What is a data processing agreement?
A data processing agreement is the contract that GDPR Article 28 requires when a supplier processes personal data on your behalf and on your instructions. It is not optional and not a formality: without the agreement, the processing itself is unlawful, no matter how good the security otherwise is. Datatilsynet, the Danish Data Protection Agency, has published a standard template that many Danish agreements are based on.
Data controller vs. data processor
The division of roles determines who must do what:
- The data controller decides the purposes and means: why and how personal data is processed. That is typically you as a company when it concerns your customers and employees.
- The data processor only processes the data on instruction from the controller, for example your hosting provider, payroll bureau or IT operations partner.
A supplier can easily be a controller for its own data (its own employees) and a processor for yours. And the chain continues downwards: if the processor itself uses subcontractors (sub-processors), they must be approved by you and be subject to the same obligations.
What must the agreement contain?
The GDPR sets concrete minimum requirements. A data processing agreement must, among other things, establish:
- The subject matter and duration of the processing: which data, which categories of individuals and for how long.
- The instructions: The processor may only process data as agreed, not for its own purposes.
- Confidentiality: Employees with access must be bound by a duty of confidentiality.
- Security measures: appropriate technical and organisational measures, such as encryption, access control and backup.
- Sub-processors: requirements for prior approval and for passing on the obligations.
- Assistance to the controller: with access requests, personal data breaches and impact assessments.
- Deletion or return of data when the agreement ends.
- Audit and inspection: your right to verify that the agreement is actually complied with.
Data processing agreements with Microsoft and your IT provider
In practice, most SMBs have two important agreements to keep track of. One is with Microsoft: if you use Microsoft 365 or Azure, the data processing agreement is part of Microsoft's standard terms (the Data Protection Addendum). It does not need to be negotiated, but you need to know it exists and be able to reference it in your records. The other is with your IT provider: an operations partner with access to your servers and user data is by definition a data processor. MI Support IT is itself a data processor for our customers, and the data processing agreement is a standard part of our IT outsourcing and managed services agreements. Feel free to ask for it, that is exactly the kind of check you as controller are expected to carry out.
How MI Support IT helps
We help make the technical side of the agreements match reality: which systems process personal data, which subcontractors are involved, and does the security live up to what the agreement promises. With IT advisory you get the overview. Contact us for a no-obligation chat.