MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
A good example of a data processing agreement always contains the same core elements: a description of the processing, the binding instructions, the security obligation (Article 32 GDPR), agreements regarding sub-processors, the obligation to report data breaches, and the return or deletion of data after completion. These components are not optional — Article 28(3) of the GDPR mandates them. Below, we will review the most important provisions so that you can assess the value of an example.
The short answer
- Description of processing: subject, duration, nature, purpose, types of data and data subjects.
- Binding under instructions: the processor acts only on written instructions.
- Security: appropriate technical and organisational measures (Article 32).
- Sub-processors: only with consent and with the passing on of obligations.
- Data breach and return: notification obligation to the controller and deletion upon completion.
Processor Agreement example: the standard components
Each usable example opens with a description of the processing. This states the subject, duration, nature, and purpose of the processing, plus the types of personal data and the categories of data subjects. This description is not an introduction, but limits what the processor may do: anything outside of this falls outside the scope of the assignment.
Instruction binding follows immediately thereafter. The processor processes the data exclusively on the basis of documented instructions from the controller. If he deviates from this, he acts at his own risk and may himself become the controller for that processing.
Security (Article 32)
The security provision refers to Article 32 of the GDPR: appropriate technical and organisational measures. In a strong example, these are not only mentioned in abstract terms, but reference is made to concrete measures such as encryption, access control, logging, and a periodic evaluation. What constitutes “appropriate” depends on the sensitivity of the data and the risks of the processing.
Pay attention to the confidentiality clause: anyone who has access to the data on behalf of the processor is bound by a duty of confidentiality. Without that provision, the security agreement is incomplete.
Subprocessors
A processor often engages parties itself—a hosting provider, a backup service. The sub-processor clause stipulates that this is only permitted with the (general or specific) consent of the controller. Furthermore, the processor must impose the same GDPR obligations on the sub-processor as those set out in the processor agreement. The main processor remains liable for compliance by its sub-processors.
Data breach notification obligation
A good example states that the processor reports a data breach to the controller without delay, with sufficient information to assess the severity. The processor does not report to the Dutch Data Protection Authority itself — that remains the responsibility of the controller, who must report within 72 hours of becoming aware of it if the breach poses a risk. Specify the minimum information the notification must contain and the channel through which it is submitted.
Return and disposal
The final provision regulates what happens after completion. The processor returns the personal data or destroys them, at the option of the controller, and deletes existing copies — unless a statutory retention obligation requires otherwise. A strong example specifies a concrete timeframe and requires confirmation of the deletion.
Honest recommendation
An example from a reputable supplier is usually perfectly usable for a standard service. Compare it to the six components above: if they are all included, you can use it without a lawyer. That is sufficient for the typical SME situation.
Consult a lawyer when processing special categories of data, transferring data outside the EU, or when you are a processor yourself and wish to offer a sample as your own model. Blindly copying a sample without adapting it to your actual processing is a common mistake.
Read more: view the checklist to test the example, read which pitfalls to avoid, or draft one directly via the data processing agreement.
Frequently Asked Questions
A description of the processing, the binding instructions, the security obligation (Article 32 GDPR), agreements regarding sub-processors, the obligation to notify in the event of data breaches, and the return or deletion of data after completion. Article 28 paragraph 3 of the GDPR prescribes these elements.
Do not do so blindly. Adapt the example to your actual processing: types of data, purpose, retention period, and sub-processors. An example that does not correspond to reality creates a false sense of security and may be in violation of the GDPR.
There is no single main provision: the strength lies in the combination. If one mandatory element is missing — for example, the sub-processor clause or the deletion provision — the model does not comply with Article 28 of the GDPR.
That the processor processes data exclusively on documented instructions from the controller. If he deviates from this, he acts at his own risk and may himself become the controller for such processing.
The measures must be appropriate to the sensitivity of the data and the risks (Article 32 GDPR). A strong example mentions concrete measures such as encryption, access control, and logging, and mandates confidentiality for everyone with access.
The processor reports the breach to the controller without delay. The controller decides whether notification to the Data Protection Authority within 72 hours is required. A good example specifies what information the notification contains and through which channel it is submitted.
That the processor returns or destroys the data after completion, at the option of the controller, and deletes copies unless a statutory retention obligation requires otherwise. A specific time limit and confirmation of the deletion must be included.