Data processing agreements: what has to be in one and how to get it signed
If a supplier touches your customers' personal data, Article 28 requires a contract with specific contents. Here is what it must contain, who needs one, and the three clauses worth reading before you sign.
You are the controller of your customers' data. Every tool you hand it to — the email platform, the analytics, the helpdesk, the hosting — is a processor acting on your instructions. Article 28 says that relationship must be governed by a contract, and it specifies what the contract has to say.
This is not optional paperwork and it is not something the supplier does you a favour by providing. Without it, the transfer of data to that supplier has no lawful footing.
What Article 28 requires it to contain
A DPA is not free-form. It must set out, at minimum:
- Subject matter, duration, nature and purpose of the processing.
- The type of personal data and the categories of data subject.
- That the processor acts only on documented instructions from you.
- That staff are under a duty of confidentiality.
- Security measures under Article 32.
- Terms for engaging sub-processors — authorisation, and notice of changes.
- Assistance with data subject requests and with breach notification.
- Deletion or return of the data at the end of the contract.
- That the processor makes available the information needed to demonstrate compliance, and allows audits.
If a supplier's document is missing several of these, it is a marketing page with the word agreement at the top.
Which of your suppliers need one
- Email and SMS platforms — obviously.
- Hosting and CDN, including your WordPress host.
- Analytics, including anything that sets an identifier.
- Helpdesk, reviews, live chat.
- Payment providers — usually controllers in their own right for fraud and compliance purposes, which changes the shape of the contract rather than removing the need for one.
- Freelancers and agencies with access to any of the above.
Keep a list. Not because a regulator will ask for it first, but because when somebody does ask, the shops that have it answer in an hour and the shops that do not spend a fortnight discovering tools they forgot about.
The three clauses worth actually reading
- Sub-processors. Look for the list, and for how you are notified of changes. "We may update this list from time to time" with no notice period means you cannot meet your own transparency obligations.
- International transfers. If data leaves the EEA, the contract needs a transfer mechanism — standard contractual clauses, an adequacy decision, or a certification framework. Check which, and check it is current rather than referencing something superseded.
- Deletion on termination. Look for a stated period and for what "deletion" means where backups are concerned. "Deleted within 90 days, backups expire within a further 30" is honest. Silence is not.
How to get it signed without a legal department
Most suppliers publish a standard DPA that you accept online or countersign. That is normal and fine. The practical process:
- Find the supplier's DPA — usually linked from their terms or a trust page.
- Read the three clauses above. Skim the rest against the Article 28 checklist.
- Accept or sign, and save a dated copy. A link is not a record; the page will change.
- Record it in your processing register alongside what data the tool gets and why.
Where a supplier has no DPA at all and will not produce one, that is your answer about the supplier.
The register is the part that pays off
Article 30 requires most organisations to keep records of processing activities. For a shop this is a spreadsheet, not a project: one row per tool, with what data it receives, why, where it is stored, which DPA governs it and when you last checked.
It takes an afternoon to build and it is the document that turns a data subject access request, a breach, or a supplier migration from a panic into a task.
Sources and further reading (4)
- GDPR Article 28 — Processor
- GDPR Article 30 — Records of processing activities
- EDPB — Guidelines 07/2020 on controller and processor concepts
- European Commission — Standard contractual clauses
Checked on 23 September 2026. Provider prices, mailbox rules and legal guidance change — verify anything you plan to act on.
A DPA you can actually put in the folder
Auralata publishes its data processing terms as part of its agreement, names its sub-processors, and deletes a store's data when you remove it — so the row in your register takes a minute to fill in.