GDPR Data Processing Agreement: When You Need One and What It Must Include

Last updated:
08.04.2026
If external service providers process personal data on behalf of your company, the GDPR requires you to enter into a contract with them that sets out the terms and conditions for this processing. Learn what a data processing agreement (DPA) entails and why it is essential for your business.
GDPR Data Processing Agreement: When You Need One and What It Must Include
Key Takeaways
  • A DPA is required when a service provider processes personal data on behalf of and according to the instructions of a controller.
  • The client remains the controller and bears primary responsibility for data processing.
  • A DPA is typically not required if the recipient acts as an independent controller or determines the purposes and means of processing as part of their professional services.
  • In accordance with Article 28(3) of the GDPR, the DPA must specify, among other things, the purpose and nature of the processing, technical and organizational measures (TOMs), sub-processors, and deletion procedures.
  • In the event of violations, both the controller and the processor may be held liable, each within the scope of their respective duties and areas of responsibility.

What is a data processing agreement?

Companies must enter into a data processing agreement with service providersif external providers are to process data on behalf of and according to the instructions of the company.

Before the introduction of the General Data Protection Regulation (GDPR), this contract was known as a data processing agreement (DPA). An important difference from the previous legal situation is that the data processor is now required to maintain a record of processing activities .

Which processing activities does the DPA cover?

Under the GDPR, data processing occurs when service providers (data processors) process personal data on behalf of and according to the instructions of a controller (client) (Art. 4 No. 8 GDPR and Art. 28 Para. 1 GDPR). According to Art. 4 No. 2 GDPR, processing includes, among other things, the collection, recording, alteration, or storage of personal data.  

Typical applications include, for example, payroll processing via an external service provider as well as the engagement of web hosts, newsletter service providers, or marketing agencies.

The data processing agreement governs the collaboration with service providers, such as newsletter providers.

What is the significance of the DPA for companies?

With a DPA, both the client and the contractor gain clarity regarding powers and instructions as well as the subject matter and purpose of the processingThe rights and obligations of the respective data processing are clearly defined in a data processing agreement.

In addition, data processing agreements provide companies with a certain level of security: in the event of a data protection breach committed by the data processor, they can prove that the responsibility lay within the processor's scope of duties.  

Caution: Even in the case of data processing, the controller remains the responsible party within the meaning of the GDPR. The external service provider acts only in a supporting capacity and is therefore the "extended arm" of their client.

When is there no data processing?

Data processing must be distinguished from joint controllership under Art. 26 GDPR and the mere transmission of personal data to a controller.

  • Pure data transmission: If a controller transmits personal data to another party, no data processing agreement is required for this. However, a legal basis is required for the transmission as well as for the processing of the data by the other controller.
  • Joint controllership: If two or more controllers jointly determine the purposes and means of processing personal data, they are joint controllers and must define who fulfills which GDPR obligation in a "joint controllership agreement" pursuant to Art. 26 GDPR.  

Identifying data processing

To help with distinguishing data processing, the following question is helpful: Can the intended purpose of the data processing be pursued even without the third party?  

If you can answer the question with a yes and the third party is therefore easily replaceable, this is an indication of data processing on behalf of a controller. If you answer the question with a no, this suggests that it is not purely data processing on behalf of a controller and that joint controllership may exist.

In practice: Who needs a data processing agreement?

Whether a data processing agreement is required depends on the role in which the service provider processes personal data.

In short: A DPA is necessary if an external service provider processes personal data on behalf of your company and under your instructions . In this case, you remain the controller within the meaning of the GDPR, and the service provider acts as a processor – essentially as an "extended arm" of your company.

When answering the question of whether data processing on behalf of a controller is taking place and a DPA must therefore be concluded, the primary factor is the extent of instruction : The more a service provider is bound by your instructions, the greater the likelihood that you remain the controller under the GDPR and must enter into a data processing agreement.

When must a DPA be concluded?

A DPA must be concluded if all of the following points apply:

  • You commission an external service provider and personal data is processed in the process.
  • The service provider processes this data on behalf of your company (Art. 4 No. 8 GDPR).
  • The service provider is bound by your instructions: The more you define the purpose, process, and scope of the processing, the more likely it is that data processing on behalf of a controller is taking place.

In these cases, as the controller, you must use the data processing agreement to ensure that the service provider maintains an adequate level of data protection. You do not need an additional legal basis solely for the activities of the data processor. The decisive factor remains the legal basis upon which you base your processing.

Important: Companies should regularly monitor their data processors and verify that the level of data protection is still being maintained.

Example: For tools like Google Analytics, a data processing agreement (DPA) is generally required because personal data is processed and transmitted. However, a DPA does not replace the need to verify the legal basis.

When is a DPA generally not required?

Data processing typically does not occur when you provide personal data to service providers who perform an independent professional service and in doing so act without being subject to instructions . In these scenarios, the service providers are generally responsible for their own processing.

These include, for example:

  • Tax advisors
  • Lawyers
  • Auditors
  • Banking institutions
  • Postal services
  • Collection agencies with debt assignment

What are the key components of a DPA?

To conclude data processing agreements in compliance with the GDPR, various aspects must be contractually regulated in accordance with Article 28(3) of the GDPR. These include:

  • Subject matter, duration, nature, and purpose of the processing
  • Type of personal data
  • Categories of data subjects
  • Rights and obligations of the controller
  • Scope of documented instructions
  • Confidentiality obligations of persons authorized to process the data
  • Ensuring technical and organizational measures by the processor
  • Requirements for engaging sub-processors
  • Assisting the controller with requests and claims from data subjects, ensuring processing security, notification obligations in the event of data breaches, and data protection impact assessments
  • Return or deletion of personal data after the processing services are completed
  • Obligation of the processor to inform the controller immediately if an instruction infringes data protection law
  • Provisions on how compliance with the stated obligations is to be demonstrated

Tip: Looking to set up your GDPR-compliant data processing agreement? Use our free DPA template.

Responsibility and liability in data processing agreements

In the event of data protection breaches, both the controller and the processor can be held liable. The processor is specifically liable for breaches that fall within their area of responsibility, such as failing to follow instructions or violating their own obligations as a processor.  

Both parties can exonerate themselvesif they can prove that they are not responsible for the damage. For data subjects, the controller generally remains the primary point of contact.

Conclusion: Set up DPAs securely and collaborate with peace of mind

When outsourcing the processing of personal data, you set the pace, and the DPA ensures harmony in your collaboration with your external service provider. To ensure that data processing activities are documented in contractual compliance with current data protection law, these agreements must be drafted properly. The data protection experts at Proliance and the Proliance 360 software are here to support you with expertise and automation.

Frequently Asked Questions

Still have questions? We have the answers.

When is a Data Processing Agreement (DPA) under GDPR required – and what are the consequences without one?

Whenever your company transfers personal data to third parties – such as cloud providers, marketing agencies, or newsletter service providers – a Data Processing Agreement (DPA) is mandatory. Failure to have one can result in significant penalties. Schedule a consultation with Proliance now to legally and centrally manage your DPAs with all service providers.

What must a data processing agreement (DPA) include under Article 28(3) GDPR?

The Data Processing Agreement (DPA) regulates, among other things, the subject matter, duration, nature, and purpose of processing; the types of personal data and categories of data subjects; rights and obligations; instructions; confidentiality; technical and organizational measures (TOMs); sub-processors; assistance with data subject requests and reporting obligations; and the return or deletion of data upon completion. Proliance offers expertise and automation with Proliance 360.

Who is liable for data protection breaches in data processing?

In the event of data protection breaches, both the controller and the processor can be held liable, each within the scope of their duties and areas of responsibility. The processor is particularly liable for breaches within their own area, for instance, in cases of dereliction of duty or failure to follow instructions. Proliance assists with GDPR-compliant data processing agreements and the monitoring of processors.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Sabrina Schaub
Freelance Editor
Leveraging her content expertise, Sabrina supports the Proliance team in communicating complex topics clearly. As a freelance writer, she understands the data privacy requirements across different sectors and translates even complex information into content tailored to specific target audiences.
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in