Skip to content

Data Processing Agreement (DPA): When You Need One and What Must Be Included

Provimedia Redaktion 7 min read 09 July 2026 2 views
Datenschutz & DSGVO
Data Processing Agreement (DPA): When You Need One and What Must Be Included
Illustrative image · AI-generated

A data processing agreement (DPA) is always mandatory when an external service provider, such as a cloud storage provider, a newsletter tool, payroll accounting, IT maintenance, or an AI service, processes personal data on behalf of your company (Article 28 GDPR). The contract must, among other things, govern the subject matter and duration, the nature and purpose of the processing, the data categories, and the obligations and rights of both parties (Article 28(3)). Without a valid DPA, no real personal data may be entrusted to a service provider.

By the Provimedia editorial team. As of July 2026. This article is general information, not legal advice, and not a ready-to-sign contract template.

What Is a Processor?

Under Article 4(8) GDPR, a processor is "a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller." Typical examples in everyday business are the cloud storage provider, the email marketing tool, the outsourced payroll office, the IT service provider with remote maintenance access, and increasingly AI services to which employees submit texts containing personal data.

Important: even though the service provider processes the data technically, your company remains the controller in the legal sense and is liable externally.

When Do You Need a DPA?

Whenever you entrust an external service provider with processing personal data and that provider acts under instruction for you rather than on its own responsibility for its own purposes. Under Article 28(1) GDPR, the controller may only work with processors that offer "sufficient guarantees" for appropriate technical and organizational measures. Choosing the service provider is therefore itself a data protection decision, not just a question of price.

What Must a DPA Contain? (Article 28(3) GDPR)

Mandatory itemShort description
Subject matter and duration of the processingWhat exactly is processed and how long the contract runs
Nature and purpose of the processingWhat the data is processed for
Type of data and categories of data subjectsWhich data types (for example contact data) and whose data (for example customers, applicants)
Obligations and rights of the controllerHow the controller exercises its control and instruction rights
Processing only on documented instructionsThe processor may not act on its own authority
Confidentiality obligation of the personnel involvedPersons with access are bound to confidentiality
Appropriate TOMs under Article 32The service provider secures the data technically and organizationally
Rules for subprocessorsConditions under which the service provider may engage further service providers
Support with data subject rights and Articles 32 to 36The service provider assists with information, deletion, or notification obligations
Deletion/return of data after the contract endsA clear rule for what happens to the data at the end
Verification and audit rightsThe controller can check compliance or have it checked

This table reflects the structure under Article 28(3) GDPR and serves as guidance on which points a DPA must cover. It does not replace a legal review of the specific contract text by your data protection officer or by legal counsel.

DPA or Joint Controllership? A Common Point of Confusion

Not every collaboration with an external partner is processing on behalf of a controller. If two parties decide jointly on the purposes and means of the processing, Article 26 GDPR applies instead ("joint controllers"), a different contractual construct with its own transparency obligations. A DPA only fits when the service provider acts exclusively on your instructions and pursues no purposes of its own. When in doubt, your data protection officer will clarify this.

What Happens Without a Valid DPA?

Violations of the obligations of controllers and processors under Articles 8, 11, 25 to 39, 42, and 43 GDPR, and therefore also against Article 28, can be penalized with fines of up to 10 million euros or 2% of worldwide annual turnover, whichever amount is higher (Article 83(4) GDPR). In practice, a missing DPA also means that sharing the data with the service provider itself can be unlawful.

Checklist: Five Steps to a DPA

  1. Identify service providers: which external tools and providers have access to personal data?
  2. Clarify the role: processing on behalf of a controller (Article 28) or joint controllership (Article 26)?
  3. Check or request the contract: does the provider already offer a DPA (many standard providers do)?
  4. Cross-check the mandatory content: does the contract contain all the points from Article 28(3)?
  5. Document it: note the DPA in the record of processing activities (Article 30).

The DPA is only one building block of the broader accountability obligation; more on that in our article Accountability Under the GDPR. Anyone who also wants to raise employee awareness of the correct handling of external service providers will find exactly these fundamentals in our GDPR fundamentals training, which can be booked online.

Frequently Asked Questions (FAQ)

When Is a DPA Mandatory?

Whenever an external service provider processes personal data on instruction on behalf of your company, for example with cloud, email marketing, or payroll services (Article 28 GDPR).

What Must a DPA Necessarily Contain?

Among other things, the subject matter and duration of the processing, the nature and purpose, the data categories involved, rules on being bound by instructions, confidentiality, technical security, subprocessors, support obligations, and deletion after the contract ends (Article 28(3) GDPR).

Do the Provider's Terms and Conditions Count as a DPA?

Only if the terms and conditions actually contain all the mandatory content from Article 28(3) GDPR and are legally effective as a contract on data processing. Many reputable providers offer a separate DPA document for this purpose, which should be reviewed.

What to Do If a Provider Does Not Offer a DPA?

Then no real personal data may be entrusted to it. Either switch to an alternative provider that offers a DPA, or consistently anonymize the data before using the service.

Sources

  • Regulation (EU) 2016/679 (GDPR), Article 4(8), Article 26, Article 28(1) and (3), Article 83(4): eur-lex.europa.eu

Share this article

Stay up to date

Get the latest articles, insights and industry updates straight to your inbox.

Unsubscribe at any time. See our privacy policy.

Decide for yourself what Google shows you

Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.

Add provimedia.de to my preferred sources

Bereit für den dokumentierten Schulungsnachweis?

Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.