Liaise Advocaten logo

Data processing agreement

As soon as you have another party process personal data for you, the GDPR calls for a data processing agreement. That sounds like something for large organisations, but it applies to virtually every business. If you use a cloud service, a mailing tool, a hosting provider or an accounting package, an external party is processing data on your behalf, and a processing agreement belongs with that.

Liaise draws up data processing agreements and reviews the copies suppliers put in front of you. That way you can be sure the arrangements are sound and that you meet what the law requires of you.

What is a data processing agreement?

A data processing agreement is a contract between you and the party that processes personal data for you. As a business you determine why and how customer or user data is processed; you are the controller. The party that processes that data on your instructions, your hosting provider or software supplier for instance, is the processor. The agreement records what that processor may do with the data, which security measures it takes and how it acts in the event of an incident. As soon as you have data processed by an external party, the GDPR requires an agreement of this kind.

When do you need a data processing agreement?

You need a data processing agreement as soon as an external party processes personal data for which you are responsible. In practice this covers more situations than businesses realise. Think of the party that hosts your website, the service you send your newsletter with, your cloud storage service, your CRM or accounting system, or a freelancer who processes data for you.

Not every external party is a processor. Where a party determines for itself what it does with the data, it is an independent controller and different arrangements apply. That distinction is far from always clear in practice. We help you determine which parties you need a processing agreement with.

What must a data processing agreement contain?

The GDPR prescribes a number of subjects that have to be regulated in every data processing agreement:

  • The subject matter, duration, nature and purpose of the processing, and which data and data subjects are involved.
  • The security measures the processor has to take.
  • The agreement that the processor processes the data only on your instructions and does not use it for its own purposes.
  • The conditions on which the processor may engage other parties.
  • The way in which the processor assists you with a personal data breach, with requests from data subjects and with audits.
  • What happens to the data when the collaboration ends: return or deletion.

An agreement missing one of these points does not meet the requirements. We make sure all the mandatory elements are in it and that they fit the way you work in practice.

 

Having your supplier’s version reviewed

Many suppliers put their own standard processing agreement in front of you. It is usually drafted from their interest, not yours. You often see broad powers to engage sub-processors, limited liability in the event of a personal data breach, or unclear arrangements about what happens to your data on termination. It pays to have such a version assessed before you sign, particularly where sensitive data or an important supplier is involved. We look at the agreement and set out what to watch for or what you would do better to have amended.

Would you like a data processing agreement drawn up, or a version put to you reviewed? Get in contact and you will have an answer within one working day.

Want a data processing agreement drawn up or reviewed?

  • Merel Teunissen
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Response within one working day

Your message goes to one of our lawyers.

  • Merel Teunissen
  • Jaap Versteeg
  • Charissa Koster
  • Roland Wigman
  • Alexandra Iedema
  • David Allick

How can we help?

How do we reach you?