Data processing agreement
In shortThree clauses decide it: sub-processors, place of processing, deletion after termination.
At a glance
- Legal basis
- Article 28 GDPR; without this contract, engaging a provider to handle personal data is unlawful
- Who carries responsibility
- The controller, meaning your company — including for the choice of provider
- The three decisive places
- Sub-processor list, place of processing including remote access, deletion and return after termination
- Reading time
- About fifteen minutes if you confine yourself to those three places
- Most common gap
- Support and maintenance from third countries, governed only in an annex or not at all
- Second most common gap
- Deletion "after termination" with no deadline and no format
A data processing agreement governs what a service provider may do with personal data it processes for you. Without one the engagement is unlawful, which is why practically every provider has one ready.
That is exactly the problem. These contracts get signed rather than read — and the three places where they differ disappear into the boilerplate.
First: the sub-processors
The list usually sits in an annex or on a sub-page and is rarely sent along. It is the most revealing page in the whole contract, because it shows who besides your counterparty sits on the data: data-centre operators, support providers, analytics tools, delivery services.
Look at the change mechanism too. Are you informed of new sub-processors, with how much notice, and may you object? A right to object with no deadline and no termination right is not one.
Second: the place of processing
Not the registered office, not the data centre in the marketing material — the contractual promise. And then the question that is almost always missing: does it also cover support, maintenance, backups, logs and telemetry?
Remote access from a third country to data in the EU is a transfer in data protection terms. Where that point is left unsettled, the Data residency promise describes the resting state rather than operations.
Third: deletion and return
"On termination the data will be deleted or returned" is a phrase that leaves everything open. It becomes usable with three additions: a deadline, a format and a confirmation.
This clause is also where the contract meets the Exit strategy. Agreeing a deadline and a machine-readable format here settles the contractual part of your exit before you need it.
What the contract cannot do
It binds no authority in a third country. That is the core of Schrems II: where local law permits access, the best contract changes nothing. For transfers without an adequacy decision your own assessment therefore comes on top — the contract is its foundation, not its substitute.
Common questions
- Do I have to read the whole contract?
- No. Most of it is standardised and irrelevant to your decision. Three places are not: sub-processors, place of processing, and the deletion or return clause.
- Why does the sub-processor list matter so much?
- Because it reveals who besides your counterparty sits on the data. The European provider running on American infrastructure shows up exactly here — and nowhere else.
- What is a usable right to object?
- One with a deadline. "We will inform you of new sub-processors" with no notice period and no termination right on objection is worthless in practice. Advance notice plus an extraordinary termination right is what works.
- Is "processing in the EU" enough?
- Only if it also covers support, maintenance, backups and logs. Remote access from a third country to data in the EU is itself a transfer in data protection terms.
Sources
See also
Related terms
- Schrems IISince 2020 you must assess yourself whether data is safe in the recipient country — the provider cannot do it for you.
- Data residencyData residency says where the data sits. Not who is allowed to reach it.
- Shadow ITShadow IT is rarely disobedience. It shows where the official tool fails to do a job.