MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
A data processing agreement (Art. 28 GDPR) is a mandatory contract between the controller (your BV) and the processor (an external party that processes personal data on your behalf). Examples: hosting provider, payroll service, marketing tool, cloud software. Content is legally prescribed: subject matter, duration, nature of processing, type of data, and processor obligations. Without a valid data processing agreement: a Data Protection Authority fine of up to 2% of global turnover. For SME BVs, this is an almost daily occurrence. Below are the mandatory content and practice.
The short answer
- What: mandatory contract between controller and processor (Art. 28 GDPR).
- Who is the processor: hosting, payroll, marketing tool, cloud software, customer support.
- Required content: subject, duration, nature, data, processor obligations.
- Format: in writing (email agreement is permitted).
- Sanctions: AP fine of up to 2% of global turnover for non-compliance.
What is processor vs. controller?
Controller
Determines the purpose and means of processing — your BV regarding customer data, employee data, and marketing.
Processor
Performs processing on behalf of the controller — without making its own decision regarding the purpose or means. E.g., a hosting provider that keeps your data on servers, a payroll service that calculates salaries.
Jointly responsible parties
Two parties jointly determine the goal/means — e.g., a partnership between companies with shared customer data. Another form of agreement (Art. 26 GDPR).
When is a data processing agreement required?
- Hosting/cloud provider for customer or employee data.
- Payroll service for salary administration.
- Email marketing tool (Mailchimp, Klaviyo).
- CRM software (HubSpot, Salesforce).
- Customer support tool (Zendesk, Intercom).
- Accounting software (Yuki, Exact, Moneybird) — when processing personal data.
- HR software (Personio, AFAS).
- Backup service.
- Marketing agency that executes campaigns using data.
- Collection agency for debtors.
Virtually any external tool with customer or personnel data.
Mandatory content (Art. 28 para. 3 GDPR)
- Subject and duration: what is being processed, and for how long.
- Nature and purpose of processing: hosting, processing, analysis.
- Type of personal data: Name, address, financial, health.
- Categories of stakeholders: customers, employees, suppliers.
- Rights and obligations of the responsible party.
- Processor obligations:
- Process exclusively on documented instructions.
- Staff confidentiality.
- Adequate security (TOM = Technical and Organizational Measures).
- Consent required for sub-processors.
- Assistance with requests from data subjects.
- Help with data breach notifications.
- Help with DPIAs.
- After end: delete or return data.
- Audit rights responsible.
Subprocessors
Processor may engage sub-processors (e.g. hosting provider uses server center) — with the consent of the controller. Standard clauses:
- List of current sub-processors.
- Obligation to inform of a new sub-processor.
- Right of the responsible party to object.
- Sub-processor has the same obligations as a processor.
Standard Contractual Clauses (SCC)
For transfers outside the EU (US tools): EU Commission standard contractual clauses. Required:
- Mention in processor agreement.
- SCC attachments completed.
- For the US: additional security measures (following Schrems II).
Supplier's standard agreement is often sufficient
Major suppliers (Microsoft, Google, AWS, Mailchimp) have a standard Data Processing Agreement (DPA):
- To be accepted online upon account application.
- Complies with GDPR.
- For SMEs: usually sufficient — no separate negotiation.
Important: accept and archive as evidence in current condition.
Tessa's data processing agreements
Tessa has 8 processors:
- Hosting: AWS — DPA accepted online, archived.
- Accounting: Yuki — DPA in contract.
- HR software: Personio — DPA in contract.
- Email marketing: Mailchimp — DPA online accepted.
- Cloud storage: Google Workspace — DPA in subscription.
- Customer Support: Zendesk — DPA under contract.
- CRM: HubSpot — DPA under contract.
- Payroll administration: ADP — custom-built proprietary DPA.
Central archive with all DPAs — immediately available during AP checks.
Honest recommendation
For SMEs: inventory all external parties with access to personal data. For large standard tools: accept and archive standard DPAs. For specific or small suppliers: have your own template ready (€500-€1,500 with a lawyer). For international tools: verify SCCs. The inventory takes 4-8 hours, prevents a DPA fine, and ensures GDPR compliance.
For other topics: processing register, privacy statement and data breach.
Frequently Asked Questions
Mandatory contract (Art. 28 GDPR) between the controller and an external party that processes personal data on your behalf. E.g. hosting, payroll, marketing tool, cloud software. Content prescribed by law.
With every external party that processes personal data on your behalf: hosting, payroll, email marketing, CRM, HR software, accounting, customer support, etc. Virtually every external SaaS tool containing customer or employee data.
Subject matter and duration, nature and purpose of processing, type of data, categories of data subjects, processor obligations (instructions, confidentiality, security, sub-processors, assistance with rights/data breach, end-of-deletion, audit), controller rights.
Major vendors (Microsoft, Google, AWS, Mailchimp) offer standard Data Processing Agreements (DPA) that can be accepted online. For SMEs: usually sufficient, no separate negotiation required. Important: archive as proof.
External party engaging a processor (e.g., hosting provider using a server center). The processor may do so with the consent of the controller. Standard clauses: list of current sub-processors, right to object to new ones.
For US tools or other non-EU tools: EU Commission Standard Contractual Clauses (SCC) mandatory. Mention in DPA + SCC appendices completed. For US: additional security measures following Schrems II.
AP fine of up to 2% of global turnover or €10 million. In the event of a data breach at a processor without a DPA: both parties are liable. Invest 4-8 hours in inventory and DPAs — prevents fines and ensures compliance.