Data processing agreement concluded by the parent company – is it effective towards subsidiaries?

23 September 2025

Is a data processing agreement signed solely by the parent company effective with respect to the subsidiaries? This question is increasingly arising in the practice of capital groups that centralize data management and IT security processes. In the era of GDPR and growing regulatory requirements, such a model allows for the standardization of practices, reduction of costs, and increased control over data processors. However, the lack of direct involvement of subsidiaries in the data processing agreement may pose serious legal and practical risks – both in the context of the interpretation of Article 28 of the GDPR and in the eyes of supervisory authorities.

The parent company, due to its stronger negotiating position resulting from a larger scale of operations and resources, can more effectively select suppliers offering advanced technologies, such as cloud solutions, information systems, or data encryption tools.

The practice of centralization is particularly common in regulated sectors, such as finance or healthcare, where capital groups must meet stringent legal requirements.

It happens that the parent company, by signing a main service agreement for the benefit of all companies in the group (services related simultaneously to the necessity of processing personal data by the service provider), also enters into a data processing agreement on its own behalf – as the data controller. However, the subsidiaries do not sign this agreement with the signatures of their representatives (they do not appear as parties to the agreement), but they are usually mentioned as entities to which the agreement also applies. This raises the question of whether such data processing agreements are actually effective with respect to the subsidiaries.

Comparison of Article 28(3) of the GDPR in Polish and English Versions

The phenomenon described above, of entering into a data processing agreement solely by the parent company, without authorization from the subsidiaries, yet with the expectation that this agreement will also be effective with respect to those companies, seems to be more common in international and foreign capital groups. Therefore, let us start by comparing the first sentence of Article 28(3) of the GDPR in its Polish version with its English-language version, as this may prove to be a source of potential interpretative differences.

Polish Language Version of Article 28(3) of the GDPR

„Processing by a data processor shall be governed by a contract or other legal instrument, which is subject to the law of the Union or the law of a Member State and binds the data processor and the controller, specifies the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data, and the categories of data subjects, as well as the obligations and rights of the controller.”

Key elements:

  • The contract (or other legal instrument) must bind the data processor and the controller.
  • This indicates the necessity of a direct legal relationship between the controller and the processor, suggesting that both entities are parties to this agreement.
  • The Polish text leaves little room for interpretation that the contract may be concluded by another entity (e.g., the parent company) on behalf of the data controller, without its direct involvement as a party.

English version of Article 28(3) GDPR

„Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller”.

Key elements:

  • The contract (or other legal act) must be binding on the processor with regard to the controller („binding on the processor with regard to the controller”).
  • The phrase „with regard to the controller” is less unequivocal than the Polish „wiążą podmiot przetwarzający i administratora”. It may suggest that the contract must specify the processor's obligations towards the controller, but does not necessarily require the controller to be a direct party to the contract.
  • It seems that the English version allows for some flexibility regarding who formally concludes the contract, as long as the processor is bound by obligations towards the specified controller.

The Polish text clearly suggests that the contract must be concluded between the controller and the processor. This is indicated by the use of the phrase „wiąże podmiot przetwarzający i administratora” – both parties must be bound, connected by one contract.

The English text uses the phrase „binding on the processor with regard to the controller”, which can be interpreted in such a way that the contract imposes obligations on the processor in relation to the controller, but does not necessarily require the controller to be a formal party to the contract. This would open the possibility for a contract to be concluded by another entity (e.g., the parent company) on behalf of another controller, provided that the processor is legally bound to that controller under the contract.

However, linguistic differences do not automatically imply differences in legal interpretation. The GDPR is a Union act, and therefore its interpretation should be consistent across all Member States.

DPO Function - it is well conveyed

Intent of the EU legislator and EDPB guidelines

According to the guidelines of the European Data Protection Board (EDPB), Article 28(3) of the GDPR aims to ensure that data processing by the processor is carried out in accordance with the instructions of the data controller and that there is a formal, written document regulating this relationship. The English version of the EDPB document “Guidelines 07/2020 on the concepts of controller and processor in the GDPR” emphasizes that the delegation is governed by a contract between the controller and the processor:

“Any processing of personal data by a processor must be governed by a contract or other legal act under EU or Member State law between the controller and the processor, as required by Article 28(3) GDPR.”

The Polish translation of these guidelines does not differ from the English version, as it states:

“Any processing of personal data by a processor must be governed by a contract or other legal act under EU or Member State law concluded between the controller and the processor, in accordance with the requirements of Article 28(3) GDPR.”  

The EDPB guidelines (in both Polish and English versions) also emphasize (following the text of the GDPR itself) that the data processing agreement must also specify the obligations of the controller, as directly stated in Article 28(3) sentence one of the GDPR. Therefore, signing the agreement directly by each data controller seems to be an indispensable element. Otherwise, it would be difficult to consider that such a controller's obligations towards the processor are binding if they are based solely on a declaration from the parent company – which is, after all, a separate entity.

Let us therefore take another look at both versions of the provision:

Polish version of Article 28(3) of the GDPR

“Processing by the processor takes place on the basis of a contract or other legal instrument, which are governed by EU law or the law of a Member State and bind the processor and the controller, specifying the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects, the obligations and rights of the controller.”

English version of Article 28(3) of the GDPR

“Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller”.

The above fragments therefore support the conclusion that both in the assessment of the GDPR (common to all countries applying the GDPR) and in light of the text of the regulation itself, regardless of its language version, a data processing agreement should be concluded between the data controller and the data processor. This means that the data controller also assumes certain obligations and should be a party to this agreement (and not merely a beneficiary, e.g., as a company belonging to a capital group indicated in the data processing agreement as entitled to use the services of the processor with whom the agreement was concluded by the parent company).

Risks Associated with Concluding Data Processing Agreements by the Parent Company

Narzędzia RODO
Using good GDPR tools is not work!
Applications, calculators, GDPR snapshots - everything that can help you manage your personal data protection system.
SEE MORE
Although the English version of Article 28(3) GDPR appears to be more flexible, as it leaves room for discussion about the permissibility of the structure of concluding data processing agreements by the parent company with effects for the subsidiaries, it is worth noting the following risks:

  • Lack of Direct Involvement of the Data Controller

If a subsidiary (data controller) is not a party to the agreement, it may face difficulties in directly enforcing its rights against the data processor, particularly in the case of legal disputes. Each company acting as a data controller should have control over the data processor, which usually requires its involvement in the agreement. Additionally, the effectiveness of imposing obligations on the data controller in an agreement to which it is not a party may be problematic. It is also important to remember the documented instructions of the data controller, which should serve as the basis for any actions taken by the data processor. In practice, such instructions are often considered to be the main agreement and the data processing agreement; however, in the discussed case, they will not originate from the data controller – they will not be signed by it.    

  • Diverse National Interpretations

In some member states (e.g., in Poland, where there is a strong emphasis on a direct contractual relationship), supervisory authorities may consider the absence of a specific data controller's signature on the agreement as a violation of Article 28 of the GDPR. This may even apply to situations where a specific entity has been explicitly identified in the agreement as entitled to use the services of the data processor and as one of the data controllers – which the data processor accepted by signing such an agreement.

Summary

A solution in which the parent company enters into a data processing agreement, while other companies are merely listed as data controllers, may be deemed non-compliant with the GDPR, as it does not ensure full accountability and control over the data processor (Article 5(2) in conjunction with Article 28 of the GDPR). The lack of formal involvement in the agreement of the subsidiaries mentioned in the agreement as additional data controllers may lead to difficulties in enforcing rights against the data processor.

If companies operating within a capital group wish to act under a single agreement on the same terms, the recommended action – regardless of the differences that may exist between the various language versions of the GDPR and the differences in the approach of supervisory authorities – will be to conclude a data processing agreement, under which all these companies (all data controllers) will be parties to such an agreement. They should enter into this agreement directly, and if they wish to do so through the parent company, it must act explicitly on their behalf based on the granted power of attorney. Only in such a configuration will each company, as a data controller, acting under and within a single agreement, unambiguously establish its own verifiable, transparent, and enforceable relationship with the data processor. This will guarantee its ability to exercise the rights and obligations arising from Article 28 of the GDPR.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.