A data processing agreement is the written contract in which a controller sets out the terms on which a processor handles personal data on its behalf. The GDPR makes this contract compulsory as soon as you outsource processing, and prescribes the subjects it must cover.
Legal basis
The obligation is contained in Article 28(3) of the General Data Protection Regulation. The agreement must describe the subject matter, duration, nature and purpose of the processing, and identify the types of personal data and categories of data subjects. It must also contain eight specific undertakings: processing only on documented instructions, confidentiality, security under Article 32 GDPR, conditions for engaging sub-processors, assistance with data subject requests, assistance with breaches and impact assessments, return or deletion after termination, and making information available for audits. Article 28(1) adds that you may only use processors offering sufficient guarantees.
How it works in practice
Almost every outsourcing arrangement is caught: payroll, hosting, your CRM supplier, the company that shreds your archives. Most suppliers use their own template, attached as a schedule to the main contract. That template is negotiable, even when presented as fixed. Pay particular attention to the schedule describing the processing operations: it must reflect what actually happens, not a generic description that fits every customer. Transfers outside the European Economic Area need an additional basis, usually the European Commission’s standard contractual clauses.
Where it goes wrong
Three mistakes recur. The first is signing a processing agreement with a party that is not in fact a processor but determines purposes and means itself; that makes it a joint controller, with different rules. The second is blanket authorisation for sub-processors, which means you lose sight of where your data physically sits. The third is a security schedule that only refers to "appropriate measures" without naming a single concrete standard, which offers nothing to hold on to once an incident occurs.
Related terms
The processing agreement is closely linked to the personal data breach, since it should fix the deadline within which the processor must inform you, and to the data protection impact assessment, for which the processor must supply information. It also interacts with general terms and conditions, because it frequently conflicts with the liability cap in the main contract.
Would you like your processing agreements reviewed? Our IT lawyers assess them and negotiate where that is needed.

