The contract almost every website needs
As soon as a provider touches personal data on someone's behalf – hosting, newsletters, backups – Article 28 GDPR requires a contract with prescribed content. It is no formality: without it, passing the data on is simply unlawful.
The data processing agreement – DPA for short – is the most frequently overlooked building block. It is needed as soon as a third party processes data on instruction, and that covers more services than most lists contain.
Is a DPA needed?
What has to be in it
Article 28(3) lists the minimum content. A contract missing one of these points does not meet the requirement – even at twenty pages long.
- Subject matter and duration of the processing, nature and purpose, type of data and categories of data subjects.
- Bound by instructions: processing only on documented instructions, transfers to third countries included.
- Confidentiality of the people involved, secured by contract or by law.
- Technical and organisational measures under Article 32 – named concretely, not as a statement of intent.
- Rules for sub-processors: authorisation, notice of changes, passing on the same obligations.
- Assistance with data subject rights, breaches and impact assessments.
- Deletion or return at the end of the service – at the controller's choice, not the provider's.
- Means of demonstrating compliance and audits, including tolerating inspections.
The contract alone is not enough
Article 28 requires more than a signature: only a provider offering sufficient guarantees may be chosen. That choice is a separate assessment made before the contract is signed and likewise belongs on record – certifications, location of processing, handling of government requests.
In practice a short note per provider is enough. What matters is that it exists: an inspection asks not only for the contract but also for the reasoning behind the choice.
A processing agreement signed after the first data has already flowed heals nothing – it only records when things improved.