When it is needed
Whenever a supplier handles personal data on the company's behalf: cloud and SaaS providers, payroll and HR services, IT support with access to systems, marketing platforms, call centres or security providers. Without a DPA, using the supplier is itself a breach of the GDPR.
What it must include
Article 28 sets the minimum content: the subject, duration, nature and purpose of the processing, the types of data and categories of people concerned, and the processor's obligations. These include acting only on documented instructions, confidentiality of staff, appropriate security measures, using sub processors only with authorisation and under the same terms, helping the controller with data subject requests and breach notifications, deleting or returning data at the end, and allowing audits.
International transfers
If the processor or its sub processors handle data outside the European Economic Area, the DPA must also cover the transfer mechanism, usually the European Commission's standard contractual clauses or an adequacy decision.
DPAs and security
The DPA is also where security expectations become contractual: certifications such as ISO 27001, breach notification deadlines and audit rights. Reviewing these terms is part of third party risk management. In Spain, the AEPD publishes guidance on these contracts.




