
Data processing agreements with your providers
Data processing on behalf of a company happens when a provider handles personal data not for its own purposes but on the company's instructions, and almost every use of a cloud service, a newsletter tool, a CRM or a hosting provider falls under that definition, which is why a data processing agreement is needed almost every time.
With hosting, newsletter sending, a CRM and an agency that has access to customer data, an agreement is required with practically no exceptions, since all of them technically touch personal data even when they have no say in why the data was collected in the first place.
No agreement is needed where a provider decides the purposes and means of processing itself and acts as an independent or joint controller rather than following instructions. A tax adviser running the books under their own professional rules usually falls into that category rather than that of a processor.
The company, not the provider, is liable toward the website visitor, even when a data breach happens on the hosting or CRM side. The data processing agreement splits responsibility between company and provider between themselves, but it does not relieve the company of answering to the person whose data was processed.
Article 28(3) of the GDPR requires the agreement to fix the subject matter and duration of processing, its nature and purpose, the type of data and categories of data subjects, the provider's obligations toward the company's instructions, the conditions for bringing in sub-processors, what happens to the data on deletion or return after the contract ends, and the company's right to actually check how the provider processes the data.
If the provider transfers data outside the European Union, the agreement or an annex to it needs its own transfer safeguards, usually EU standard contractual clauses, not just a note that the service happens to sit in another country.
In an agreement already signed, three things are worth checking. Whether it names concrete categories of data and people rather than a vague phrase like customer personal data. Whether the company has an audit right rather than just the provider's own assurance. And whether it describes what happens to the data once the contract ends.
A missing or incomplete data processing agreement shows up as a significant factor in more than a third of German GDPR fines, and the maximum penalty under this article reaches up to 10 million euro or 2 percent of worldwide annual turnover, whichever is higher.
Good practice on the provider's side looks simple. The data processing agreement gets offered on its own, without the client having to ask for it, uses concrete wording instead of generic phrases, and needs no separate negotiation every time a client raises the question.
A data processing agreement is needed with every provider that stores or processes visitor data on a site's behalf, including hosting and newsletter tools. Illia BizTech works out with the client early on which of the site's providers fall under this requirement, rather than leaving the question of a processing agreement for the moment a regulator asks about it.
Illia BizTech builds and maintains websites for small and medium businesses in Russian, German and English, from the first version through ongoing maintenance and SEO work. A team carries the project from idea to launch without long internal approval chains, so the client speaks directly with the people writing the code and managing the content, not through a chain of account managers. That fits businesses moving to Germany or expanding into the German-speaking market who want to explain their task once, not repeat it on every call.

