The Data Processing Agreement: Who Processes Data for Whom — and When You Need One
Hardly any contract is demanded so often and understood so rarely. Yet the basic idea behind processing on behalf of a controller is simple — once the roles are sorted out properly.
A law firm runs its email through a provider, a cultural association uses a newsletter tool, a practice has its appointment system technically maintained. In all three cases, a service provider handles personal data that does not belong to it. This is exactly what processing on behalf of a controller is for — and the contract that goes with it, the data processing agreement (DPA).
The two roles: controller and processor
The GDPR sets out a clear division of labour. The controller is whoever decides on the purposes and means of the processing — your organisation. The processor is whoever processes data for you, bound by your instructions and without purposes of its own — the hosting company, the newsletter tool, the IT support. Art. 28 GDPR requires a contract with defined minimum content for this relationship — from subject matter and duration through confidentiality and protective measures to deletion once the contract ends.
When you need a DPA
Rule of thumb: whenever an external party can access your organisation's personal data as part of its service — even if that access is not intended. Typical cases: hosting, maintenance with server access, cloud storage, newsletter delivery. Services where the provider carries its own professional responsibility, such as tax advice or postal delivery, are not processing on behalf of a controller.
The often overlooked special case: no access, no DPA
If a piece of software runs entirely on a server belonging to your organisation and the vendor permanently has no access to the data, no processing on behalf of a controller takes place in that respect. A DPA only becomes necessary if the vendor does receive access after all — for instance for setup or maintenance. A note on my own products: they work exactly this way – as your own installation on your hosting, with no ongoing access on my side. For organisations handling specially protected data under Art. 9 GDPR, this is pleasantly tidy: the fewer external parties have access, the shorter the list of contracts.
In short
The DPA governs a real power relationship: your data in someone else's hands. Sort out the roles — who decides, who merely executes? — and it becomes clear who you need a contract with. The other basic obligations are covered in GDPR Basics for Organisations.
Frequently asked questions
Do I need a DPA with every service provider?
No — only with those that process personal data under your instructions or can access it.
What happens if the contract is missing?
The processing is formally not GDPR-compliant; supervisory authorities can impose fines on both sides. Reputable providers present the contract without being asked.
Is a template from the internet enough?
As a starting point, yes. What matters is that the contract matches the actual service: which data, which access, which sub-processors.
Last updated: August 2026 · This article provides general information and is not legal advice.
Ask a question — I always reply personally.
Sounds like your topic?
Let’s find out – with no obligation – where your biggest lever is.






