Dieter
← All articlesData protection explained

Data processing agreement (DPA): when you need one, what it must contain and when you don’t

A data processing agreement is mandatory as soon as a service provider processes personal data on your behalf: hosting, cloud, newsletters, CRM. With tax advisers, lawyers or banks, on the other hand, you don’t need one. This guide explains how to tell the difference, the mandatory contents under Art. 28 GDPR, how to deal with sub-processors and US providers, and how to check a provider’s DPA in ten minutes.

Sebastian SchenkLegally reviewed by Franziska Breidenbach
Last reviewed: Thursday, 17 September 2026
Data processing agreement (DPA): when you need one, what it must contain and when you don’t

Table of contents

  1. In brief
  2. What processing on behalf of a controller is
  3. When do you need a DPA?
  4. When don’t you need a DPA?
  5. The mandatory contents under Art. 28(3) GDPR
  6. Sub-processors: Art. 28(2) and (4) GDPR
  7. US providers and other third countries
  8. Form, templates and who provides the contract
  9. When must the DPA be concluded?
  10. What happens without a DPA?
  11. Checking a provider’s DPA in ten minutes
  12. Creating a DPA with Dieter
  13. Conclusion

In brief

  • Processing on behalf of a controller exists when a service provider processes personal data only on your instructions and pursues no purposes of its own. In that case a contract under Art. 28(3) GDPR is mandatory, before processing begins.
  • Typical processors: hosting providers, cloud storage, email providers, newsletter tools, CRM and SaaS providers, payroll bureaus, document shredding services, IT service providers with access to your systems.
  • No DPA needed with independent controllers: tax advisers, lawyers, auditors, banks, postal and parcel services, insurers. They decide on the means and purposes of processing themselves.
  • The DPA has eight mandatory contents. If one is missing, the contract is incomplete. With large providers the DPA is usually part of the terms of service, but you still have to check and document it.

What processing on behalf of a controller is

The GDPR knows two roles. The controller decides on the purposes and means of processing (Art. 4(7) GDPR). The processor processes personal data on behalf of the controller (Art. 4(8) GDPR), that is, bound by instructions and without any decision of its own about what happens to the data. A newsletter provider that stores your subscriber list and sends out mailings when you click is the classic example. It may not do anything with the addresses other than what you tell it to.

Because you are handing data out of your own control, Art. 28 GDPR requires three things of you: you may only use processors that provide sufficient guarantees for the security of the data (paragraph 1). You must conclude a contract with a defined minimum content (paragraph 3). And you remain responsible towards the data subjects and the supervisory authority, even if the mistake happens at the service provider. The DPA is therefore not a form for the filing cabinet but the document with which you organise this responsibility.

When do you need a DPA?

Whenever an external service provider processes or stores personal data on your behalf, or can even just access it on a regular basis. The amount of data does not matter. The most common cases in everyday business:

Service providerWhy it is commissioned processingTypical providers
Website hosting and serversStores log files, form data, customer accountsIONOS, Hetzner, Strato, All-Inkl, AWS, Vercel
Cloud storage and office suiteStores documents, emails, contactsMicrosoft 365, Google Workspace, Dropbox, Nextcloud hosting providers
Email marketingManages subscribers, measures opensMailchimp, Brevo, CleverReach, HubSpot
CRM, ticketing system, project softwareManages customer and contact dataHubSpot, Pipedrive, Zendesk, Asana, Notion
Payroll processing by a payroll bureauProcesses employee data according to your specificationsData centres, payroll service providers without tax advisory services
IT maintenance and remote maintenanceCan access personal data while workingIT system houses, managed service providers
Document shredding, archivingTakes in data carriers containing personal dataShredding services, scanning service providers
Web analytics, consent management, chat toolsProcess user data from the websiteGoogle Analytics, Matomo hosting, Usercentrics, chat providers
Call centres, customer service, applicant managementProcesses data of your customers or applicants following a scriptOutsourcing service providers, recruiting platforms

The same applies in the other direction: if you process data for other companies, for example as an agency, IT service provider or software vendor, you are the processor and must offer your customers a DPA. Agencies will find the right procedure on the page Data protection for agencies.

When don’t you need a DPA?

The most common misconception in practice is the DPA with the tax adviser. It is not necessary, and for a clear reason: tax advisers, lawyers and auditors process the data of your customers and employees on their own responsibility under their professional law. They are not bound by instructions and are therefore controllers themselves. For tax advisers this has even been written explicitly into the law since 2021 (§ 11(2) of the German Tax Advisory Act, StBerG). The German Data Protection Conference (DSK) has summarised the distinction in its short paper no. 13. You do not need a DPA with:

  • Professionals bound by professional secrecy: tax advisers, lawyers, notaries, auditors, doctors and company doctors.
  • Banks and payment service providers for transfers and card payments. They act under their own regulatory obligations.
  • Postal and parcel services for transporting consignments.
  • Insurers, debt collection agencies with their own decision-making latitude, detective agencies and other service providers that determine themselves how they carry out the task.
  • Tradespeople, cleaning companies, suppliers who do not handle personal data in terms of content. A cleaning service that walks through the office in the evening is not commissioned processing but a case for a confidentiality obligation and locked cabinets.

The mandatory contents under Art. 28(3) GDPR

Art. 28(3) GDPR prescribes the minimum content. First the framework: subject matter and duration of the processing, nature and purpose, type of personal data, categories of data subjects, and the obligations and rights of the controller. Then eight specific provisions that the contract must impose on the processor:

PointObligation of the processorWhat this means for you
(a)Processing only on documented instructions, including for transfers to third countriesThe provider may not use your data for its own purposes, for example to train AI models or for advertising. Check exactly this point in provider DPAs.
(b)Commitment of the persons involved to confidentialityThe service provider’s staff must be bound to confidentiality.
(c)All measures required under Art. 32 GDPRThe provider’s TOM belong in the contract as an annex. You must compare them with your own protection needs.
(d)Compliance with the conditions for sub-processors (paragraphs 2 and 4)You must know which further processors are used, and you must have a right to object.
(e)Assistance with data subject rightsIf a customer requests access, the provider must supply you with the necessary data, usually within a few days.
(f)Assistance with security, data breaches and DPIAs (Art. 32 to 36)Above all: notification of data breaches to you, so that you can meet your 72-hour deadline under Art. 33. Look for a specific deadline in the contract; 24 to 48 hours is customary.
(g)Deletion or return of all data at the end of the contractWhen the contract ends you get your data back or it is deleted, at your choice, with proof.
(h)Making evidence available and allowing auditsYou have a right to audit, in practice usually satisfied by certificates (ISO 27001, SOC 2) and the provider’s reports.

In addition, the processor must inform you if it considers an instruction to be unlawful (paragraph 3, third sentence). And paragraph 10 makes clear: if the processor itself determines the purposes and means, it becomes a controller, with all the obligations and full liability.

Sub-processors: Art. 28(2) and (4) GDPR

Almost every cloud provider uses service providers of its own: data centres, support companies, analytics tools. It may only engage these further processors with your prior written authorisation, either for each individual case or as a general authorisation with a duty to inform you of changes (paragraph 2). In practice, provider DPAs contain a general authorisation plus a list of sub-processors and a right to object within a set period. That is permissible as long as you are actually informed. So subscribe to the change notifications of your most important providers. The processor must impose the same obligations on its sub-processors and is liable to you for them (paragraph 4).

US providers and other third countries

If the provider or one of its sub-processors is located outside the EU and the EEA, you need, in addition to the DPA, a basis for the transfer under Chapter V of the GDPR. For the USA, since 10 July 2023 that has been the adequacy decision on the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795): if the provider is certified under it, the DPA is sufficient. You can check this in the public list of the US Department of Commerce. Without certification, or for other third countries, you need the standard contractual clauses of the EU Commission (Implementing Decision (EU) 2021/914), Module 2 for controller to processor, plus a documented assessment of whether the law of the destination country actually supports the clauses in practice. Both bases belong by name in your privacy policy.

Form, templates and who provides the contract

The DPA must be in writing, which includes an electronic format (Art. 28(9) GDPR). A DPA accepted by click in the provider’s customer account is valid. Keep a dated copy. With large providers the DPA is included in the terms of service (Microsoft “Data Protection Addendum”, Google Cloud “Data Processing Terms”, Mailchimp “Data Processing Addendum”). You do not have to negotiate anything, but you do have to check whether it covers the eight mandatory contents and assign it to your record of processing activities.

For service providers without a DPA of their own, such as your regional IT support company or a payroll bureau, you need a template. With Implementing Decision (EU) 2021/915, the EU Commission has published standard contractual clauses specifically for data processing agreements; they are legally sound but very formal. The responsibility for ensuring that a suitable DPA is in place lies in every case with the controller, meaning you. So do not wait for the service provider to send you a contract on its own initiative.

When must the DPA be concluded?

Before the first processing. The DPA is the prerequisite for you being allowed to pass on the data at all. If a service is already in use and the contract is missing, obtain it immediately and document the date. That does not cure the breach retroactively, but it ends it, and that is exactly what counts in a later inspection. At the end of the contract, point (g) applies: have the deletion or return confirmed and file the confirmation with your record of processing activities.

What happens without a DPA?

A missing or incomplete DPA is a breach of Art. 28 GDPR and falls within the fine bracket of up to 10 million euros or 2 percent of worldwide annual turnover (Art. 83(4)(a)). In every inspection, the first thing supervisory authorities ask for is the record of processing activities and the associated DPAs. A folder with gaps is a folder with fine potential. On top of that comes the practical risk: without a DPA, in the event of a data breach at the service provider you have no contractual notification deadline, no right to information and no provision on liability. You find out from the press and are liable anyway.

Checking a provider’s DPA in ten minutes

  1. 1Roles clear? The provider is named as processor, you as controller. If it says “independent controller”, you do not need a DPA but must check whether the disclosure is permissible at all.
  2. 2Subject matter, data, data subjects described? If there is only a placeholder, fill it in.
  3. 3Only on instructions? No right for the provider to use your data for its own purposes, product improvement or AI training, unless anonymised.
  4. 4TOM as an annex? At least a description following the usual control areas, better still a certificate.
  5. 5List of sub-processors and right to object? With a duty to inform you of changes.
  6. 6Notification deadline for data breaches? Specified in hours, not “without undue delay”.
  7. 7Deletion or return at the end of the contract? With a deadline and proof.
  8. 8Third country covered? Data Privacy Framework or standard contractual clauses named.
  9. 9Audit right or certificates? One of the two must be present.
  10. 10Date and version saved? Copy filed with the record of processing activities, change notifications subscribed to.

Creating a DPA with Dieter

For service providers without a contract of their own, and for your own customers when you are the processor yourself, Dieter generates the DPA from a short questionnaire: roles, subject matter, data categories, sub-processors, TOM as an annex. The contract is versioned and updated when the law changes. The overview of all processors sits right next to the record of processing activities. Details on the page Create a data processing agreement.

Conclusion

The DPA is the tool with which you organise a responsibility you cannot hand over. The work lies less in the contract text than in the overview: which service providers process data for you, which of them are processors, is there a complete contract in place for each one, and who checks the change notifications? If you can answer these four questions at any time, you have Art. 28 GDPR under control.

Author

Sebastian Schenk

Co-Founder & CEO

Lawyer and data protection officer. Drives product vision at simply Legal and ensures Dieter is sound legally and in practice.

Sources and further reading

Frequently asked questions

Do I need a DPA with my tax adviser?

No. Tax advisers process client data free from instructions under their professional law and are therefore controllers themselves. Since 2021 this has been stated explicitly in § 11(2) of the German Tax Advisory Act (StBerG). The same applies to lawyers and auditors. A DPA would even be wrong here, because it asserts a binding to instructions that does not exist.

Do I need a DPA for Microsoft 365 or Google Workspace?

Yes. Both store emails, documents and contacts on your behalf. The DPA is included in the terms of service (Microsoft: Data Protection Addendum, Google: Data Processing Terms) and takes effect when the contract is concluded. Check the data processing region and the list of sub-processors, and file a dated copy with your record of processing activities.

Does a DPA have to be signed?

No. Art. 28(9) GDPR requires written form but expressly allows an electronic format. Acceptance by click in the customer account or by email is sufficient, as long as you can prove when which contract text was agreed.

What is the difference between a DPA and a non-disclosure agreement (NDA)?

An NDA protects trade secrets between the contracting parties. The DPA governs the handling of third parties’ personal data, meaning that of your customers and employees, in line with the requirements of Art. 28 GDPR. An NDA does not replace a DPA, even if it contains data protection clauses.

Do I need a DPA with my external data protection officer?

Usually not. The data protection officer exercises a function that is independent by law and does not act on instructions. Confidentiality, data access and the return of documents at the end of the contract belong in the service contract. If you want to be on the safe side, add a confidentiality clause modelled on Art. 28.

Does the DPA obligation also apply to associations and sole traders?

Yes. Art. 28 GDPR is tied to the role of controller, not to size. An association that manages its members in the cloud and a sole trader with a newsletter tool need the DPA just as much as a large corporation.

What if the service provider refuses to sign a DPA?

Then you may not entrust it with any personal data. Art. 28(1) GDPR obliges you to work only with processors that provide sufficient guarantees. A provider that refuses the contract does not provide them. With small service providers, a clear template of your own often helps instead of the formal EU clauses.

This article reflects the position at the date of publication. We update our content when the law changes.

Related articles

Dieter helps you avoid fines

Ready to go

Dieter takes care of your data protection.

Get started without a demo call and set up your data protection in a few steps.

Get started