All articles
Privacy7 min read

Checking a DPA: the points where it goes wrong in practice

How to check a data processing agreement (DPA) efficiently for sub-service providers, rights to issue instructions and audit clauses, so you avoid high fines.

Martin Semmele

A decision-maker checks a data processing agreement for critical points at a desk.
A decision-maker checks a data processing agreement for critical points at a desk. · AI-generated

Key takeaways

  • A missing or deficient DPA can lead to fines, within a statutory range of up to 10 million euros.
  • When the provider brings in new sub-service providers, you need a real right of objection in the contract.
  • To meet the 72-hour notification deadline for personal data breaches, the DPA has to oblige the service provider to inform you quickly.
  • After the contract ends, it must be clearly set out how and when your data is deleted in full.

Why checking a DPA gets stuck in everyday work

When you book software for your business, external tools almost always process personal data of your customers. Under Art. 28 GDPR, a data processing agreement is a legal requirement. If that contract is missing or has gaps, fines under Art. 83(4) GDPR of up to 10 million euros or 2 per cent of worldwide annual turnover are possible1. A Hamburg case shows that small breaches are penalised too: a mail-order business received a fine of 5,000 euros plus 250 euros in fees because it had not concluded a data processing agreement with a service provider it had engaged2.

The paper chaos of everyday business.

The reality in small and medium-sized businesses usually looks different from the textbook. Standard contracts from software providers often run to dozens of pages of legal clauses. Without a legal department of your own, valuable time is lost in everyday work. Managing directors and team leads face the task of assessing risks without ploughing through legal texts for hours.

A structured review protects your business from nasty surprises. Instead of negotiating every sentence with a lawyer, you concentrate on the critical points where contracts fail in practice. This guide is not legal advice, it serves as operational orientation. Where a clause leaves you uncertain, you should refer it to a lawyer in case of doubt.

  • Sub-service providers: who processes your data in the background?
  • Right to issue instructions: do you keep full control over the software?
  • Audit rights: how demonstrable are the protective measures?
  • Notification deadlines: are you told in time when it matters?
  • Deletion: what happens to your data after cancellation?

The sub-processor list: who is actually reading along?

No modern cloud service runs its entire infrastructure on its own. SaaS providers use external data centres for hosting, third parties for sending email or specialised search engines for data analysis. In data protection law these service providers are called sub-processors.

Transparency beats blanket promises.

A workable contract names every sub-service provider it uses, with name, function and company location. The critical point lies in changes to that list. If the contract allows the provider to bring in new sub-service providers without your express consent, you lose control over the path the data takes.

You need a contractually assured notification before every change. The contract has to give you a reasonable window of at least 14 days to object to a new sub-service provider being brought in. If there is no right of objection, or if the information only appears on a hidden web page, the arrangement does not meet the requirements for secure data processing.

Arrangement in the DPAEffect in practiceAssessment
Blanket prior authorisationThe provider can bring in new service providers at any time.Critical
Notification by email with a 14-day periodYou are actively informed and can object if you have concerns.GDPR-compliant
Transparent list with location in the EUClarity about every processing location and service provider.Optimal

The right to issue instructions: limits of control in everyday SaaS

As the client you remain the legal owner of the processed data and the controller for it. The service provider may only process your data exactly as you specify. This right to issue instructions is the core of processing on behalf of a controller under Art. 28 GDPR.

How instructions work in practice.

With standardised software you rarely issue instructions by letter or email. Configuring the application, switching functions on or setting deletion periods in the user interface count as a technical instruction. The contract has to record that using the software counts as your instruction.

An often overlooked point is the provider's duty to warn. The contract has to oblige the service provider to inform you without undue delay if an instruction you have given infringes data protection law. Without that clause you carry the full risk of unlawful configurations on your own.

  • Clear determination: software settings count as a legally valid instruction.
  • Documented form: text form by email or ticket system is sufficient.
  • Active duty to warn: the provider informs you about unlawful instructions.
  • Limits on changes: the provider may not adjust instructions on its own authority.

Audit rights: between paper form and real audits

The GDPR obliges you to check regularly that the service provider keeps to the technical and organisational measures. An on-site audit in the provider's data centre is, however, practically impossible with cloud services. No data centre grants outside visitors free access to its server rooms.

Certificates as a pragmatic route.

The contract therefore has to set out clear substitutes for physical audits. Recognised audit reports to ISO 27001, SOC 2 or BSI C5 evidence the security of the infrastructure through independent third parties. What matters is that the provider makes this evidence available to you free of charge and without long delay.

A contract that ties audit rights to high fees or rules audits out altogether is not acceptable. You have to keep the right to request additional information where there are legitimate doubts or after security incidents.

In practice three routes are open to you. An on-site audit gives the most direct insight, but it requires travel, scheduling and specialist staff of your own, and large cloud providers usually do not grant it at all. Recognised certificates and audit reports to ISO 27001, SOC 2 or BSI C5 are produced by independent auditors and can usually be requested straight away, all that is left for you is to read them against your own requirements. Questionnaires sit in between: they answer your specific questions, but they require you to formulate the questions and assess the answers yourself, and the provider needs time to reply.

Notification deadlines: when every hour counts

If a security breach occurs at the service provider, the clock is running. Under Art. 33 GDPR you have to report a personal data breach to the competent supervisory authority within 72 hours of becoming aware of it3. That period runs without interruption, including at weekends and on public holidays3.

Without undue delay is not enough as a word.

The legislator requires the processor to inform the controller without undue delay about security incidents3. In the contract this vague word should be made precise with a concrete time. If the provider only informs you after two days, you are left with a few hours for your own analysis.

Agree a notification deadline of at most 24 to 48 hours from discovery of the incident in the contract. The provider then has to pass on all available information about the extent of the breach, the categories of data affected and the countermeasures taken.

  • Concrete time frame: notification to you within a maximum of 24 to 48 hours.
  • Complete details: type of incident, people affected and categories of data.
  • Contact person: naming a direct contact for emergencies.
  • Documentation duty: a written report on the causes and countermeasures.

Deletion after the contract ends: the clean cut

Once the cooperation has ended, your data may not remain on the service provider's servers. Art. 28(3), first sentence, point (g) GDPR requires all personal data to be either deleted in full or returned, at the client's choice.

Hidden hurdles when you cancel.

In practice, some providers try to charge for data exports or to impose long retention periods. A proper contract makes sure that exporting your data in a common format such as JSON or CSV is possible free of charge.

Look for written confirmation of deletion. Within a defined period, the service provider has to confirm in writing the final deletion of all copies, including those in backups. Statutory retention obligations of the provider are the only exception.

  • Right to choose: decide between full deletion and return of the data.
  • Common format: free export of all data structures.
  • Backup deletion: deletion in backups within a reasonable period.
  • Confirmation: written evidence of the deletion carried out.

An example from practice: support without DPA headaches

ComLayer shows that modern customer service software and reliable privacy go together. As a platform for AI-supported customer support, the tool processes customer requests on behalf of businesses. All content and conversations stay in European regions.

Automation without legal grey areas.

To meet all privacy requirements, ComLayer provides a reviewed data processing agreement. The service providers it uses are named openly. The AI does not use customer data for its own training. That is how GDPR-compliant AI can be used in support without creating legal uncertainty.

The flexible pricing model lets teams of every kind get started. The offer begins with the Free variant at 0 euros a month for testing. For productive AI support the Pro plan is available from 49 euros a month plus 12 euros per seat, while the Scale plan covers larger volumes at 199 euros a month.

  • Hosting in the EU: all content stays on European servers.
  • Transparent DPA: ready-made contract templates under Art. 28 GDPR available.
  • No model training: your knowledge base stays your protected property.
  • Open communication: all sub-service providers are listed transparently.

Frequently asked questions

When exactly do I need a DPA?

A DPA is always mandatory under Art. 28 GDPR when an external service provider, for example a cloud software provider, processes personal data for you on your instructions.

Who has to provide the DPA?

In practice the service provider usually supplies the draft contract. As the client, though, you remain legally responsible for the DPA meeting the strict requirements of the GDPR.

What happens if I do not conclude a DPA?

Missing DPAs are a hard compliance risk. In a Hamburg case the supervisory authority imposed a fine of 5,000 euros plus 250 euros in fees on a mail-order business. The statutory maximum is 10 million euros or 2 per cent of worldwide annual turnover.

Can I have audit rights replaced by certificates?

Yes. Since on-site checks are often impossible with large SaaS providers, audit rights may be covered by recognised certificates such as ISO 27001 or by reports from independent auditors.

How much time do I have to report a personal data breach at the service provider?

Where a personal data breach poses a risk to the people affected, you have to report it to the competent supervisory authority within 72 hours under Art. 33 GDPR.

Sources

  1. 01externer-datenschutzbeauftragter-dresden.de
  2. 02heise.de
  3. 03informationssicherheitsbeauftragter-dresden.de

Start for free · No credit card

Set up this evening. Answering by tomorrow morning.

Embed the widget, add your knowledge, done — ComLayer takes over, even when nobody is at the computer.