Data protection agreement: the seven terms it has to contain, and the two that get negotiated

A data protection agreement is one of the few contracts whose contents are largely prescribed, which makes reviewing one much faster than it looks. Article 28 of the GDPR lists what has to be in it. Seven terms are effectively fixed and two are where the actual negotiation happens.

The fixed seven

Subject matter and duration of the processing; its nature and purpose; the types of personal data and categories of person; the obligation to act only on documented instructions; confidentiality commitments from the people who handle it; appropriate security measures; and the conditions on engaging another processor. If a draft is missing one of these, it is not a data protection agreement yet.

Negotiated one: sub-processor change

General authorisation with notice, or specific authorisation each time. Vendors want general with a short notice period; buyers want a right to object that means something. The number worth reading is the notice period, because a right to object inside a period too short to migrate is a right in name only.

Negotiated two: audit

Everybody asks for an audit right and almost nobody exercises it. What matters more is what the vendor will give without one: a current certification, a penetration test summary, an incident notification commitment with a time on it. Trade the audit right for those and you get more.

Assistance and deletion

The agreement should say how the vendor helps you answer a request, and what happens to the data at the end. Return or delete at your choice is the norm; watch for language that lets the vendor keep a copy indefinitely for its own analytics.

The practical review

Read the seven prescribed terms, then the sub-processor notice period, then the end-of-contract clause. That is ten minutes of work and it catches almost everything that matters for a small buyer, which is a far better use of the time than a full mark-up nobody has the leverage to enforce.

Questions people ask about data protection agreement

Do we need one with every vendor?

With every processor, which is every vendor that handles personal data on your instructions. The count is larger than most lists; the builder on this site sizes it including sub-processors.

Is the vendor's standard DPA acceptable?

Usually, for a small buyer. The leverage to change it rarely exists and the standard version is generally Article 28 compliant. Read it anyway: the sub-processor notice period and the end-of-contract clause are the two lines worth knowing.

What if the vendor has no DPA at all?

That is the finding. A vendor processing personal data with no agreement is the gap in your chain, and it is usually a small tool somebody signed up for on a card.

Sources

Related answers

Keep the request record: $10 a monthStart the request record