Processor agreement
A processor agreement governs the processing of personal data by a processor on behalf of a controller. Article 28 GDPR sets out the agreement’s essential content.
A processor agreement is the arrangement between a controller and a processor for the processing of personal data. The document’s title is not decisive. The relevant question is whether a service provider processes data for the controller and under the controller’s documented instructions. Typical examples include cloud services, payroll providers, IT support and external archiving.
Under Article 28 GDPR, the agreement must address, among other matters, the subject matter and duration, the nature and purpose of the processing, the types of personal data and categories of data subjects, and the controller’s rights and obligations. It must also cover documented instructions, confidentiality, security measures, assistance with data-subject rights and personal-data breaches, the return or deletion of data, and information and audits.
A processor generally needs the controller’s prior specific or general written authorisation to appoint a sub-processor. The controller may use only processors that provide sufficient guarantees for appropriate technical and organisational measures. A processor must inform the controller if, in its view, an instruction infringes data protection law. Where a service provider uses data for its own purposes and determines those purposes itself, its role may go beyond that of a processor.
The assessment should therefore cover the actual arrangement, not only a contract template: which data are processed for which purpose, who determines the essential means, where does processing take place and which sub-processors are involved? The section on processors and service providers provides the organisational context. The processor agreement check and the processor assessment checklist support a structured initial review.
Learn more
General orientation, not individual advice.
Discuss your data protection matter
Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000