To undertake

What is a data processing agreement for a software company? Explanation and use

What is a Data Processing Agreement for a software company? Explanation of its function, when you need it, and what to look out for as an SME.

Published on August 31, 2026 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

What is a Data Processing Agreement for a software company? It is the agreement in which you, as a SaaS provider or software developer, stipulate how you process the personal data that your customer (the data controller) entrusts to you. Article 28 of the GDPR mandates this agreement as soon as your software processes personal data on behalf of the customer — which is almost always the case with an online platform, an app, or a cloud service. You are then the processor, and that role entails its own obligations: security, sub-processors, notification requirements, audits, and the return of data at the end of the service.

The short answer

  • What: a mandatory agreement (Art. 28 GDPR) between your software company and the customer regarding the processing of personal data.
  • Your role: processor — you process data exclusively on behalf of the client.
  • Key topics: purpose and nature of processing, security (Art. 32), sub-processors, data location, data breach notification obligation, audit and return/deletion.
  • Who draws it up? In practice, almost always the software vendor itself, as a fixed part of the terms of service.
  • When: before the first processing, i.e. at the start of the subscription or implementation.

What exactly is a data processing agreement for a software company?

What is a Data Processing Agreement for a Software Company Explained for a SaaS Provider

The GDPR distinguishes between two roles. The customer determines why and how personal data is processed: that is the controller. You, as the software supplier, process that data on behalf of the customer and according to their instructions: that is the processor. This relationship arises as soon as a SaaS platform, an email tool, an accounting app, or a customer portal stores or processes third-party personal data.

Article 28(3) of the GDPR stipulates that this relationship must be recorded in writing (or digitally). Without a data processing agreement, both the customer and you are acting in violation of the GDPR. For a software company, the agreement is not a separate piece of paper, but a structural part of your service: you enter into it with every business customer who processes personal data via your software.

Why the processor side is different

Most explanations regarding data processing agreements are written from the client's perspective. For a software supplier, the emphasis is different. You determine the technical setup, choose the hosting and sub-processors, and are responsible for security. The client typically signs your template, not the other way around. This means that your data processing agreement must realistically align with how your service works technically.

A few points that carry more weight for you as a processor:

  • Instruction-dependent. You may only process data on the customer's instruction. Therefore, describe precisely which processing operations are “included” in the standard service, so that not every customer can impose separate instructions.
  • Sub-processors. You will almost certainly use cloud and infrastructure providers (hosting, email, backup, monitoring). These are sub-processors and must be properly arranged.
  • Security. Article 32 of the GDPR places part of the technical and organizational measures on you. You must be able to demonstrate what you do.
  • Liability. As a processor, you want to limit your liability; customers, on the other hand, want room. You strike that balance here.

The key agreements at a glance

Key agreements in a data processing agreement for a SaaS provider

A workable data processing agreement for a software company regulates, in any case:

  • Subject and duration of processing, linked to the term of the subscription.
  • Nature, purpose, and type of data: which categories of data subjects and personal data your software affects (often in an appendix).
  • Security measures in accordance with Article 32, such as encryption, access control, and logging.
  • Sub-processors: a list and a procedure for changes.
  • Data location: where the data is located (EU/EEA) and what applies to transfers outside of it.
  • Data breach notification obligation: the timeframe within which you inform the customer.
  • Audit and cooperation: how the client can exercise control.
  • Return and deletion of data after completion.

Subprocessors and cloud

Sub-processors and cloud hosting in the processor agreement of a software company

Virtually no software company runs entirely on its own hardware. You use cloud hosting, an email provider, a payment service, and a monitoring tool. All those parties that process personal data on your behalf are sub-processors. Article 28, paragraphs 2 and 4 of the GDPR stipulates that you may only engage sub-processors with the customer's consent and that you must impose the same obligations on them as those that apply to you.

In practice, you usually work with general consent: the customer agrees to a published list of sub-processors, and you inform them in advance of any changes, including a period for objection. This is workable for large numbers of customers. Pay attention to the data location: if a sub-processor (for example, a large cloud provider) operates outside the EEA, you need a valid legal basis for transfer, such as the European Commission's Standard Contractual Clauses.

Security, data breaches and end of service

Three topics that often come down to when it comes to software:

  • Security (Art. 32). Describe concretely what you do: encryption of data at rest and in transit, two-factor authentication, separate environments, backups, and recovery procedures. Be honest about what you do and do not offer.
  • Notification obligation. In the event of a data breach, you, as the processor, must inform the customer “without delay” so that they can assess whether notification to the Dutch Data Protection Authority is necessary. Set a realistic timeframe, for example, within 48 hours of discovery.
  • Return and deletion. Upon completion of the service, you must return or delete the data, at the customer's choice. Arrange an export format and a deletion period, and take statutory retention obligations into account.

Practical example

A SaaS provider of planning software for the healthcare sector entered into a data processing agreement with every customer but had recently moved the hosting to a new cloud provider without updating the list of sub-processors. When a customer conducted an audit, it turned out that the data location no longer matched the agreement. By keeping the list of sub-processors up-to-date from then on and informing customers in advance, the problem was resolved structurally — and the audit was completed more quickly.

Honest recommendation

Lawyer advises a software company on the data processing agreement

As a software supplier, you need a data processing agreement — this is not a choice, but a legal obligation. The main question is whether to engage a lawyer yourself. If you run a standard SaaS service with common sub-processors and ordinary (non-sensitive) personal data, you can manage perfectly well with a well-thought-out standard template that you have drafted once and then reuse for all customers. However, if you process sensitive data (healthcare, financial), have customers who impose their own templates, or work with many sub-processors outside the EEA, then legal guidance is indeed advisable — precisely because you bear the risk.

Want to know more? View the data processing agreement for a software company, read how to draft such an agreement and which pitfalls to avoid.

Frequently Asked Questions

What is a data processing agreement for a software company?

It is the agreement required under Article 28 of the GDPR in which your software company, as a processor, sets out how it processes the personal data entrusted to it by the customer (controller). Topics include security, sub-processors, data location, notification obligations, and data return.

Am I a processor or a controller as a SaaS provider?

Usually a processor: you process personal data on behalf of and at the instruction of your client. You are the controller for your own client administration, but for the data that clients process via your software, you are a processor.

Is a data processing agreement mandatory for software?

Yes. As soon as your software processes personal data on behalf of the customer, an agreement is mandatory under Article 28 of the GDPR. Without an agreement, both you and the customer are acting in violation of the GDPR.

Who drafts the data processing agreement?

In practice, it is almost always the software vendor itself, as a fixed part of the terms of service. You use one standard model for all your clients. Large clients sometimes impose their own model; in that case, you assess whether it aligns with your technology.

What are sub-processors?

These are parties you engage who, in turn, process personal data, such as your cloud hosting, email provider, or monitoring tool. You may only use them with the customer's consent and must impose the same GDPR obligations on them that apply to you.

Where should the data be placed?

Preferably within the EU/EEA. If data is held by a sub-processor outside this area, you need a valid legal basis for transfer, such as the European Commission's Standard Contractual Clauses. Clearly define the data location in the agreement.

What happens to the data if the customer stops?

At completion, you return the data or delete it, at the customer's choice. Establish an export format, a deletion period, and any statutory retention obligations to ensure there is no ambiguity at the end of the service.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

September 8, 2026

What are the general terms and conditions for companies that sell training and courses? Function and legal status

What are general terms and conditions for companies that sell education and courses? Explanation of the function, when you need it and where...

September 8, 2026

What is an order confirmation? Explanation and use

What is an order confirmation? Explanation of its function, when you need it, and what to look out for in the SME sector.

September 8, 2026

The debt collection procedure: how a debt collection process works

The debt collection process from A to Z: amicable settlement, summons, judgment, and attachment. Steps, turnaround time, and costs per phase explained.

September 8, 2026

Notice of default example: the most important provisions

Need an example of a notice of default? The most important provisions listed and why an example never fits perfectly.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation