Skip to content
Legiscope
Menu
Data Privacy

Data Processing Agreements Under GDPR: Complete Guide

Complete guide to GDPR data processing agreements: mandatory clauses, sub-processor rules, audit rights, and enforcement examples under Article 28.

A data processing agreement (DPA) is the legally mandated contract between a data controller and a data processor under the GDPR. Every time an organisation engages a vendor, cloud provider, payroll bureau, or any third party that handles personal data on its behalf, Article 28 requires a binding written agreement that sets out the terms of that processing relationship.

Despite this clear obligation, DPA deficiencies remain one of the most common findings in supervisory authority audits across Europe. The DLA Piper GDPR Fines Survey January 2026 reported cumulative fines exceeding EUR 7.1 billion since the regulation took effect, with a growing number of enforcement actions targeting inadequate or missing processor agreements. In 2024 alone, the Spanish AEPD issued over 40 sanctions where the absence or insufficiency of a data processing agreement gdpr was a contributing factor.

This guide covers every element you need to draft, review, and maintain compliant DPAs.

What Does Article 28 Require in a Data Processing Agreement?

Article 28(3) GDPR prescribes the minimum content that every data processing agreement gdpr must include. The contract must be in writing, which includes electronic form, and must set out:

  • Subject matter and duration of the processing
  • Nature and purpose of the processing
  • Types of personal data processed
  • Categories of data subjects whose data is processed
  • Obligations and rights of the controller

These are not optional boilerplate elements. Each clause must be specific to the actual processing relationship. A generic template that fails to describe the concrete processing activities will not satisfy the regulation.

Beyond the descriptive clauses, Article 28(3)(a)-(h) imposes eight specific obligations on the processor:

  1. Process only on documented instructions from the controller, unless required by EU or Member State law.
  2. Ensure confidentiality – all authorised persons must be under a confidentiality commitment.
  3. Implement appropriate security measures in accordance with Article 32.
  4. Respect the conditions for engaging sub-processors, including prior written authorisation.
  5. Assist the controller in responding to data subject rights requests.
  6. Assist with breach notification, DPIAs, and prior consultation under Articles 32-36.
  7. Delete or return all personal data after the end of services.
  8. Make available all information necessary to demonstrate compliance and contribute to audits.

Omitting any one of these eight points renders the DPA non-compliant. The Finnish Data Protection Ombudsman fined a healthcare processor EUR 608,000 in 2023 partly because the DPA lacked adequate data deletion provisions.

How Should You Handle Sub-Processor Obligations?

The sub-processor chain is where many data processing agreement gdpr arrangements break down. Article 28(2) requires that a processor must not engage another processor without prior specific or general written authorisation of the controller.

Under specific authorisation, the processor obtains written consent before engaging each sub-processor. Under general authorisation, the processor informs the controller of intended changes, giving the controller the opportunity to object. The DPA must specify which model applies and document the objection mechanism.

Article 28(4) requires that the same data protection obligations in the controller-processor DPA be imposed on every sub-processor by contract. The processor remains fully liable for the sub-processor’s performance. A 2024 audit by the Danish DPA (Datatilsynet) found that 35% of processor agreements reviewed failed to include adequate sub-processor flow-down clauses, resulting in formal compliance orders.

What Audit Rights Must the DPA Include?

Article 28(3)(h) requires the processor to make available all information necessary to demonstrate compliance and to allow for and contribute to audits conducted by the controller or a mandated auditor. Effective audit clauses should address:

  • Scope – whether the controller can audit premises, systems, and documentation, or accept third-party reports (SOC 2, ISO 27001) as a substitute
  • Frequency and notice – how often audits may occur and required notice periods
  • Cost allocation – who bears audit costs
  • Sub-processor coverage – whether audit rights extend down the chain

The DPA must preserve the right to conduct direct audits even where third-party certifications are accepted as the default, particularly following security incidents.

How Should International Transfers Be Addressed?

Where a processor or sub-processor is located outside the EEA, the data processing agreement gdpr must address international data transfers under Chapter V of the GDPR. The DPA should specify:

The EDPB Recommendations 01/2020 on supplementary measures remain the authoritative reference. Any DPA involving transfers to a non-adequate jurisdiction that omits these elements is exposed to enforcement risk.

Common Mistakes in Data Processing Agreements

Using generic templates without customisation. A data processing agreement gdpr that describes the processing as “providing services” without specifying data types, data subject categories, or purposes fails Article 28(3). The Belgian DPA sanctioned a controller in 2023 for using an identical template across 12 processors without adapting it to the specific processing performed by each.

Failing to update DPAs when processing changes. When the scope changes – new data categories, new purposes, new sub-processors – the agreement must be updated. A record of processing activities that reflects current processing but an outdated DPA creates a compliance gap supervisory authorities will identify.

Missing data deletion provisions. The obligation to delete or return personal data at the end of the relationship is frequently absent or vaguely drafted. Specifying the deletion timeline, method, and provision of a deletion certificate strengthens compliance.

How Does Enforcement Target DPA Failures?

The Greek DPA (HDPA) fined PricewaterhouseCoopers EUR 150,000 in 2019 for processing personal data without a compliant DPA. The authority found that PwC had processed employee data on behalf of a client without any written agreement addressing Article 28 requirements.

In Germany, the Berlin Commissioner for Data Protection fined a real estate company EUR 14.5 million in 2019 (later reduced on appeal), with findings that included inadequate data processing agreements with service providers who had access to tenant data.

The Spanish AEPD imposed a EUR 200,000 fine on a fintech company in 2024 partly because its DPA with a payment processor did not include sub-processor notification and objection mechanisms.

These cases reinforce that supervisory authorities read the actual contract text and sanction specific deficiencies. Meeting the broader GDPR requirements demands that DPAs receive the same attention as any other compliance obligation.

Checklist for a Compliant Data Processing Agreement

Use this checklist alongside your GDPR compliance checklist to verify each DPA in your vendor portfolio:

  • [ ] Subject matter, duration, nature, and purpose of processing described specifically
  • [ ] Types of personal data and categories of data subjects identified
  • [ ] All eight Article 28(3) processor obligations included
  • [ ] Sub-processor authorisation model specified (specific or general)
  • [ ] Sub-processor flow-down clause requiring equivalent obligations
  • [ ] Sub-processor change notification and objection mechanism documented
  • [ ] Audit rights preserved, with scope, frequency, and cost terms
  • [ ] International transfer mechanism identified with TIA obligations
  • [ ] Data deletion or return obligations with timeline and certification
  • [ ] Controller due diligence on processor documented

Frequently Asked Questions

Is a data processing agreement always required under GDPR?

Yes, whenever a controller engages a processor to handle personal data on its behalf. Article 28(3) requires a binding written contract with no threshold or de minimis exception. Even a small business using a cloud email provider is in a controller-processor relationship that requires a DPA.

Can we use the processor’s standard DPA template?

You can, provided it meets all Article 28 requirements and accurately describes the specific processing performed. The controller remains responsible for verifying adequacy and customising the template where standard terms do not reflect the actual processing relationship.

What happens if our processor refuses to sign a DPA?

You cannot lawfully engage that processor. If a vendor will not sign a DPA or agree to mandatory Article 28 clauses, you must either negotiate until the agreement is compliant or find an alternative processor. Using a processor without a DPA exposes the controller to enforcement action.

How often should DPAs be reviewed?

There is no fixed review period in the GDPR, but best practice is to review DPAs at least annually and whenever there is a material change in the processing relationship. Your ROPA review cycle is a natural trigger for DPA reviews.

Does the DPA need to cover data breach notification?

Yes. Article 28(3)(f) requires the processor to assist the controller with breach notification obligations under Articles 33 and 34. The DPA should specify the notification timeline (typically without undue delay and within a fixed number of hours), the information to be provided, and the cooperation obligations during incident response.

FAQ

What is a Data Processing Agreement (DPA) under GDPR?

A DPA is a legally binding contract required by Article 28 GDPR between a data controller and a data processor. It must specify the processing subject matter, duration, nature, purpose, data types, and the processor’s obligations including security, sub-processor management, and audit rights.

Are standard template DPAs (e.g. vendor terms) acceptable under GDPR?

Yes, if they cover all mandatory Article 28(3) elements. Many cloud vendors (AWS, Google, Microsoft) offer pre-signed DPAs. Controllers should verify these cover all required clauses rather than accepting them unchecked, as some vendor templates favour the vendor.

What happens to a DPA when the controller-processor relationship ends?

Article 28(3)(g) requires the processor to delete or return all personal data to the controller at the end of services. The DPA must specify which option applies and within what timeframe. Processors retaining data beyond this without instruction violate Article 28.

Do DPAs need to be updated when GDPR changes or new regulations apply?

Yes. DPAs should be reviewed when regulations change, when processing activities change materially, and when sub-processors are added or changed. The EU Standard Contractual Clauses were updated in 2021 — DPAs using old SCCs should be updated to reflect the new versions.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
02Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

GDPR Article 46 lists multiple safeguards for international data transfers. Three dominate practice: Binding Corporate Rules (BCRs), Standard Contractual Clauses (SCCs), and the EU-U.S. Data Privacy…

April 30, 2026
03Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — so the software a DPO uses is now itself an accountability signal.

July 7, 2026
04Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
05Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
06Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

For a regulated-industry DPO, that distinction is the whole decision. Consent is one lawful basis under Art. 6(1)(a) GDPR; a compliance program is everything around it.

July 9, 2026
07Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026
08Data Privacy

Cookie Audit: How to Map Your Website's Cookies

A cookie audit is the foundational step for any website's GDPR and ePrivacy compliance. Without a complete, documented inventory of every cookie and tracking technology deployed on your site, your…

March 28, 2026