is the processor. The GDPR requires you to have a data processing agreement in place.
When is a data processing agreement required?
Article 28(3) of the GDPR stipulates that processing by a processor shall be governed by a contract. This is mandatory in every situation where an external party processes personal data on your behalf, regardless of the scale or type of data.
Common situations requiring a DPA:
- A cloud provider storing your customer data (SaaS platforms, hosting)
- A payroll provider running your payroll administration
- A marketing agency using email addresses for campaigns
- An IT administrator with access to your systems
- A call centre handling customer enquiries on your behalf
What must a data processing agreement contain?
Article 28(3) GDPR prescribes a number of mandatory provisions. A DPA must contain at least the following:
1. Subject matter and duration of processing
Clearly describe which processing activities the processor carries out and for what period. This gives both parties clarity about the scope of the engagement.
2. Nature and purpose of processing
Why are the personal data being processed? Think of payroll administration, customer service, cloud storage or marketing campaigns.
3. Type of personal data and categories of data subjects
Specify which data are processed (name, email, national ID number, health data) and whose data they are (employees, customers, patients).
4. Obligations and rights of the controller
The controller retains the right to give instructions to the processor and must ensure that the legal basis for processing is in order.
5. Instruction-bound processing
The processor may only process personal data on the basis of documented instructions from the controller (Art. 28(3)(a)).
6. Confidentiality
Persons authorised to process the personal data at the processor must be bound by a confidentiality obligation (Art. 28(3)(b)).
7. Security measures
The processor implements appropriate technical and organisational measures pursuant to Art. 32 GDPR to ensure an appropriate level of security.
8. Sub-processors
The processor does not engage another processor (sub-processor) without prior consent of the controller. Where a general written authorisation is given, the processor must inform the controller of any changes.
9. Assistance with data subject rights
The processor assists the controller in responding to data subject requests (access, rectification, erasure, etc.) under Art. 15-22 GDPR.
10. Assistance with breach notification and DPIAs
The processor assists the controller in complying with obligations around data breaches (Art. 33-34) and data protection impact assessments (Art. 35-36).
11. Deletion or return after termination
After the end of the processing services, the processor deletes all personal data or returns them, unless storage is required by law.
12. Audit rights
The processor makes available all information necessary to demonstrate compliance and allows for audits and inspections (Art. 28(3)(h)).
Common mistakes
- Not having a DPA at all — this is mandatory even for small vendors
- Using a generic template without customisation — the agreement must be specific to the processing
- Forgetting to address sub-processors — a common source of non-compliance
- Not tracking when agreements expire — renewals and reassessments are essential
Practical tips
- Inventory all external parties that process personal data on your behalf
- Use a template that covers all Art. 28 requirements, but customise it per vendor
- Maintain a central register of all DPAs with expiry dates
- Schedule annual reviews to check agreements are still up to date
- Use a tool like DPAkit to generate, send and centrally manage data processing agreements
Summary
A data processing agreement is an essential element of GDPR compliance whenever you have an external party process personal data. Art. 28 GDPR prescribes exactly what it must contain. By managing your DPAs in a structured way, you avoid fines and demonstrate to auditors that you take compliance seriously.