Whenever a service provider processes personal data on your behalf, that processing must be governed by a data processing agreement, unless another legal act under Union or Member State law already governs it (Article 28(3) GDPR). It must be in writing, but electronic form is enough (Article 28(9) GDPR). The duty falls on both parties: the European Data Protection Board (EDPB) treats the absence of an agreement as an infringement of the GDPR, for which a fine may be imposed on both the controller and the processor. No Article 28 agreement is needed where the company receiving the data uses it for its own purposes and decides itself how to process it. It is then a separate controller. How to tell a controller, a processor and joint controllers apart is covered in Sharing data with a partner: controller, processor or joint controller.
Which provisions such agreements most often lack, and how to check the agreements you already have step by step, is covered on Privacio, a site built by Linden (in Lithuanian). Here we cover when the agreement is required, who signs it, how sub-processors are authorised and what happens when there is no agreement or it exists only on paper.
What the law requires
A processor is whoever processes personal data on behalf of the controller (Article 4(8) GDPR). A controller may use only a processor that provides sufficient guarantees that appropriate technical and organisational measures will be implemented (Article 28(1) GDPR). In its Guidelines 07/2020 on the concepts of controller and processor, the EDPB stresses that this duty is ongoing. It does not end on the day the agreement is signed.
The agreement must set out the subject matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects and the obligations and rights of the controller (Article 28(3) GDPR). Then come the processor’s duties: to process data only on documented instructions, to ensure confidentiality and security, to follow the rules on sub-processors, to help answer people’s requests, to help with the obligations under Articles 32 to 36 (security, breach notification, impact assessment), to return or delete the data when the services end, and to provide information and allow audits (Article 28(3)(a)–(h) GDPR). Why an ordinary services contract does not meet these points is explained in our article on the GDPR document package. What the security duty requires is covered in GDPR security measures: what Article 32 actually requires.
The EDPB adds two important points. First, the agreement should not merely restate the provisions of the GDPR. The security measures must be described in enough detail for the controller to assess whether they are appropriate. Second, the agreement may form part of a wider contract, but the EDPB recommends setting out the provisions implementing Article 28 in one place, for example in an annex.
Who signs, and whose template
The parties to the agreement are the controller and the processor – the organisations, not their staff. A client asked whose name to put in the agreement when the organisation’s data protection officer is external. The officer does not become a party. Their task is to inform and advise the controller or processor about its obligations (Article 39(1)(a) GDPR). It is signed by whoever may conclude transactions on the organisation’s behalf under the law, its founding documents or a power of attorney – usually the manager or a person they have authorised (Articles 2.81(1), 2.82(1) and 2.137(1) of the Civil Code).
The GDPR does not say who drafts the text. If the supplier does, that is not a problem in itself. But the EDPB is clear: the imbalance in bargaining power between a small company and a large supplier does not justify accepting terms that do not comply with the GDPR. The controller must assess the terms and, by accepting them, takes on responsibility. If the supplier changes its terms, merely publishing the changes on its website is not enough.
Accepting a supplier’s online terms is usually possible, because written form includes electronic form. Just keep a copy of the version of the terms and the date you accepted them. The controller must be able to demonstrate compliance (Article 5(2) GDPR), and the supplier may change what the link shows.
When a processor receives a draft agreement from its client, it is worth negotiating the limits of liability. In one project we proposed tying the processor’s liability to the client’s documented instructions, that is, to what the processor actually controls. But a liability cap agreed between the parties limits neither a fine that the supervisory authority sets under the Article 83 criteria (Article 83(2) GDPR) nor liability to people for the entire damage (Article 82(4) GDPR).
Sub-processors: the whole chain must be in writing
A processor may not engage another processor without the controller’s prior specific or general written authorisation (Article 28(2) GDPR). Under a general authorisation, it must give notice of intended changes and the chance to object. According to the EDPB, in that case the controller’s silence within the agreed period can be read as authorisation. That is why the period and the way notice is given should be written into the agreement.
A sub-processor must be bound by the same data protection obligations. If it fails to meet them, the initial processor remains fully liable to the controller (Article 28(4) GDPR). The EDPB puts it simply: the whole chain of processing must be governed by written agreements. This is why a client may ask you to confirm not only your agreement with them but every agreement in the chain. If a sub-processor accesses the data from a country outside the European Economic Area, the rules on data transfers also apply.
What happens when there is no agreement
It can come to light not at signing but later. One company, while preparing a data protection impact assessment, asked its supplier to send their data processing agreement. It turned out there were only general purchase terms, and nobody had signed specific terms. A gap like that has to be fixed in a hurry, while an assessment, an inspection or an incident is already under way. What a supplier must answer in a client’s GDPR questionnaire is covered in A client’s GDPR questionnaire to a supplier: what you must answer.
The first risk is a fine for both parties. The EDPB states that both the controller and the processor are responsible for putting the agreement in place, so both may be fined. Breaches of the controller’s and processor’s obligations under Articles 25 to 39 may be subject to an administrative fine of up to ten million euros or, in the case of an undertaking, up to 2 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(4)(a) GDPR). According to the EDPB, an agreement concluded before the GDPR applied and never brought into line with it also infringes Article 28(3).
The second risk is liability to people. A processor is liable for damage if it did not comply with the obligations placed on processors or acted outside or contrary to the controller’s lawful instructions (Article 82(2) GDPR). Where both are responsible, each is held liable for the entire damage (Article 82(4) GDPR). Without an agreement it is hard to prove which instructions were given and whether they were followed.
The third risk is that the supplier becomes a controller. If a processor infringes the GDPR by determining the purposes and means of processing itself, it is considered a controller in respect of that processing (Article 28(10) GDPR). It then carries all of a controller’s duties, starting with the legal basis and informing people.
When to call a lawyer
- when a supplier has access to employee, health, financial or video data;
- when you have received a draft agreement from a client or supplier and need to decide what to negotiate;
- when it is unclear whether a partner is a processor or a separate controller;
- when the chain includes sub-processors outside the European Economic Area;
- when a missing or defective agreement came to light during an inspection, an incident or an impact assessment.
Frequently asked questions
Is it enough to accept a supplier’s online terms?
Usually yes, if the data processing terms form part of them and meet Article 28(3) GDPR. Written form includes electronic form (Article 28(9) GDPR). Keep a copy of that version and proof of when you accepted it, because the supplier may later change what the link shows.
Does the data processing agreement have to be a separate document?
No. It can be part of the main services contract. The EDPB recommends setting out the provisions implementing Article 28 in one place, for example in an annex, so that they are easy to show during an inspection.
Is an agreement signed before 2018 still fine?
Only if it contains every element required by Article 28(3) GDPR. The EDPB states that agreements concluded before the GDPR applied should have been updated, and one not brought into line with the GDPR infringes Article 28(3).
What if a supplier engaged a sub-processor without authorisation?
Ask for information on who that entity is, where it operates and on what terms it processes the data. Such a step infringes Article 28(2) GDPR. Depending on the risk, it may be enough to formalise the authorisation and the chain agreement, or you may need to demand that the processing stops.
How to start
List the suppliers that see your employees’ or customers’ data and send us the agreements or terms you have with them. We will tell you where an agreement is missing, where it exists only on paper and what to negotiate first.
A practical step-by-step guide is on Privacio, a site built by Linden: Sutartys su paslaugų tiekėjais: ko trūksta dažniausiai (in Lithuanian). You can also check whether your organisation needs a record of processing activities with the Privacio tool (in Lithuanian).
Email: info@linden.lt
More about this service: GDPR audit, compliance documents and consultations.