Data Processing Agreement – we provide a template for the agreement and a security questionnaire.

16 January 2026

A data processing agreement is one of the most important documents required by the GDPR in relationships with external entities that have access to personal data. Its absence or incorrect content can lead to serious violations of regulations and substantial financial penalties, as confirmed by numerous decisions of the President of the Polish DPA. Although Article 28 of the GDPR specifies in detail the elements that a data processing agreement should contain, in practice, doubts still arise regarding when it should be concluded, how to distinguish between data processing and data sharing, and how to properly verify the data processor before transferring data to them.

In this article, we comprehensively explain what a data processing agreement is, when its conclusion is mandatory, what obligations rest on the data controller and the data processor, and what risks are associated with improper regulation of this cooperation.

We also discuss the principles of further data processing, the formal requirements regarding the agreement, and the current position of the supervisory authority. Additionally, we provide a practical template for the data processing agreement and a security questionnaire, which can assist in meeting the requirements of the GDPR and enhancing data processing security within the organization.

Downloadable Materials

TOOLS

Template of the data processing agreement
compliant with GDPR along with attachments

Download

TOOLS

Template of the security questionnaire for verifying the processor

Download

What is a data processing agreement?

Simply put, a data processing agreement (DPA) is an agreement made when the processing of personal data by the data controller is to be carried out on their behalf by another external entity.

Parties to the data processing agreement – who enters into it?

The parties to the data processing agreement are the data controller, who commissions the processing for their own purposes, and the data processor, who will process the personal data on behalf of the data controller.

When is it necessary to conclude a data processing agreement?

A data processing agreement is required when an external entity provides services to the data controller that necessitate the processing of personal data. This applies, for example, to accounting services – which are inextricably linked to the service provider's access to the personal data of the employees or contractors of the service recipient.

Examples of data processing agreements:

  • external accounting service for a company,
  • external payroll and HR services of the enterprise,
  • external archiving services,
  • external document destruction services,
  • IT services (e.g., hosting, maintenance) provided by an external entity,
  • external call center services,
  • security services, including monitoring, provided by an external entity,
  • external IT system (e.g., CRM) hosted on the provider's server, within which personal data of the administrator's employees or clients is processed.

When is it a data processing entrustment and when is it a data sharing?

It is important to note that not every service provider with whom the data controller collaborates, resulting in external access to personal data, acts solely on the instructions of the controller and for its purposes. Sometimes, the entity providing the service is not bound by the client's (controller's) instructions but by the regulations that apply to it. This applies, for example, to statutory auditors, lawyers, or legal advisors, who are considered separate data controllers rather than data processors – even though they act on behalf of the client.

There are no stupid GDPR questions - there are free answers!

Whether we are dealing with an entrustment or a sharing of data primarily depends on the degree of independence of the service provider in determining the purposes of processing. If the service provider is not bound by the client's instructions and can use the data for its own purposes, it is usually not a processor but a separate controller. This will be the case, for example, when the service provider must ensure its own compliance with the law, fulfill obligations arising from regulations (including those related to data retention), and apply legal requirements defining the scope of data and the principles of handling it within the provided service. On the other hand, if the service provider has no own purpose and processes data solely for the purpose of fulfilling the controller's task, acting according to its instructions, it is generally a processor.

Examples of separate data controllers:

  • statutory auditor,
  • law firm,
  • legal advisory office,
  • bank,
  • courier company or postal service.

How to verify a processor before entrusting data?

Verification of the data processor is an obligation of the data controller arising directly from Article 28 of the GDPR. It involves checking whether the potential processor (contractor) provides "sufficient guarantees" for the implementation of technical and organizational measures to ensure that the processing meets the requirements of the GDPR and protects the rights of the data subjects.

In other words, before we outsource the processing of personal data, we must ensure that the preliminarily selected processor will adequately protect that data. The verification typically includes a security questionnaire or an interview with questions regarding procedural safeguards (policies, DPO), organizational (incidents, authorizations, training), physical (data centers), and technical (encryption, backups, penetration testing) measures. The assessment of the processor should be conducted before entering into a data processing agreement and should be repeated periodically.

What must the data processing agreement contain?

If the verification of the processor is successful and the parties decide to enter into a data processing agreement, it should include the following elements in accordance with Article 28(3) of the GDPR:

  • subject matter of the processing – what the agreement pertains to, what processing has been entrusted to the processor,
  • duration of the processing – how long the data will be processed on behalf of the data controller,
  • nature of the processing – what activities the processor may perform, with what frequency (elements such as repeatability, long-term nature, volume, and applied technologies may also be indicated),
  • purpose of the processing – why and for what specific purpose the processor is to process personal data on behalf of the data controller,
  • type of personal data – what personal data will be subject to the entrustment,
  • categories of data subjects – whose data will be processed (e.g., clients, the data controller, employees of the data controller),
  • obligations and rights of the data controller – obligations include, for example, the manner and deadline for transferring data for processing and providing all information necessary for the processor to fulfill the agreement, while the rights of the data controller are usually closely related to the obligations of the processor (e.g., the obligation to provide assistance on the part of the processor means the right of the data controller to obtain that assistance),
  • obligations of the processor – discussed below.

What are the obligations of the processor?

Article 28(3) of the GDPR also specifies the obligations of the processor, which should be explicitly regulated in the data processing agreement. These include:

Practical DPO Course
Practical DPO Course
will confirm your high competencies
Prepare to fulfill the role of Data Protection Officer. We invite you!
CHOOSE A DATE

  • processing personal data solely on the documented instructions of the data controller – including in relation to the transfer of personal data to a third country or an international organization, unless such obligation is imposed on the processor by Union law or the law of the member state to which the processor is subject (in such a case, before commencing processing, the processor shall inform the data controller of this legal obligation, unless the law prohibits providing such information due to an important public interest),
  • ensuring that persons authorized to process data are committed to confidentiality or are subject to an appropriate statutory obligation of confidentiality,
  • taking the measures required under Article 32 of the GDPR – implementing appropriate technical and organizational measures to ensure the security of processing,
  • complying with the conditions for using the services of another data processor (sub-processor),
  • assisting the data controller in fulfilling the obligation to respond to requests from the data subject regarding the exercise of their rights,
  • assisting the data controller in fulfilling the obligations specified in Articles 32–36 of the GDPR – including the obligation to report breaches, notifying the data subjects of breaches of their personal data, or conducting Data Protection Impact Assessments,
  • deleting or returning personal data and deleting existing copies – unless Union law or the law of the member state requires the retention of personal data,
  • providing the data controller with information necessary to demonstrate compliance with the obligations specified in Article 28 of the GDPR and enabling the data controller or an auditor authorized by the data controller to conduct audits (including inspections) and contributing to them.

When and under what conditions can a processor use the services of another data processor (further processing)?

It may happen that a processor subcontracts the entrusted activities to another entity, thereby creating a sub-processing relationship for personal data. For this to be possible, prior written consent from the data controller is required. This consent may be specific (pertaining to a particular entity) or general (framework, with a notification mechanism for changes and the right to object).

Specific consent means that the controller pre-approves a particular sub-processor in a clear and unequivocal manner. In practice, this often also includes specifying a particular service or activity, location, or category of data. On the other hand, general consent means that the controller allows the processor to use sub-processors in advance (e.g., from a specified list or category). However, a condition is the obligation to inform the controller of any intended changes regarding the addition or replacement of sub-processors. This model is linked to the controller's right to object to such changes (i.e., to block a specific planned sub-processor) instead of having to express prior, individual consent for each specific entity each time.

Importantly, the same data protection obligations that arise from Article 28(3) of the GDPR and those stipulated in the agreement between the controller and the data processor must be imposed on the sub-processor. This particularly concerns the obligation to provide sufficient guarantees for the implementation of appropriate technical and organizational measures. Furthermore, if the sub-processor fails to fulfill its data protection obligations, the original data processor bears full responsibility towards the controller for the fulfillment of these obligations.

Must the data processing agreement be in writing?

According to Article 28(9) of the GDPR, the data processing agreement must be concluded in writing, including in electronic form. Such a form ensures accountability and facilitates oversight by the supervisory authority. It is worth adding that the GDPR does not require a qualified signature. However, for evidential purposes, solutions that allow for the clear identification of the parties and ensure the integrity of the content of the agreement are recommended.

GDPR. Support is useful!

Can standard contractual clauses replace the data processing agreement?

The data controller and the data processor may develop their own data processing agreement, containing all elements required by Article 28 of the GDPR, or rely on standard contractual clauses resulting from the implementing decision of the Commission (EU) 2021/915 of June 4, 2021. Such clauses may replace a developed data processing agreement, providing appropriate guarantees of compliance with the GDPR without the need to create a document from scratch.

What follows from the decisions of the Polish DPA regarding data processing agreements?

The data processing agreement is not merely a formality or an "additional piece of paper" in the documentation. This is evidenced by the binding decisions of the President of the Polish Data Protection Authority, including:

  • Decision DKN.5131.29.2022 of August 6, 2022 – imposing a monetary penalty for entrusting the processing of personal data without a written data processing agreement and without verifying whether the processor provides sufficient guarantees for the implementation of appropriate technical and organizational measures to ensure that the processing meets the requirements of the GDPR and protects the rights of data subjects,
  • Decision DKN.5130.2415.2020 of November 12, 2024 – imposing a monetary penalty for the failure of the data controller and processor to implement appropriate technical and organizational measures ensuring the security of personal data, including their confidentiality, and for the lack of verification of the processor (the decision clearly indicates that both the content of the agreement and the method of verifying the processor were analyzed in detail during the proceedings),
  • Decision DKN.5130.2024.2020 of February 11, 2021 – imposing a monetary penalty for entrusting the processing of personal data without a contractual obligation for the processor to process data solely on the documented instructions of the data controller, as well as for failing to specify in the agreement the categories of individuals whose data is being processed and the type of personal data (by indicating their categories),
  • Decision DKN.5131.50.2021 of February 8, 2023 – imposing a monetary penalty for the failure to implement appropriate technical and organizational measures ensuring the security of personal data, which resulted in a breach of their confidentiality and accountability, as well as for the lack of verification of the processor,
  • Decision DKN.5131.35.2021 of October 10, 2024 – imposing a monetary penalty for the lack of verification of the processor to determine whether it provides sufficient guarantees for the implementation of appropriate technical and organizational measures to ensure that the processing meets the requirements of the GDPR and protects the rights of data subjects, as well as for entrusting the processing of personal data based on an agreement that did not contain all elements required under Article 28(3) of the GDPR.

Downloadable Materials

Entering into a data processing agreement, its content, and the prior verification of the data processor are crucial for ensuring compliance with the GDPR. This impacts both the security of personal data and the security of the organization as the data controller. To facilitate the proper execution of the data processing agreement procedure, we provide two templates:

TOOLS

Template of the data processing agreement
compliant with GDPR along with attachments

Download

TOOLS

Template of the security questionnaire for verifying the processor

Download

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.