Legal Operations

Data Processing Agreement (DPA): Obligations, Content and Template

A data processing agreement (DPA) governs how a service provider processes personal data on your behalf under Article 28 GDPR. This guide explains when a DPA is mandatory, what it must contain, and how to handle templates, review and contract management.

AB
Published January 16, 2020·Updated June 27, 2026
11 min read
More on this topic

A data processing agreement (DPA) governs how a service provider processes personal data on your behalf under Article 28 GDPR. This guide explains when a DPA is mandatory, what it must contain, and how to handle templates, review and contract management.

As soon as an external service provider processes personal data on your behalf — whether cloud hosting, a newsletter tool or payroll — the GDPR requires a data processing agreement (DPA). It is not a formality but the legal basis that makes the processing lawful in the first place.

This guide explains who the obligation applies to, when it does not apply, what a DPA must contain under Article 28 GDPR, in which form it is concluded — and how to stay on top of it with a template, a review checklist and proper contract management.

What is a data processing agreement (DPA)?

A data processing agreement is a contract between a controller and a processor that governs how personal data is processed on the controller's behalf. Article 4 No. 8 GDPR defines the processor as a natural or legal person, authority, institution or other body that processes personal data on behalf of the controller.

The decisive feature is that the processor is bound by instructions: it pursues no purpose of its own with the data and acts solely on the controller's instructions. By this definition, data processing concerns a large number of companies — and also private individuals who process personal data on behalf of others. IT service providers in particular are affected, as data processing is part of the core business of electronic data processing.

Who is responsible for compliance?

ControllerDetermines the purpose and means of processing
ProcessorProcesses data solely on documented instructions

If the processor does not comply with its obligations under the GDPR, in the worst case it will itself be regarded as the controller under Article 28 (10). This also applies to concluding a valid data processing agreement, as the processing of personal data by the processor may only take place on documented instructions from the controller.

When is a DPA mandatory?

The GDPR is clear about the need for a data processing agreement: only those who conclude a DPA may process data for a controller. Conversely, anyone who has data processed also needs a DPA. The obligation to conclude one therefore applies to both parties — controller and processor.

The GDPR provides no exception for genuine data processing on behalf of a controller. If no DPA is in place where processing on behalf is taking place, the cooperation should not begin, because the processing would otherwise be unlawful.

When is a DPA not required?

Not every disclosure of personal data is processing on behalf of a controller. A DPA is unnecessary whenever the recipient processes the data not on instructions but in its own responsibility and for its own purposes. In these cases there is generally no processing under Article 28 GDPR:

  • Professionals bound by confidentiality such as lawyers, tax advisors or auditors: by the prevailing view they are controllers in their own right, as they provide their service independently and not on instructions.
  • Banks and payment service providers processing in fulfilment of their own legal obligations.
  • Postal and telecommunications services, insofar as they merely handle transport.
  • Transfer of function: if a provider takes over a task entirely in its own responsibility and decides on the purposes and means itself, it is not a processor.

In some of these constellations the classification is disputed in practice. When in doubt, examine the roles carefully — if the relationship does fall under Article 28, the DPA is mandatory.

Typical examples of processing on behalf

Most companies conclude more DPAs than they realise. Processing on behalf of a controller typically occurs with:

  • Cloud hosting and infrastructure (e.g. AWS, Microsoft Azure)
  • E-mail and newsletter tools and marketing automation
  • Web analytics and tracking services
  • Payroll and HR software
  • CRM and support systems holding customer data
  • Backup, archiving and external IT maintenance (such as remote support)

Rule of thumb: as soon as a provider gains access to the personal data of your customers, employees or prospects in the course of its service and processes that data only on your behalf, you need a DPA.

DPA, joint controllership and transfer of function

Correctly classifying the relationship determines which contract you actually need. Three constellations must be distinguished:

  • Processing on behalf (Article 28 GDPR): the provider processes solely on instructions and without any purpose of its own. A DPA is required.
  • Joint controllership (Article 26 GDPR): two or more parties jointly determine the purposes and means of processing. Here you conclude not a DPA but a joint controller agreement.
  • Transfer of function: the recipient independently determines the purposes and means and is therefore a controller in its own right. Instead of a DPA, a separate legal basis for the data transfer is needed.

This distinction is not academic: concluding a DPA where joint controllership actually applies documents the parties' obligations incorrectly — with the same liability risks as a missing contract.

What must a data processing agreement contain?

According to Article 28 (3), processing must be carried out by a processor on the basis of a contract with the controller. This agreement must contain detailed information on the following points:

  • Subject and duration of processing
  • Type and purpose of processing
  • Type of personal data
  • Categories of affected persons
  • Duties and rights of the controller

Components of a data processing agreement

  • Subject matter and duration of processing
  • Nature and purpose of processing
  • Rights and obligations of the controller
  • Obligations of the processor
  • Involvement of subcontractors
DPA

Article 28 (3) also provides that the DPA include the contractor's technical and organizational measures (TOM) for the security of processing referred to in Article 32 GDPR.

Should the processor use other subcontractors to fulfil its mandate, the technical and organizational measures of these subcontractors must be integrated into its own TOMs. In addition, DPAs must be concluded with the subcontractors.

For a clause-by-clause walkthrough of how to check an existing DPA for completeness and GDPR compliance, see our DPA review checklist.

Technical and organizational measures (TOM)

The technical and organizational measures under Article 32 GDPR are the heart of every DPA: they describe concretely how the processor ensures the security of processing. The benchmark is a level of protection appropriate to the risk. The TOMs typically cover:

  • Pseudonymisation and encryption of personal data
  • Ensuring the confidentiality, integrity, availability and resilience of systems
  • Access and entry controls and separation of processing
  • the ability to restore the availability of data quickly after an incident
  • a process for regularly testing and evaluating the effectiveness of the measures

The TOMs belong as an annex to the DPA and should be specific enough that compliance can be demonstrated in a dispute. Blanket wording does not satisfy the requirements of Article 32.

The form of contract conclusion

Article 28 (9) GDPR stipulates that the DPA must be drafted in writing, which can also be done in an electronic format. This is the classic written form — a printed version of the contract with the signatures of the contracting parties, obtained by post.

The electronic format mentioned, on the other hand, is not to be understood as the "electronic form" within the meaning of Section 126a of the German Civil Code (BGB), but rather as a DPA represented in a file format. This corresponds to the text form within the meaning of Section 126b BGB.

If the text form under Section 126b BGB is assumed, the agreement naming the person of the declarant must be provided on a durable medium. A durable medium is any medium that enables the recipient to retain or store a declaration and is suitable for reproducing the declaration unchanged.

It is therefore generally possible to send the DPA as a PDF file by e-mail, even without entering individual customer data. However, it is not enough for the DPA to be available only on the website, as this is not suitable for reproducing the declaration unchanged. It is important that the name of the declarant is evident from the document sent, so that the text form requirement is met.

The declaration that the customer agrees to the DPA can also be made electronically. There are essentially no special requirements here. Options include ticking a checkbox, a declaration of consent by e-mail or any other unequivocal means. It is only important that the consent is adequately documented.

DPA as an annex to terms and conditions

A DPA can be added as an appendix to the terms and conditions, but it remains a separate agreement that requires the customer's express consent. It is also reasonable to assume that, under Section 305c BGB (surprising and ambiguous clauses), clauses regulating the data processing relationship do not become part of the terms and conditions. Because of the formal requirement, it is therefore advisable to make the DPA available for download as a separate PDF document.

The declaration of consent can likewise be obtained electronically, as described above.

Consequences of a missing DPA

A missing DPA is a breach of Article 28 (3) GDPR — with consequences for both sides, but above all for the processor:

  • The processor carries controller-level liability: the DPA is the instrument that allocates responsibilities and liability between the parties and documents the processor's instruction-bound role. Without it, the processor can no longer rely on that privileged position and bears the liability risk that a DPA would otherwise distribute and direct toward the controller. If, lacking any basis of instruction, the processor even determines the purposes and means of processing itself, it is expressly deemed a controller under Article 28 (10) and is liable accordingly.
  • Fines: the breach of Article 28 can be penalised under Article 83 (4) with fines of up to 10 million euros or 2 percent of worldwide annual turnover, whichever is higher. The obligation binds both parties, so a supervisory authority can in principle pursue either side.
  • Damages and reputational risk: data subjects can claim damages under Article 82 GDPR; on top of that come warnings and a significant loss of trust.

The DPA is therefore not bureaucratic box-ticking but precisely the instrument that orders liability between controller and processor and shields the processor from full controller liability.

DPA template: free download

Drafting a DPA from scratch is demanding, especially for smaller companies and start-ups. A vetted template ensures that no mandatory component under Article 28 GDPR is missing, and it can be adapted to your specific processing.

Our free DPA template to download contains all the required clauses and serves as a starting point for your own data processing.

Reviewing and managing DPAs

As the number of service providers grows, so does the number of DPAs you have to conclude, review and keep track of over their lifetime. Losing the overview here risks gaps in documentation — and with them exactly the liability a DPA is meant to avert.

In a contract management platform such as top.legal, DPAs can be stored centrally, linked to the relevant TOMs, renewed on time and evidenced on demand. That keeps your data processing audit-ready at all times.

Frequently asked questions about data processing agreements

What is a DPA in simple terms?

A data processing agreement (DPA) is a contract under Article 28 GDPR by which a company allows a service provider to process personal data on its behalf and on its instructions. It sets out which data is processed for what purpose and how it is protected.

Who needs a data processing agreement?

Any company that has personal data processed by an external service provider — for example through cloud hosting, newsletter tools or payroll. The obligation applies to both the controller and the processor.

Is a DPA legally required?

Yes. Where processing on behalf of a controller takes place, concluding a DPA is mandatory under Article 28 (3) GDPR. Without it, the processing is unlawful.

Who must provide the DPA?

In practice the processor, i.e. the service provider, usually supplies a template. However, both parties remain responsible for concluding it effectively.

What happens without a DPA?

A missing DPA breaches Article 28 (3) GDPR. Above all, the processor then carries the liability risk like a controller, because the DPA would otherwise distribute that liability and document the instruction-bound role. On top of this come fines of up to 10 million euros or 2 percent of worldwide annual turnover and claims for damages from data subjects.

Does a DPA have to be signed?

A DPA must be drafted in writing under Article 28 (9) GDPR, which can also be done electronically (in text form). A handwritten signature is not strictly required — what matters is that the declarant is identifiable and the consent is documented.

Ready for the next step?

Book a demo with our team and see top.legal in action

More on the topic