When is a data processing agreement required?

Law and last update: 2026-10-10

Short answer

A data processing agreement is required whenever a controller has personal data processed on its behalf by a processor (Article 28(3) GDPR; the same rule applies under the UK GDPR). Typical processors are cloud and hosting providers, SaaS tools that hold your customer or employee data, payroll and accounting providers, and IT support with access to your systems. It is not required between independent controllers, and joint controllers need an Article 26 arrangement instead. The agreement must be in writing, which includes electronic form (Article 28(9)).

General information as of 2026-10-10, not legal advice.

Who is a processor

A processor processes personal data on behalf of the controller and on its documented instructions, rather than for its own purposes. If a service provider decides the purposes of processing itself (for example, a bank or an accountant acting under its own legal duties), it is usually a controller in its own right and Article 28 does not apply to that processing.

Common situations that need a DPA

  • hosting, cloud storage and email providers;
  • CRM, helpdesk, HR and marketing SaaS holding customer or employee data;
  • payroll, bookkeeping and outsourced customer service;
  • IT support or developers with access to systems containing personal data;
  • a processor engaging a sub-processor (Article 28(2) and (4)): the same obligations must flow down.

What the agreement must contain

Article 28(3) lists the content: the subject-matter, duration, nature and purpose of processing, the types of personal data and categories of data subjects, and the processor's obligations: documented instructions, confidentiality, security measures (Article 32), conditions for sub-processors, assistance with data subject rights and with Articles 32–36, deletion or return of data at the end, and information and audits to demonstrate compliance.

Check your DPA

KROTKA's GDPR Article 28 checklist shows, with verbatim quotes, which of the required provisions your data processing agreement contains and which are missing.

Check your data processing agreement against Article 28

Every required provision found with a quote, or marked missing.

Frequently asked questions

Do I need a DPA with every supplier?

Only with suppliers that process personal data on your behalf as processors. Independent controllers do not need an Article 28 agreement.

Can a DPA be part of the terms of service?

Yes. Article 28 requires a contract or other legal act in writing, including electronic form; it can be a separate document or part of the main terms.

Is a DPA required under the UK GDPR?

Yes. Article 28 of the UK GDPR contains the same requirement.

Legal sources

This guide is for information only and is not legal advice. KROTKA does not provide legal advice.

More short guides