Cybersicherheit24 September 2026·8 min read

Data processing agreement (DPA): when it is mandatory and what belongs in it

Newsletter tool, cloud storage, external payroll: almost every company needs DPAs under Art. 28 GDPR. The checklist for mandatory content and typical mistakes.

When a DPA is mandatory

As soon as a service provider processes personal data on your behalf and on your instructions, you have a processing relationship, and Art. 28 GDPR requires a data processing agreement (DPA, in Germany known as an AVV). This covers far more than classic IT providers: newsletter tools, cloud storage, hosting, external payroll, ticketing systems and many SaaS applications process customer or employee data on your behalf.

What does not need a DPA

No DPA is needed where the recipient processes the data under its own responsibility, for example tax advisers, lawyers or banks. Pure maintenance contracts without targeted data access are generally also out of scope. The dividing line is who determines the purposes and means of processing: you alone (processing on your behalf) or the service provider itself (independent controllership).

Mandatory content under Art. 28(3) GDPR

  • Subject matter, duration, nature and purpose of the processing, plus data categories and data subjects.
  • Instruction binding: the processor acts only on documented instructions.
  • Confidentiality obligations for the personnel involved.
  • Technical and organisational measures (TOMs) under Art. 32 GDPR.
  • Rules for sub-processors: approval and flow-down of obligations.
  • Duties to assist with data subject rights and data breaches.
  • Deletion or return of the data after the contract ends.
  • Evidence and control rights, including audits.

Typical mistakes in practice

The most common weak points: no DPA exists at all, the DPA was never signed or activated (many providers require a click in the customer account), the TOM annex is empty or outdated, and new sub-processors added by the provider are not tracked. For providers outside the EU, the question of third-country transfers comes on top, usually solved via EU Standard Contractual Clauses in addition to the DPA.

DPAs when things go wrong

A data breach is the moment your DPAs are put to the test: the processor must notify you of incidents without undue delay so that you can meet the 72-hour deadline towards the supervisory authority. The process is described in the 72-hour roadmap, and the GDPR Breach Navigator guides you through the notification step by step. So keep a register of all processors including contract status, and the obligation turns into a genuine emergency plan.

Matching tool

Ready to automate Cybersicherheit?

GDPR 72h Leak Shield → Try it now

Frequently asked questions

Do I need a DPA for every SaaS tool?

Almost always yes, as soon as the tool processes personal data such as customer or employee data on your behalf. Reputable providers offer a DPA as standard, often for online conclusion in the customer account. If a provider offers no DPA at all, treat that as a red flag.

What penalties apply without a DPA?

A missing data processing agreement is a standalone violation of Art. 28 GDPR and can be sanctioned with fines of up to 10 million euros or 2 percent of worldwide annual turnover. Supervisory authorities have already issued fines for this.

Is my tax adviser a processor?

No. Tax advisers, auditors and lawyers process data under their own professional obligations and under their own responsibility. You do not conclude a DPA with them. The situation differs for a pure payroll service provider without an advisory role, which is regularly a processor.

What applies to providers outside the EU?

In addition to the DPA, you need a legal basis for the third-country transfer under Chapter V GDPR, in practice usually the EU Standard Contractual Clauses plus an assessment of the level of protection. Many US providers are also certified under the EU-US Data Privacy Framework.

Related articles

Cybersicherheit

Data breach reported: The 72-hour roadmap

What really matters in the first hours after a GDPR data breach — step by step.

Cybersicherheit

The 7 most expensive compliance mistakes made by German SMEs

From the missing LUCID registration to the late data breach notification: these seven omissions regularly cost mid-sized companies five- to seven-figure sums.

Cybersicherheit

EU AI Act from August 2026: These obligations apply to high-risk AI

In August 2026, the bulk of the AI Regulation becomes applicable. Which systems count as high-risk and which obligations hit providers and deployers under Art. 9 et seq.

← All articles