AGIDAT – Datenschutz | Informationssicherheit

Data Processing Agreements

DPA review and vendor assessment — legally sound contractual arrangements.

What is a data processing agreement?

Whenever you engage an external provider that processes personal data on your behalf, you have a "processing" relationship. Typical examples include cloud services, email providers, payroll software, CRM systems, and IT service providers.

In these cases, Art. 28 GDPR requires you to conclude a Data Processing Agreement (DPA). If none is in place, you as the controller are liable — even if the fault lies with the processor.

What must a DPA contain?

A compliant DPA under Art. 28(3) GDPR must, at a minimum, regulate:

  • Subject matter, duration and nature of the processing
  • Purpose of the processing and type of data
  • Categories of data subjects
  • Rights and obligations of the controller
  • The processor's duty to act only on documented instructions
  • Provisions on sub-processors
  • Assistance obligations (data subject rights, breach notifications)
  • Deletion or return of the data once the contract ends

Third-country transfers: special caution with US services

Many widely used services (Google, Microsoft, Salesforce, HubSpot, and others) transfer data to the US or other third countries. Since the Schrems II ruling, you must ensure that an adequate level of data protection exists.

We check:

  • Whether a valid transfer mechanism is in place (EU-US Data Privacy Framework, Standard Contractual Clauses)
  • Whether additional technical measures are required
  • Whether use of the service may be too risky

Our approach

  1. Inventory of all your vendors and service providers
  2. Classification by DPA requirement (yes/no/unclear)
  3. Review of existing DPAs for completeness
  4. Drafting or improvement of missing or deficient DPAs
  5. Documentation in the Records of Processing Activities