Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Practice · 2 min read · Updated 16 August 2026

Data processing agreement

In shortThree clauses decide it: sub-processors, place of processing, deletion after termination.

At a glance

Legal basis
Article 28 GDPR; without this contract, engaging a provider to handle personal data is unlawful
Who carries responsibility
The controller, meaning your company — including for the choice of provider
The three decisive places
Sub-processor list, place of processing including remote access, deletion and return after termination
Reading time
About fifteen minutes if you confine yourself to those three places
Most common gap
Support and maintenance from third countries, governed only in an annex or not at all
Second most common gap
Deletion "after termination" with no deadline and no format

A data processing agreement governs what a service provider may do with personal data it processes for you. Without one the engagement is unlawful, which is why practically every provider has one ready.

That is exactly the problem. These contracts get signed rather than read — and the three places where they differ disappear into the boilerplate.

Clause 1 Sub-processors who else sits on the data besides your counterparty, and in which countries? Clause 2 Place of processing does the promise cover support, maintenance, backups and logs? Clause 3 Deletion and return in what format, within what deadline, and what happens afterwards?
The rest of the contract is usually boilerplate. These three answer: who can reach it, where, and how do I get out.

First: the sub-processors

The list usually sits in an annex or on a sub-page and is rarely sent along. It is the most revealing page in the whole contract, because it shows who besides your counterparty sits on the data: data-centre operators, support providers, analytics tools, delivery services.

Look at the change mechanism too. Are you informed of new sub-processors, with how much notice, and may you object? A right to object with no deadline and no termination right is not one.

Second: the place of processing

Not the registered office, not the data centre in the marketing material — the contractual promise. And then the question that is almost always missing: does it also cover support, maintenance, backups, logs and telemetry?

Remote access from a third country to data in the EU is a transfer in data protection terms. Where that point is left unsettled, the Data residency promise describes the resting state rather than operations.

Third: deletion and return

"On termination the data will be deleted or returned" is a phrase that leaves everything open. It becomes usable with three additions: a deadline, a format and a confirmation.

This clause is also where the contract meets the Exit strategy. Agreeing a deadline and a machine-readable format here settles the contractual part of your exit before you need it.

What the contract cannot do

It binds no authority in a third country. That is the core of Schrems II: where local law permits access, the best contract changes nothing. For transfers without an adequacy decision your own assessment therefore comes on top — the contract is its foundation, not its substitute.

Common questions

Do I have to read the whole contract?
No. Most of it is standardised and irrelevant to your decision. Three places are not: sub-processors, place of processing, and the deletion or return clause.
Why does the sub-processor list matter so much?
Because it reveals who besides your counterparty sits on the data. The European provider running on American infrastructure shows up exactly here — and nowhere else.
What is a usable right to object?
One with a deadline. "We will inform you of new sub-processors" with no notice period and no termination right on objection is worthless in practice. Advance notice plus an extraordinary termination right is what works.
Is "processing in the EU" enough?
Only if it also covers support, maintenance, backups and logs. Remote access from a third country to data in the EU is itself a transfer in data protection terms.

Sources

See also

Related terms