Contracts

Drafting a Data Processing Agreement? Don't do it yourself! Here's why

Mr. Jaime Boogaers Privacy/ICT Law Attorney, 16 years of experience. The General Data Protection Regulation (GDPR) initially seems like a hassle to many businesses, but it is actually very important. Naturally, you do not want your own personal data...

Published on March 16, 2019 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote
Mr. Jaime Boogaers
Privacy/ICT Law Attorney, 16 years of experience
The General Data Protection Regulation (GDPR) may initially seem like a hassle to many businesses, but it is actually very important. Naturally, you do not want your own personal data to end up on the street. For this reason, as a company, you need to ensure everything is properly arranged. Fines can be substantial. As a lawyer, I have fully specialized in this area to make your business GDPR-compliant.
Mr. Jaime Boogaers

Technically, you can draft a data processing agreement yourself, but it is rarely advisable. Article 28(3) of the GDPR sets concrete requirements for such an agreement, and it is precisely the details—who is liable for what, what the processor is and is not allowed to do, and what happens in the event of a data breach—that determine whether the document protects you in a dispute or actually works against you. A free template from the internet or a version forced upon you by your supplier usually does not cover your interests as a data controller. On this page, you can read why customization pays off, where things go wrong, and what you can do concretely.

In short:

  • A data processing agreement is mandatory as soon as an external party processes personal data on your behalf (Art. 28 GDPR).
  • The content is custom-made: a free online template or a version forced upon you by your supplier usually does not protect your interests as a data controller.
  • The agreements regarding liability, data breaches, sub-processors, and transfers outside the EU.
  • If the agreement is missing or does not comply with the law, you risk a fine and damage claims.

What is a data processing agreement?

A data processing agreement is a written agreement between a data controller (you, who determines why and how personal data is processed) and a data processor (an external party that processes the data on your behalf). Examples include your accounting software, your email marketing tool, your hosting provider, or an external payroll administration firm. As soon as such a party processes personal data for you, you are required under the GDPR to record agreements regarding this.

With that agreement, you establish how the processor handles the personal data. You specify what is and is not permitted. In this way, you ensure that the personal data receives appropriate protection and that you can demonstrate that you take your obligations seriously.

When do you need a data processing agreement?

The rule of thumb is simple: if you allow an external party to process personal data, you need a data processing agreement. In practice, this often involves situations like these:

  • you use a cloud or hosting provider where customer or employee data is stored;
  • You work with accounting or payroll software , or outsource your administration;
  • you send newsletters via an email marketing tool;
  • You let an external agency run your customer service, CRM, or IT management

If you process data together with another party where you both determine the purpose and means, there is usually joint processing responsibility and different agreements apply. Are you unsure which role you fall into? Have this properly established first, as it determines which obligations rest upon you.

What must be included in a data processing agreement according to Article 28 of the GDPR?

Nowhere in the law does it state that you must have the agreement drafted by a legal expert or lawyer. However, Article 28, paragraph 3 of the GDPR sets out a number of mandatory topics that must be addressed in the agreement. Broadly speaking, these include:

  • the subject, duration, nature and purpose of the processing;
  • the type of personal data and the categories of data subjects;
  • the agreement that the processor acts exclusively on the basis of your written instructions;
  • a duty of confidentiality for everyone who works with the data;
  • appropriate security measures;
  • agreements regarding the engagement of sub-processors (subcontractors);
  • assistance with requests from data subjects and data breaches;
  • what happens to the data afterwards (return or deletion);
  • the possibility for you to check compliance (audit).

The specific implementation differs for every collaboration. A data processing agreement is therefore custom-made. Logically, simply picking a template from the internet is not sufficient: that document does not take into account your processing activities, your risks, or your suppliers.

Have a model Data Processing Agreement drafted by an in-house counsel?

€ 189,- per document

Let's make an appointment. We will discuss all your wishes before you order. The consultation is free and without obligation, and lasts 20 to 30 minutes.

  • We provide reliable & accurate custom legal services
  • During a telephone intake, we discuss all your wishes
  • Delivered within 7 days, express delivery possible
  • Fixed price per document and pay later

We also offer special GDPR packages.

Why it is better not to draft a data processing agreement yourself

Tinkering with a data processing agreement yourself is cheaper and faster – until something goes wrong. Three common mistakes will cost you dearly:

1. You do not cover all legal topics

If the agreement lacks a mandatory element from Article 28 of the GDPR, it does not comply with the law. An incomplete contract creates a false sense of security: you *think* you have everything arranged, but an audit or a dispute proves otherwise.

2. You phrase the liability to your disadvantage

The distribution of responsibility and liability lies in the wording. An incorrect sentence can result in you bearing the brunt of a processor's error. An experienced lawyer pays close attention to precisely those details.

3. You are using a model that does not suit your situation

A standard model does not take into account your processing operations, suppliers, and risks. Consequently, provisions regarding sub-processors, transfers to countries outside the EU, or retention periods often do not align with practice.

Practical examples: where things go wrong in practice

The theory sounds straightforward, but it is precisely in everyday situations that the problems arise. A few recognizable examples:

  • The hosting provider outside the EU. Your webshop runs with a provider that stores data (partially) in the United States. Without agreements regarding this transfer, you run a risk that is rarely well regulated in an internet model.
  • The sub-processor you didn't know about. Your email marketing tool itself engages an external party. If there is nothing about this in your agreement, you have no control over who gets their hands on your customer data.
  • The data leak at the supplier. Data is leaking from your payroll system. Who reports the leak, within what timeframe, and who bears the costs? If this is not established, you will be in a weak position afterwards.

In all these cases, the difference between a watertight and a defective agreement only becomes apparent the moment things go wrong – precisely when you can no longer change anything.

Do not agree to an imposed data processing agreement

A data processing agreement is concluded between the controller and the processor. Fundamentally, it is the data controller who takes the lead and indicates to the processor what is and is not acceptable. However, in practice, we frequently see the reverse: a processor has already 'for you' and presents it to you for signature.

That is not automatically wrong, but be alert. Such a document is often written primarily to remove responsibility from the processor. Especially if the processor had the agreement drafted by their own lawyer, there is a good chance that the balance will not tip in your favor. If things go wrong, such a unilateral agreement can boomerang back. Therefore, always have an imposed version checked before you sign, and strive for a balanced agreement that does justice to both parties.

Processor Agreement and liability in the event of a data breach

If a customer's personal data is leaked, that customer will likely hold you accountable first – even if the fault actually lay with the processor. This can result in a claim or compensation. At that point, the data processing agreement is consulted: based on the agreements made, it is assessed who should have done what.

A well-drafted agreement helps you demonstrate that you have fulfilled your obligations and that any shortcoming lay with the processor. That is precisely why the document should protect the position of the controller – and why an arbitrary online template or a version imposed by the processor poses a risk. Would you like to know how to strengthen your position as an entrepreneur in the event of a dispute? Our privacy and data protection specialists are happy to help.

How high are the fines under the GDPR?

The GDPR has a penalty system with two categories. For violations regarding a data processing agreement – ​​for example, if one is missing or does not meet the requirements of Article 28 – the lower category applies: a fine of up to a maximum of 10 million euros or 2% of worldwide annual turnover, whichever is higher. For more serious violations, the fine can rise to 20 million euros or 4% of worldwide annual turnover.

These are statutory maximum amounts. In practice, the Dutch Data Protection Authority rarely imposes the maximum; the amount depends on factors such as the severity and duration of the violation and the size of the organization. However, even for an SME, a fine can be very costly, quite apart from reputational damage and potential damage claims from data subjects.

The core conclusion: drafting a data processing agreement yourself is cheaper, but not if you face fines and compensation claims afterward. A properly drafted document is ultimately the cheapest insurance.

4 steps to a watertight data processing agreement

  1. Map out your processors. Make a list of all external parties that process personal data for you.
  2. Determine your role for each collaboration. Are you a data controller, a data processor, or is there joint responsibility?
  3. Document the agreements. Draft an agreement that complies with Article 28 of the GDPR and protects your interests – or have a submitted version critically reviewed.
  4. Keep the document up to date. Do your suppliers, processing activities, or sub-processors change? Then update the agreement.

Frequently asked questions about the data processing agreement

Is a data processing agreement mandatory?

Yes. As soon as you have personal data processed by an external party, you are required under Article 28 of the GDPR to conclude a data processing agreement regarding this. If this is missing, you are acting in violation of the law.

Can I use a free model from the internet?

That is allowed, but it is risky. A general model is not tailored to your processing activities, suppliers, and risks, and often lacks important provisions regarding liability, sub-processors, and data breaches. In any case, have a model reviewed before using it.

Who drafts the data processing agreement: me or my supplier?

In principle, the controller is in charge. Many suppliers do provide their own version; always check this critically, as such a document is often drafted to the processor's advantage.

What is the difference between a processor and a controller?

The controller determines the purpose and means of processing (you). The processor processes the data exclusively on your behalf and according to your instructions (for example, your software or hosting provider).

Do I need a data processing agreement with my accountant?

Often, yes. If your bookkeeper or administration office processes personal data (such as employee or customer data) on your behalf, a data processing agreement is required. However, if the office acts as an independent controller – for example, regarding statutory tax duties – the situation may be different. Have this assessed on a case-by-case basis.

How much does it cost to have a data processing agreement drawn up?

At MKB Juristen, we draft a custom data processing agreement for a fixed price of €189 per document. We discuss all your requirements in advance during a free intake, ensuring the document fits your situation perfectly.

Have a Data Processing Agreement drafted or reviewed?

Do you want to be sure that your data processing agreement is correct and protects your interests? We are happy to help you:

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

July 25, 2026

IT contracts for SMEs: which ones do you need?

IT contracts for SMEs: SLA, Data Processing Agreement/DPA, SaaS, licensing, maintenance, and development. What each is for and how they relate.

July 24, 2026

Having general terms and conditions drafted for the website: costs and process

Having general terms and conditions for the website drafted by a lawyer: what does it cost, how does the process work, and when should you choose custom-made...

July 24, 2026

Having a non-compete clause drafted: costs and process

Having a non-compete clause drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom draft over a template.

July 24, 2026

Checking contracts: step-by-step plan for SME entrepreneurs

Checking or reviewing a contract before signing: step-by-step plan, red flags, checklist, and when you need a lawyer.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation