Law and duties 3 minutes read

The contract almost every website needs

As soon as a provider touches personal data on someone's behalf – hosting, newsletters, backups – Article 28 GDPR requires a contract with prescribed content. It is no formality: without it, passing the data on is simply unlawful.

The data processing agreement – DPA for short – is the most frequently overlooked building block. It is needed as soon as a third party processes data on instruction, and that covers more services than most lists contain.

Is a DPA needed?

Can the provider come into contact with personal data, and does it do so on instruction rather than for its own purposes?
Yes – processing on behalfArticle 28 contract needed, before the first data flows. The provider needs no legal basis of its own.
No – own purposesThen this is a transfer to another controller. That needs a legal basis of its own and a mention in the privacy notice.
The most common borderline case is remote maintenance: even someone who could only theoretically access data is a processor. The possibility suffices; actually looking at the data is not required.

What has to be in it

Article 28(3) lists the minimum content. A contract missing one of these points does not meet the requirement – even at twenty pages long.

  1. Subject matter and duration of the processing, nature and purpose, type of data and categories of data subjects.
  2. Bound by instructions: processing only on documented instructions, transfers to third countries included.
  3. Confidentiality of the people involved, secured by contract or by law.
  4. Technical and organisational measures under Article 32 – named concretely, not as a statement of intent.
  5. Rules for sub-processors: authorisation, notice of changes, passing on the same obligations.
  6. Assistance with data subject rights, breaches and impact assessments.
  7. Deletion or return at the end of the service – at the controller's choice, not the provider's.
  8. Means of demonstrating compliance and audits, including tolerating inspections.

The contract alone is not enough

Article 28 requires more than a signature: only a provider offering sufficient guarantees may be chosen. That choice is a separate assessment made before the contract is signed and likewise belongs on record – certifications, location of processing, handling of government requests.

In practice a short note per provider is enough. What matters is that it exists: an inspection asks not only for the contract but also for the reasoning behind the choice.

A processing agreement signed after the first data has already flowed heals nothing – it only records when things improved.

Published 11 August 2026 · last changed 2 September 2026

This article explains general principles and does not replace legal advice on an individual case.

Back to the overview