Skip to main content

Compliance

What is a data processing agreement?

A data processing agreement is the GDPR contract between controller and processor. See what the agreement must contain, and who needs one.

In short

A data processing agreement is a contract that the GDPR requires whenever one company (the data processor) processes personal data on behalf of another (the data controller).

If you use an external IT provider, a payroll bureau, a hosted CRM or Microsoft 365, these suppliers process personal data for you, and a data processing agreement must be in place before the arrangement is lawful. The agreement establishes what the processor may do with the data, which security measures must be in place, whether sub-processors may be used, and what happens to the data when the agreement ends.

Missing data processing agreements are one of the most frequent causes of criticism and fines from Datatilsynet, the Danish Data Protection Agency, precisely because the requirement is so concrete and easy to check. The responsibility for the agreement existing lies with the data controller, in other words with you.

MI Support IT is itself a data processor for its customers and includes the data processing agreement as a standard part of its managed services agreement.

Back to the glossary

What is a data processing agreement?

A data processing agreement is the contract that GDPR Article 28 requires when a supplier processes personal data on your behalf and on your instructions. It is not optional and not a formality: without the agreement, the processing itself is unlawful, no matter how good the security otherwise is. Datatilsynet, the Danish Data Protection Agency, has published a standard template that many Danish agreements are based on.

Data controller vs. data processor

The division of roles determines who must do what:

  • The data controller decides the purposes and means: why and how personal data is processed. That is typically you as a company when it concerns your customers and employees.
  • The data processor only processes the data on instruction from the controller, for example your hosting provider, payroll bureau or IT operations partner.

A supplier can easily be a controller for its own data (its own employees) and a processor for yours. And the chain continues downwards: if the processor itself uses subcontractors (sub-processors), they must be approved by you and be subject to the same obligations.

What must the agreement contain?

The GDPR sets concrete minimum requirements. A data processing agreement must, among other things, establish:

  • The subject matter and duration of the processing: which data, which categories of individuals and for how long.
  • The instructions: The processor may only process data as agreed, not for its own purposes.
  • Confidentiality: Employees with access must be bound by a duty of confidentiality.
  • Security measures: appropriate technical and organisational measures, such as encryption, access control and backup.
  • Sub-processors: requirements for prior approval and for passing on the obligations.
  • Assistance to the controller: with access requests, personal data breaches and impact assessments.
  • Deletion or return of data when the agreement ends.
  • Audit and inspection: your right to verify that the agreement is actually complied with.

Data processing agreements with Microsoft and your IT provider

In practice, most SMBs have two important agreements to keep track of. One is with Microsoft: if you use Microsoft 365 or Azure, the data processing agreement is part of Microsoft's standard terms (the Data Protection Addendum). It does not need to be negotiated, but you need to know it exists and be able to reference it in your records. The other is with your IT provider: an operations partner with access to your servers and user data is by definition a data processor. MI Support IT is itself a data processor for our customers, and the data processing agreement is a standard part of our IT outsourcing and managed services agreements. Feel free to ask for it, that is exactly the kind of check you as controller are expected to carry out.

How MI Support IT helps

We help make the technical side of the agreements match reality: which systems process personal data, which subcontractors are involved, and does the security live up to what the agreement promises. With IT advisory you get the overview. Contact us for a no-obligation chat.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.