Data Processing Agreement (DPA): When You Need One and What Must Be Included

A data processing agreement (DPA) is always mandatory when an external service provider, such as a cloud storage provider, a newsletter tool, payroll accounting, IT maintenance, or an AI service, processes personal data on behalf of your company (Article 28 GDPR). The contract must, among other things, govern the subject matter and duration, the nature and purpose of the processing, the data categories, and the obligations and rights of both parties (Article 28(3)). Without a valid DPA, no real personal data may be entrusted to a service provider.
By the Provimedia editorial team. As of July 2026. This article is general information, not legal advice, and not a ready-to-sign contract template.
What Is a Processor?
Under Article 4(8) GDPR, a processor is "a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller." Typical examples in everyday business are the cloud storage provider, the email marketing tool, the outsourced payroll office, the IT service provider with remote maintenance access, and increasingly AI services to which employees submit texts containing personal data.
Important: even though the service provider processes the data technically, your company remains the controller in the legal sense and is liable externally.
When Do You Need a DPA?
Whenever you entrust an external service provider with processing personal data and that provider acts under instruction for you rather than on its own responsibility for its own purposes. Under Article 28(1) GDPR, the controller may only work with processors that offer "sufficient guarantees" for appropriate technical and organizational measures. Choosing the service provider is therefore itself a data protection decision, not just a question of price.
What Must a DPA Contain? (Article 28(3) GDPR)
| Mandatory item | Short description |
|---|---|
| Subject matter and duration of the processing | What exactly is processed and how long the contract runs |
| Nature and purpose of the processing | What the data is processed for |
| Type of data and categories of data subjects | Which data types (for example contact data) and whose data (for example customers, applicants) |
| Obligations and rights of the controller | How the controller exercises its control and instruction rights |
| Processing only on documented instructions | The processor may not act on its own authority |
| Confidentiality obligation of the personnel involved | Persons with access are bound to confidentiality |
| Appropriate TOMs under Article 32 | The service provider secures the data technically and organizationally |
| Rules for subprocessors | Conditions under which the service provider may engage further service providers |
| Support with data subject rights and Articles 32 to 36 | The service provider assists with information, deletion, or notification obligations |
| Deletion/return of data after the contract ends | A clear rule for what happens to the data at the end |
| Verification and audit rights | The controller can check compliance or have it checked |
This table reflects the structure under Article 28(3) GDPR and serves as guidance on which points a DPA must cover. It does not replace a legal review of the specific contract text by your data protection officer or by legal counsel.
DPA or Joint Controllership? A Common Point of Confusion
Not every collaboration with an external partner is processing on behalf of a controller. If two parties decide jointly on the purposes and means of the processing, Article 26 GDPR applies instead ("joint controllers"), a different contractual construct with its own transparency obligations. A DPA only fits when the service provider acts exclusively on your instructions and pursues no purposes of its own. When in doubt, your data protection officer will clarify this.
What Happens Without a Valid DPA?
Violations of the obligations of controllers and processors under Articles 8, 11, 25 to 39, 42, and 43 GDPR, and therefore also against Article 28, can be penalized with fines of up to 10 million euros or 2% of worldwide annual turnover, whichever amount is higher (Article 83(4) GDPR). In practice, a missing DPA also means that sharing the data with the service provider itself can be unlawful.
Checklist: Five Steps to a DPA
- Identify service providers: which external tools and providers have access to personal data?
- Clarify the role: processing on behalf of a controller (Article 28) or joint controllership (Article 26)?
- Check or request the contract: does the provider already offer a DPA (many standard providers do)?
- Cross-check the mandatory content: does the contract contain all the points from Article 28(3)?
- Document it: note the DPA in the record of processing activities (Article 30).
The DPA is only one building block of the broader accountability obligation; more on that in our article Accountability Under the GDPR. Anyone who also wants to raise employee awareness of the correct handling of external service providers will find exactly these fundamentals in our GDPR fundamentals training, which can be booked online.
Frequently Asked Questions (FAQ)
When Is a DPA Mandatory?
Whenever an external service provider processes personal data on instruction on behalf of your company, for example with cloud, email marketing, or payroll services (Article 28 GDPR).
What Must a DPA Necessarily Contain?
Among other things, the subject matter and duration of the processing, the nature and purpose, the data categories involved, rules on being bound by instructions, confidentiality, technical security, subprocessors, support obligations, and deletion after the contract ends (Article 28(3) GDPR).
Do the Provider's Terms and Conditions Count as a DPA?
Only if the terms and conditions actually contain all the mandatory content from Article 28(3) GDPR and are legally effective as a contract on data processing. Many reputable providers offer a separate DPA document for this purpose, which should be reviewed.
What to Do If a Provider Does Not Offer a DPA?
Then no real personal data may be entrusted to it. Either switch to an alternative provider that offers a DPA, or consistently anonymize the data before using the service.
Sources
- Regulation (EU) 2016/679 (GDPR), Article 4(8), Article 26, Article 28(1) and (3), Article 83(4): eur-lex.europa.eu
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Phishing and Social Engineering: How Your Employees Can Spot an Attack
Phishing, spear phishing, CEO fraud, and smishing target people, not systems. The warning signs a phishing employee training should teach, and why a successful attack quickly turns into a reportable data breach.
GDPR Fines: Real Cases from Germany and What Companies Can Learn from Them
Four real GDPR fine cases from Germany show how authorities calculate the amount, and that courts can also significantly reduce them afterward.
Information Security Training vs. GDPR Training: What Companies Actually Need
Information security protects systems and information, data protection protects people and their data. The difference, the overlap under Art. 32 GDPR, and what the new NIS2 training duty means for management boards.
Bereit für den dokumentierten Schulungsnachweis?
Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.