← IP, GDPR & Cybersecurity

GDPR · Supplier agreements

Data processing agreement — DPA

A DPA regulates processing by a supplier on the controller’s behalf under Article 28 GDPR. Before drafting, it must be established whether the relationship is genuinely controller–processor; a contract’s title cannot change roles determined by who sets the purposes and essential means.

Article 28 GDPR subprocessors security measures
RelationshipController – processor
SchedulesProcessing, security and subprocessors
LimitA DPA does not legitimise an international transfer
01

Roles are classified according to reality

An accountant, cloud provider or agency may process data on the client’s behalf for certain services but act as an independent controller for its own obligations. Sometimes parties jointly determine purposes and become joint controllers, making Article 26 rather than a standard DPA the main reference.

Roles must be mapped for each activity. The same company may have different roles for hosting, aggregated analysis, fraud prevention and its own marketing.

02

Mandatory clauses and operational schedules

The agreement must describe the subject matter, duration, nature, purpose, data types, categories of individuals and controller rights, then include Article 28 obligations.

  • Instructions: documented and applicable to the actual service.
  • Confidentiality: authorised persons and access control.
  • Security: specific technical and organisational measures, subject to controlled updates.
  • Subprocessors: authorisation, list, change notification and equivalent obligations.
  • Assistance: requests, DPIA, prior consultation and incidents.
  • End of service: return or deletion, statutory exceptions and evidence.
  • Audit: information, reports, certifications and proportionate inspections.
03

Negotiating security and liability

The security schedule must match the product: authentication, encryption, backup, customer segregation, logs, vulnerabilities and continuity. Vague promises are difficult to audit, while rigid lists can become outdated.

Liability limitations in the main agreement must align with GDPR obligations. An inter-party clause does not remove individuals’ rights or the authority’s powers but may allocate costs and internal indemnification mechanisms.

04

Due diligence and supplier monitoring

The controller must use suppliers providing sufficient guarantees. Assessment may combine security responses, independent audits, certifications, incident history and architecture documentation.

Subprocessor lists, data locations and service functions change. The agreement must create a notification and objection mechanism, while the internal team must actually monitor risky changes.

05

How we work together

  1. 01
    Collecting information

    We establish the processes, systems, suppliers, data categories, roles and existing documents relevant to the DPA.

  2. 02
    Risk and legality analysis

    We check purposes, legal bases, proportionality, time limits, transfers, security and risks to data subjects.

  3. 03
    Documents and workflow

    We draft the legal documents and align them with internal responsibilities, technical steps, evidence and response deadlines.

  4. 04
    Controlled implementation

    We deliver the final version, practical instructions and clear priorities; compliance is reviewed periodically when processes or providers change.

QUESTIONS

Frequently asked questions

Does every supplier need a DPA?

No. A DPA is needed when the supplier processes data on the controller’s behalf. An independent controller has different contractual and information responsibilities.

Can I accept the cloud provider’s standard DPA?

It may be acceptable if it covers the actual service and risks. Schedules, subprocessors, transfers, security and amendment mechanisms must be checked.

Is a DPA enough for data sent to the US?

No. In addition to Article 28, the Chapter V GDPR mechanism must be checked: adequacy, SCCs or another applicable instrument, plus necessary measures.

Need a data processing agreement (DPA)?

Send your documents for a legal assessment and a solution tailored to your commercial objective.