As soon as a service provider processes personal data for you, Art. 28 GDPR demands a contract — the data processing agreement. Without it, the handover itself is the breach, however diligent the provider. The good news: with almost every provider the DPA is three clicks away. The bad news: in almost every company nobody knows where those clicks have been made and where not.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
A processor is anyone who processes personal data on your instructions: the cloud storage holding your customer files, the newsletter tool with your list, the payroll bureau, the hoster, the AI tool in its business tier. With each of them, Art. 28 demands a contract with fixed minimum content: subject and duration, type of data, instruction-boundness, confidentiality, sub-processors, erasure after the contract ends, support duties.
No DPA is needed with parties acting on their own responsibility: accountants and lawyers (their own professional accountability), banks, the postal service. Rule of thumb: whoever is merely an extension of your tooling needs the contract — whoever carries their own professional responsibility does not.
You almost never draft a DPA yourself. Microsoft, Google, Mailchimp, OpenAI and the rest keep ready-made agreements — as a “Data Processing Agreement/Addendum” in the customer account or automatically as part of the business terms. Your task is not negotiating but checking and documenting: does a DPA exist for every tool touching personal data — and can you show that on request?
Personal and free tiers of many services conclude no DPA — that belongs to the business tier. Which is exactly why the rule “work content only in approved tools” exists: the approved tool is the one with the contract. A customer list in a personal free newsletter account is not sloppiness — it is a transfer without a legal basis.
The DPA question is an inventory question. Per tool, three entries: personal data yes/no? DPA in place? third-country transfer? Where “personal data: no” stands, the DPA question is moot; where it says “yes” and DPA “open”, you have your to-do list. These three columns simultaneously feed the records of processing activities and answer customer questionnaires — one survey, several sets of evidence.
Two honest additions. First: the DPA does not cure a third-country transfer — if the provider sits in the US, you additionally need a transfer basis (Art. 44 ff.). Second: the DPA binds the provider but does not relieve you of the duty of selection — you remain the controller and choose processors offering “sufficient guarantees” (Art. 28(1)).
In the KlarComply subscription (from €49/month) your tool inventory carries exactly these three privacy entries per tool — visible in the audit file, printable for the auditor. The free 2-minute check shows where you stand.
With everyone processing personal data on your instructions: cloud storage, newsletter service, hoster, payroll bureau, AI tools in the business tier. Not with parties acting on their own professional responsibility, such as accountants, lawyers or banks.
Practically never. Established providers keep ready-made data processing agreements, usually available in the customer account or included in the business terms. Your task is to check and document that one exists for every tool touching personal data.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free