Glossary · simply explained

Data processing agreements (DPA)

Processing on behalf occurs when a provider processes personal data for a company under its instructions — the cloud provider, the host, the newsletter tool, the IT provider with system access. For this constellation Article 28 GDPR prescribes a data processing agreement (DPA).

The DPA regulates what the provider may and must do: process only on instruction, ensure confidentiality, provide TOMs, report incidents without delay, disclose subprocessors and delete or return data after contract end.

What belongs in a DPA

Article 28 dictates the mandatory content: subject, duration, nature and purpose of the processing, data categories and data subjects, the processor’s duties — instruction binding, confidentiality, TOMs, support with data subject rights and reporting duties, handling of subprocessors, the controller’s audit rights and the rules for deletion or return at the end.

Three points decide in practice: the TOMs as a concrete, current annex; the subprocessor list including notification or consent mechanics for changes; and for third-country transfers the right safeguards — standard contractual clauses or an adequacy decision such as the EU-US Data Privacy Framework.

DPA practice in the company

  • Keep an inventory: which providers process which data — with or without a DPA?
  • Actually read TOM annexes: vague measures are a warning sign.
  • Monitor subprocessor changes — data often moves to new countries there.
  • Check managed services contracts: system access usually means processing on behalf.

Frequently asked questions about Data processing agreements (DPA)

When do I need a DPA?

As soon as a provider processes personal data for you under instructions — hosting, cloud services, SaaS tools, support with system access. No DPA is needed for independently responsible recipients (tax advisors, say) — different rules apply there.

Who must offer the DPA — customer or provider?

The duty hits both sides; in practice established providers supply standard DPAs, often for online conclusion. What matters is less who supplies the paper than that content, TOMs and subprocessors match the actual processing.

What are subprocessors and why do they matter?

Subcontractors of the provider — such as the data center behind the SaaS tool. The DPA must disclose them and make changes notifiable, because with every subprocessor data can change processing location and jurisdiction.

Is the standard DPA of a US provider enough?

The DPA alone governs the processing relationship; for transfers to third countries additional safeguards are needed — standard contractual clauses or an adequacy decision such as the EU-US Data Privacy Framework. Technical measures such as EU processing regions strengthen the position; case-by-case assessment belongs to the data protection officer.

Is a managed services contract automatically processing on behalf?

Usually yes: whoever operates systems or has access to systems with personal data — logs, user accounts, tickets — generally processes on behalf. That is why a managed services contract usually includes a DPA with concrete TOMs.

From term to implementation: KAEMI supports you from the first assessment to the ongoing managed service.