GDPR Data Processing Agreements: A Plain-English Guide
Everything you need to know about GDPR Data Processing Agreements (DPAs): what Article 28 requires, mandatory clauses, sub-processors, SCCs, and common mistakes.
Generate a data processing agreement in 60 seconds
Describe what you need in plain English. A panel of AI agents (Researcher, Drafter, Critic, Validator, Adversary) writes a review-ready draft you can edit, sign, and send.
What Is a GDPR Data Processing Agreement (DPA)?
A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor that governs how personal data is handled on the controller's behalf. Under GDPR Article 28, having one in place isn't optional — it's a fundamental compliance requirement the moment you hand personal data to a third party to process for you.
In plain terms: if you use any external tool or vendor that touches your users' personal data — a CRM, a payroll provider, a cloud hosting service, an email marketing platform — you need a DPA with them.
Controller vs. Processor: Getting the Roles Right
Before you can draft a DPA, you need to know who's who. GDPR draws a sharp line between the two roles.
- Data Controller: The party that determines why and how personal data is processed. If you collect customer data for your business and decide what to do with it, you're the controller.
- Data Processor: A third party that processes personal data on the controller's instructions. They act under authority delegated by the controller — not for their own purposes.
For most businesses, you're the controller and your vendors (cloud platforms, analytics tools, HR software) are processors. But the roles can flip: if you process data on behalf of your clients, you're a processor. The distinction matters enormously because it determines which obligations sit with whom.
Important edge case: If a processor starts using data for their own purposes — beyond what the controller instructed — they legally become a controller for those decisions. That's a major GDPR violation and changes the entire liability picture.
Sub-Processors
Processors often bring in their own vendors to help deliver their service. These are sub-processors, and they're subject to the same chain of obligation. A processor cannot engage a sub-processor without prior written authorisation from the original controller. If a sub-processor fails to meet their data protection obligations, the original processor remains fully liable to the controller for the breach.
What GDPR Article 28 Requires: The 8 Mandatory DPA Clauses
GDPR Article 28(3) is unusually prescriptive. It specifies eight topics that every DPA must address. Missing even one creates legal exposure. Here's what each clause needs to cover:
| # | Clause | What it means in practice |
|---|---|---|
| 1 | Processing on documented instructions only | The processor may only process data as the controller directs — in writing, including email. |
| 2 | Duty of confidentiality | All staff and contractors with access to personal data must be bound by confidentiality, either by contract or by statutory obligation. |
| 3 | Appropriate security measures | The processor must implement technical and organisational measures under GDPR Article 32 — encryption, access controls, resilience testing, breach recovery procedures. |
| 4 | Sub-processor rules | No new sub-processors without the controller's prior written authorisation; the same data protection obligations must flow down the chain. |
| 5 | Data subject rights assistance | The processor must help the controller respond to access, erasure, rectification, and objection requests from individuals. |
| 6 | Controller's compliance assistance | The processor must assist with GDPR obligations including security, breach notifications (Article 33), and Data Protection Impact Assessments (Article 35). |
| 7 | End-of-contract data deletion or return | When the services end, the processor must either delete or return all personal data — at the controller's choice — and delete existing copies. |
| 8 | Audit and inspection rights | The processor must provide all information necessary to demonstrate Article 28 compliance and submit to audits or inspections by or on behalf of the controller. |
These aren't suggestions — both the controller and the processor are responsible for ensuring the contract exists and covers all eight areas. Failure to enter into a written contract is itself an infringement of the GDPR, regardless of whether any actual data harm occurs.
What Else Should a DPA Include?
Beyond the mandatory eight, a thorough DPA should also define:
- Subject matter, duration, and purpose of the processing (what data, for how long, and why)
- Categories of personal data and types of data subjects involved
- Breach notification timelines (typically 24–48 hours notice to the controller, to allow the controller to meet the 72-hour regulatory deadline under GDPR Article 33)
- International transfer mechanisms if data flows outside the EU/EEA (more on this below)
- Audit specifics: frequency, format (paper-based, third-party audit reports), and cost allocation
International Data Transfers: SCCs and the Post-Schrems II Landscape
If your processor is based outside the EU/EEA, or if data is routed through servers outside the EEA, your DPA needs to address international transfers. The primary mechanism is Standard Contractual Clauses (SCCs).
The 2021 SCCs
The European Commission published new SCCs on 4 June 2021 (Commission Implementing Decision 2021/914). These replaced the pre-GDPR versions, which became entirely invalid after 27 December 2022 — any contract still relying on the old SCCs is non-compliant. The new SCCs use a modular structure with four modules depending on the direction and nature of the transfer:
- Module 1: Controller → Controller
- Module 2: Controller → Processor
- Module 3: Processor → Sub-Processor
- Module 4: Processor → Controller
Every transfer governed by SCCs must also be accompanied by a Transfer Impact Assessment (TIA) — a documented risk analysis of the legal environment in the destination country, including government access laws. This came out of the 2020 Schrems II ruling, which struck down the EU-US Privacy Shield and held that simply signing SCCs isn't enough if the destination country's laws undermine their protections.
UK Transfers (Post-Brexit)
After Brexit, the UK adopted its own data protection regime — UK GDPR — and no longer uses EU SCCs for transfers to third countries. UK businesses exporting personal data need to use either:
- The International Data Transfer Agreement (IDTA), or
- The EU SCCs plus the UK Addendum
Transfers between the EU and UK are currently covered by the UK's adequacy decision from the EU Commission — meaning no SCCs are needed for EU-to-UK transfers (pending any future review of that decision).
The Real Cost of Getting This Wrong
GDPR enforcement has intensified significantly. By early 2025, regulators across the EU had issued over 2,245 fines totalling approximately €5.65 billion since GDPR took effect. That's not just big tech: authorities in Spain, Italy, Germany, and Romania issue fines regularly across all industries.
Here's the two-tier fine structure under GDPR Article 83:
| Tier | Maximum Fine | Typical Violations |
|---|---|---|
| Tier 1 | €10 million or 2% of global annual revenue (whichever is higher) | Violations of Article 28 (DPA obligations), record-keeping, processor vetting |
| Tier 2 | €20 million or 4% of global annual revenue (whichever is higher) | Unlawful data transfers, breach of basic processing principles, consent violations |
Recent examples that touched on processor and transfer obligations:
- Uber (2024): Fined €290 million by the Dutch DPA for transferring EU driver data to the US without adequate safeguards after discontinuing their SCCs in 2021.
- LinkedIn (2024): Fined €310 million by the Irish DPC for unlawful behavioral analysis and targeted advertising.
- Clearview AI (2024): Fined €30.5 million by the Dutch DPA for building an illegal biometric database from scraped images, with the DPA also considering personal liability for management.
Beyond fines, regulators can ban processing entirely, order compliance audits, and issue public reprimands — any of which can be more damaging than the monetary penalty itself.
How to Draft a Compliant DPA: A Practical Checklist
Whether you're a controller vetting vendors or a processor setting up your own DPA template, here's a practical starting point:
For Controllers (You're Buying a Service)
- Identify every third-party vendor that touches personal data you control
- Confirm their sub-processor list and authorisation process
- Check whether their standard DPA covers all 8 Article 28(3) clauses
- Verify the applicable transfer mechanism if the vendor operates outside the EEA
- Set up a process to receive and review sub-processor change notifications
- Keep a record of all DPAs linked to your Records of Processing Activities (Article 30)
For Processors (You're Providing a Service)
- Create a DPA template that covers all mandatory Article 28(3) clauses
- Define your sub-processor list and your process for notifying controllers of changes
- Specify how you'll assist with data subject rights requests and breach notification
- Document your security measures in enough detail to satisfy controller due diligence
- Establish a clear data deletion or return procedure on termination
You can create a professional DPA with Pactlio — describe your arrangement in plain English and get a review-ready draft structured around the Article 28(3) requirements.
Jurisdiction Notes
EU / EEA
GDPR applies directly to any controller or processor established in the EU/EEA, and extraterritorially to any organisation targeting EU residents (Article 3). Every controller-processor relationship involving EU personal data needs an Article 28-compliant DPA.
UK
UK GDPR mirrors GDPR almost identically for DPA purposes. The ICO's guidance on controller-processor contracts follows the same eight-clause framework. Use IDTA or the UK Addendum for transfers to third countries.
US
There's no single US federal equivalent to GDPR, but US businesses handling EU residents' data must still comply with GDPR. State-level laws (California CPRA, Virginia CDPA, Colorado CPA) have their own processor contract requirements — CPRA, for example, requires a written contract with "service providers" covering similar ground to GDPR Article 28.
Switzerland
Switzerland's revised Federal Act on Data Protection (revFADP), which came into force September 2023, has similar DPA requirements to GDPR and recognises EU SCCs as a valid transfer mechanism with minor adaptations.
Common Mistakes to Avoid
- Using a pre-2021 SCC template. The old SCCs expired in December 2022. Any DPA still relying on them is non-compliant — review and update all vendor contracts.
- Skipping sub-processor oversight. Many controllers approve a processor without asking who their vendors are. Your liability doesn't stop at Tier 1 — it extends down the whole chain.
- Vague security language. Phrases like "reasonable security measures" aren't enough. Specify encryption standards, access control policies, incident response procedures, and penetration testing frequency.
- No breach notification timeline. GDPR gives controllers 72 hours to notify regulators. If your DPA doesn't require processors to alert you within 24–48 hours of discovering a breach, you'll likely miss that window.
- Forgetting end-of-contract provisions. Failing to specify data deletion or return — and getting written confirmation it happened — leaves personal data floating in vendor systems after the relationship ends.
- Assuming a vendor's DPA is automatically compliant. Even widely used boilerplate DPAs from large platforms should be reviewed. "Standard" doesn't mean complete.
This article is for informational purposes. Pactlio generates professional drafts for review — not legal advice.
Frequently Asked Questions
When is a DPA legally required under GDPR?▾
A DPA is required under GDPR Article 28 any time a data controller engages a third-party processor to handle personal data belonging to EU or EEA residents. This applies regardless of whether the processor itself is based in the EU — if you're touching EU personal data on someone else's behalf, a written DPA must exist before processing begins.
What's the difference between a data controller and a data processor?▾
A data controller decides the purpose and means of processing — what data is collected and why. A data processor handles the data on the controller's instructions, without deciding how it's used. For example, if you run an e-commerce site and use a third-party email platform to send order confirmations, you're the controller and the email platform is the processor.
Can a processor use sub-processors without permission?▾
No. Under GDPR Article 28, a processor cannot engage a sub-processor without prior written authorisation from the controller — either specific (approving each sub-processor individually) or general (allowing the processor to add sub-processors with advance notice and an objection window). If a processor goes rogue and adds sub-processors without authorisation, they can be treated as a controller for those decisions and face direct GDPR liability.
What are Standard Contractual Clauses (SCCs) and do I need them in my DPA?▾
SCCs are pre-approved contract clauses published by the European Commission that authorise personal data transfers outside the EU/EEA. You need them when your processor (or sub-processor) is based in a country without an EU adequacy decision. The 2021 SCCs (Commission Implementing Decision 2021/914) must be used for all new transfers — the pre-2021 versions became invalid in December 2022. For UK-to-third-country transfers, you use the UK IDTA or the UK Addendum to the EU SCCs instead.
What fines apply if I don't have a compliant DPA?▾
Failing to have a compliant DPA in place violates GDPR Article 28 and can trigger Tier 1 fines of up to €10 million or 2% of global annual revenue — whichever is higher. More serious underlying violations (such as unlawful data transfers) can escalate to Tier 2 fines of up to €20 million or 4% of revenue. Regulators can also issue reprimands, processing bans, and corrective orders alongside or instead of monetary fines.
Can I use a vendor's pre-built DPA, or do I need my own?▾
You can use a vendor's standard DPA as long as it genuinely covers all of GDPR Article 28's mandatory clauses. Major cloud and SaaS providers typically offer compliant DPA addendums, but you should review them carefully — a widely-used boilerplate isn't automatically compliant. If a vendor doesn't provide a DPA and you're the controller, the responsibility falls on you to issue one.