Data Processing Agreement – when is it needed and what should it include?

By Mallbutiken · Facts verified September 30, 2026 · Approx. 6 minutes reading

A data processor agreement (DPA) is required when an external party processes personal data on your behalf in the role of a data processor. The agreement is also called a processor agreement or DPA. Start by assessing the actual roles of the parties. Just because you send data to a supplier does not automatically mean the supplier is a processor.

When is a data processor agreement needed?

The controller determines the purposes and means of the processing. The processor processes data on behalf of the controller. A typical example is a service that stores customer registers according to the customer company's instructions. An employee within your own organization, on the other hand, is not an external data processor.

Assess each processing activity individually. A supplier may be a processor for one function and an independent controller for another. The title of the agreement does not change the actual distribution of responsibilities.

Situation What do you need to assess?
A payroll system calculates salaries using your data. If the supplier processes the data on your behalf and according to your instructions, this points to a processor relationship.
A recipient uses data for their own purposes. Investigate independent controllership. A data processor agreement cannot replace that assessment.
Two organizations determine the purposes and means jointly. Joint controllership may be applicable. In that case, a different distribution of responsibility applies under Article 26.

Therefore, ask: why is the data being processed, who makes the critical decisions, and is the supplier allowed to use it outside the assignment? Document the answers before choosing an agreement.

What should the data processor agreement contain?

Article 28 of the GDPR requires binding regulation. The agreement must be in writing; electronic format is also acceptable. Describe the processing of the assignment: what it concerns, how long it lasts, its nature and purpose, what data and persons are affected, as well as the rights and obligations of the controller.

The core contractual terms should cover, among other things, the following:

  1. Instructions. What processing is permitted and how are changes documented?
  2. Confidentiality. How is the duty of confidentiality ensured for authorized personnel?
  3. Security. What measures are required under Article 32?
  4. Sub-processors. How is prior authorization granted and how are changes handled?
  5. Data subject rights. What support should the processor provide for, e.g., requests for access or erasure?
  6. Assistance according to Articles 32–36. How does the support function regarding security work, incidents, and impact assessments?
  7. Termination. How is personal data and copies returned or deleted, taking into account legal requirements for continued storage?
  8. Control. What information and opportunity for audit should the controller receive?

The agreement also needs to handle the processor's obligation to inform if an instruction, in their view, violates applicable data protection regulations. The complete legal requirement framework can be found in Article 28, linked under sources.

How to turn the appendices into an actual working tool

A well-written main text is not enough if the appendices only say "personal data according to the assignment." Instead, test whether a new person in charge at your company can understand the data flow without asking the person who made the procurement.

Processing instruction: describe a defined flow

Fictional example: A company lets a supplier send monthly customer mailings. The documentation describes customer names and email addresses, import from the customer register, mailings based on the company's instructions, and handling of unsubscriptions. In addition, the parties need to decide on storage, erasure, access, and if additional systems are included.

Compare that with the phrasing "marketing and IT." The latter says little about what the supplier is actually allowed to do. A useful row in the appendix contains system → data → permitted action → recipient → storage period.

Security appendix: write what should be verifiable

Describe practical measures and who is responsible for them. This can involve access control, multi-factor authentication, logging, backups, and restoration. These examples are not a universal minimum level; appropriateness depends on the risks of the processing.

"High security" is difficult to follow up on. "Permissions are reviewed upon role change and termination of employment" is a concrete procedure that can be audited. At the same time, check that the appendix corresponds to what the service actually delivers.

Sub-processors and countries of processing: distinguish between two issues

Identify which subcontractors process data and what data they receive. The agreement needs to handle specific or general written prior authorization according to Article 28. In case of general authorization, planned changes or additions must be notified so that the controller can object.

Also assess whether data is transferred to countries outside the EU/EEA. A data processor agreement alone does not resolve the requirements for such transfers. The rules in Chapter V of the GDPR need to be assessed separately, even when international support or access is included.

Incidents and termination need clear contact paths

According to Article 33(2), a processor must notify the controller without undue delay after becoming aware of a personal data breach. Do not confuse this with the controller's rule regarding notification to the supervisory authority within 72 hours, where that notification obligation applies.

Therefore, determine which contact receives alerts, how it is reached outside office hours, and how supplemental information is provided. Also write how you proceed when the service is terminated: export format, schedule, return, deletion, and handling of copies. Practical details need to align with the agreement's legal obligations.

Checklist before signing

  • Have you assessed the role for each relevant processing activity?
  • Are parties, service, and appendix versions clear?
  • Can the instructions be followed without verbal supplements?
  • Have the security measures been compared with the actual functions of the service?
  • Are sub-processors and relevant data flows known?
  • Have any third-country transfers been assessed separately?
  • Are there functional contact paths for incidents and data subject requests?
  • Can data be returned or deleted when the assignment ends?
  • Do you have a plan for following up on the supplier?
Common misconception: A non-disclosure agreement (NDA) does not replace a data processor agreement. Confidentiality is part of data protection, but Article 28 sets additional requirements. Nor does a processor agreement automatically create a legal basis for all processing.

When is a ready-made template useful?

A template is suitable when you have clarified the processor relationship and need to structure terms, instructions, and appendices. In complex responsibility structures or international data flows, an individual review may be necessary. If the supplier already has an agreement, you should check it against the assignment before adding a parallel document.

Mallbutiken's DPA with processing instruction and security appendices

Document the relationship and appendices

Mallbutiken's DPA package contains a main agreement, processing instruction, security appendix, sub-processor and third-country register, as well as documentation for supplier audits, incidents, and erasure in Word/PDF.

View the DPA template package

Common questions

Are DPA and processor agreement the same thing?

DPA is often used as an abbreviation for Data Processing Agreement and refers in this context to a data processor agreement. Always check the content and roles, not just the abbreviation.

Does every supplier need to sign our document?

The decisive factor is a binding regulation that meets the requirements for the specific relationship. It does not have to be your own document or a separate paper form.

Back to blog