GDPR · Supplier agreements
Data processing agreement — DPA
A DPA regulates processing by a supplier on the controller’s behalf under Article 28 GDPR. Before drafting, it must be established whether the relationship is genuinely controller–processor; a contract’s title cannot change roles determined by who sets the purposes and essential means.
Roles are classified according to reality
An accountant, cloud provider or agency may process data on the client’s behalf for certain services but act as an independent controller for its own obligations. Sometimes parties jointly determine purposes and become joint controllers, making Article 26 rather than a standard DPA the main reference.
Roles must be mapped for each activity. The same company may have different roles for hosting, aggregated analysis, fraud prevention and its own marketing.
Mandatory clauses and operational schedules
The agreement must describe the subject matter, duration, nature, purpose, data types, categories of individuals and controller rights, then include Article 28 obligations.
- Instructions: documented and applicable to the actual service.
- Confidentiality: authorised persons and access control.
- Security: specific technical and organisational measures, subject to controlled updates.
- Subprocessors: authorisation, list, change notification and equivalent obligations.
- Assistance: requests, DPIA, prior consultation and incidents.
- End of service: return or deletion, statutory exceptions and evidence.
- Audit: information, reports, certifications and proportionate inspections.
Negotiating security and liability
The security schedule must match the product: authentication, encryption, backup, customer segregation, logs, vulnerabilities and continuity. Vague promises are difficult to audit, while rigid lists can become outdated.
Liability limitations in the main agreement must align with GDPR obligations. An inter-party clause does not remove individuals’ rights or the authority’s powers but may allocate costs and internal indemnification mechanisms.
Due diligence and supplier monitoring
The controller must use suppliers providing sufficient guarantees. Assessment may combine security responses, independent audits, certifications, incident history and architecture documentation.
Subprocessor lists, data locations and service functions change. The agreement must create a notification and objection mechanism, while the internal team must actually monitor risky changes.
How we work together
- 01Collecting information
We establish the processes, systems, suppliers, data categories, roles and existing documents relevant to the DPA.
- 02Risk and legality analysis
We check purposes, legal bases, proportionality, time limits, transfers, security and risks to data subjects.
- 03Documents and workflow
We draft the legal documents and align them with internal responsibilities, technical steps, evidence and response deadlines.
- 04Controlled implementation
We deliver the final version, practical instructions and clear priorities; compliance is reviewed periodically when processes or providers change.
Frequently asked questions
Does every supplier need a DPA?+
No. A DPA is needed when the supplier processes data on the controller’s behalf. An independent controller has different contractual and information responsibilities.
Can I accept the cloud provider’s standard DPA?+
It may be acceptable if it covers the actual service and risks. Schedules, subprocessors, transfers, security and amendment mechanisms must be checked.
Is a DPA enough for data sent to the US?+
No. In addition to Article 28, the Chapter V GDPR mechanism must be checked: adequacy, SCCs or another applicable instrument, plus necessary measures.
Need a data processing agreement (DPA)?
Send your documents for a legal assessment and a solution tailored to your commercial objective.
Aveți nevoie de asistență juridică urgentă sau de consultanță de specialitate?
Notă juridică și limitarea răspunderii
Informațiile și articolele publicate pe acest site web sunt puse la dispoziție de Avocatul „Basuc Cosmin Ștefan” exclusiv în scop informativ și educativ general. Materialele prezentate reprezintă analize teoretice și opinii de specialitate la data redactării lor, fără a constitui consultanță juridică, asistență legală sau o opinie aplicabilă unui caz concret. Lectura sau utilizarea acestui conținut nu creează o relație profesională avocat-client între cititor și Cabinet. Având în vedere dinamica legislativă și specificul fiecărei situații de fapt, interpretările conținute nu pot substitui analiza individuală a unei cauze. Pentru stabilirea cadrului juridic aplicabil problemei dumneavoastră și obținerea unei consultații profesionale dedicate, vă invităm să contactați Cabinetul prin mijloacele oficiale de comunicare afișate.
Linkuri utile și legislație
