Processing on behalf occurs when a provider processes personal data for a company under its instructions — the cloud provider, the host, the newsletter tool, the IT provider with system access. For this constellation Article 28 GDPR prescribes a data processing agreement (DPA).
The DPA regulates what the provider may and must do: process only on instruction, ensure confidentiality, provide TOMs, report incidents without delay, disclose subprocessors and delete or return data after contract end.
What belongs in a DPA
Article 28 dictates the mandatory content: subject, duration, nature and purpose of the processing, data categories and data subjects, the processor’s duties — instruction binding, confidentiality, TOMs, support with data subject rights and reporting duties, handling of subprocessors, the controller’s audit rights and the rules for deletion or return at the end.
Three points decide in practice: the TOMs as a concrete, current annex; the subprocessor list including notification or consent mechanics for changes; and for third-country transfers the right safeguards — standard contractual clauses or an adequacy decision such as the EU-US Data Privacy Framework.
DPA practice in the company
- Keep an inventory: which providers process which data — with or without a DPA?
- Actually read TOM annexes: vague measures are a warning sign.
- Monitor subprocessor changes — data often moves to new countries there.
- Check managed services contracts: system access usually means processing on behalf.