KlarComply
HomeKnowledge › DPA (Art. 28)

The DPA: which providers need one, which do not — and how to keep track

As soon as a service provider processes personal data for you, Art. 28 GDPR demands a contract — the data processing agreement. Without it, the handover itself is the breach, however diligent the provider. The good news: with almost every provider the DPA is three clicks away. The bad news: in almost every company nobody knows where those clicks have been made and where not.

By , Founder of KlarComply · Reviewed on

Infographic: The DPA: who needs one — and who does not — Without the contract, the handover itself is the breach — here is how to keep track.
The key points of this article as a graphic — feel free to share or download it.

The basic rule: processing on instructions needs a contract

A processor is anyone who processes personal data on your instructions: the cloud storage holding your customer files, the newsletter tool with your list, the payroll bureau, the hoster, the AI tool in its business tier. With each of them, Art. 28 demands a contract with fixed minimum content: subject and duration, type of data, instruction-boundness, confidentiality, sub-processors, erasure after the contract ends, support duties.

No DPA is needed with parties acting on their own responsibility: accountants and lawyers (their own professional accountability), banks, the postal service. Rule of thumb: whoever is merely an extension of your tooling needs the contract — whoever carries their own professional responsibility does not.

The practical route: with standard services the DPA is ready-made

You almost never draft a DPA yourself. Microsoft, Google, Mailchimp, OpenAI and the rest keep ready-made agreements — as a “Data Processing Agreement/Addendum” in the customer account or automatically as part of the business terms. Your task is not negotiating but checking and documenting: does a DPA exist for every tool touching personal data — and can you show that on request?

The typical gap: the free account

Personal and free tiers of many services conclude no DPA — that belongs to the business tier. Which is exactly why the rule “work content only in approved tools” exists: the approved tool is the one with the contract. A customer list in a personal free newsletter account is not sloppiness — it is a transfer without a legal basis.

Keeping track: one list, three columns

The DPA question is an inventory question. Per tool, three entries: personal data yes/no? DPA in place? third-country transfer? Where “personal data: no” stands, the DPA question is moot; where it says “yes” and DPA “open”, you have your to-do list. These three columns simultaneously feed the records of processing activities and answer customer questionnaires — one survey, several sets of evidence.

What sits behind the DPA

Two honest additions. First: the DPA does not cure a third-country transfer — if the provider sits in the US, you additionally need a transfer basis (Art. 44 ff.). Second: the DPA binds the provider but does not relieve you of the duty of selection — you remain the controller and choose processors offering “sufficient guarantees” (Art. 28(1)).

Where to start

In the KlarComply subscription (from €49/month) your tool inventory carries exactly these three privacy entries per tool — visible in the audit file, printable for the auditor. The free 2-minute check shows where you stand.

Frequently asked questions

Which providers do I need a DPA with?

With everyone processing personal data on your instructions: cloud storage, newsletter service, hoster, payroll bureau, AI tools in the business tier. Not with parties acting on their own professional responsibility, such as accountants, lawyers or banks.

Do I have to draft the DPA myself?

Practically never. Established providers keep ready-made data processing agreements, usually available in the customer account or included in the business terms. Your task is to check and document that one exists for every tool touching personal data.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → Data breach & 72 hours → GDPR staff training → US tools & transfers →
Sources:
Article 28 GDPR — processor
Article 44 GDPR — general principle for transfers
Reviewed on 1 September 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.