If another company processes personal data on your behalf — your cloud provider, payroll bureau, CRM, email platform, or the AI tool your team just started using — GDPR requires a written contract between you. That contract is the Data Processing Agreement (DPA), and it is not optional. Article 28 of the GDPR makes it mandatory, and operating without one is a compliance gap that surfaces fast in audits, customer due diligence, and after a data breach.
Here is what a DPA is, when you need one, and the clauses you cannot leave out.
Controller, processor — who is who?
GDPR splits responsibility into two roles. The controller decides why and how personal data is processed (that is usually you). The processor handles the data on the controller’s behalf and only on its instructions (your supplier or tool). A DPA is the contract that governs that relationship. If you are the controller, it is your legal duty to make sure one is in place with every processor.
Is a DPA mandatory? Yes.
Article 28(3) requires that processing by a processor is governed by a contract that is binding and in writing (electronic form counts). No DPA means both parties are exposed — and the controller cannot demonstrate compliance, which is itself a breach of the accountability principle.
The 5 clauses you cannot leave out
- Documented instructions. The processor may only process personal data on your documented instructions — including on international transfers. This is the heart of the agreement: it stops your supplier from using your customers’ data for its own purposes.
- Confidentiality. Everyone the processor authorises to handle the data must be bound by a duty of confidentiality.
- Security measures. The processor must implement appropriate technical and organisational measures under Article 32 — encryption, access controls, backups, and so on — to protect the data.
- Sub-processors. The processor may not engage another sub-processor without your prior authorisation, and must impose the same data-protection obligations on that sub-processor. (Think of the sub-contractors behind your supplier.)
- Assistance, audits, and deletion. The processor must help you respond to data-subject requests, assist with security, breach notification and DPIAs, delete or return all personal data at the end of the contract, and make available the information you need — including allowing audits — to demonstrate compliance.
Don’t forget the scope details
Beyond the five obligations, Article 28(3) requires the DPA to set out the subject matter and duration of the processing, its nature and purpose, the type of personal data, and the categories of data subjects. These details define exactly what the processor is allowed to do — leave them vague and the whole agreement weakens.
Common mistakes
- Relying on the supplier’s standard terms without checking they actually meet Article 28.
- Forgetting DPAs for “small” tools — a single AI writing assistant or analytics script can process personal data.
- No control over sub-processors, so data quietly flows to parties you never approved.
- No mechanism to delete or return data when you stop using the service.
What to do now
Make a list of every supplier and tool that touches personal data, and check each one has a compliant DPA in place. Where it is missing, put one in place before the next audit — or the next incident — forces the issue.
Need a starting point? Use our ready-made GDPR Data Processing Agreement template, or get in touch and book your free first hour — we will review your supplier contracts with you, in plain language.
This article is general information, not legal advice. For an assessment of your specific situation, talk to a qualified lawyer.
Related reading
EU AI Act · GDPR · Business lawyer in Stockholm