Processors and service providers
Organise roles, selection, contracts, instructions and controls for external providers.
Mag. Bernhard Brandauer, Rechtsanwalt
BRANDAUER Rechtsanwälte
Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.
A service agreement is not automatically a processor agreement. Processing on behalf of a controller typically exists where a provider processes personal data for the controller and on documented instructions. The controller decides the purpose and the essential means of the processing.
The review should therefore begin before signing. Businesses should map the actual data flow, the provider's decision-making powers, security measures and possible subprocessors. Only then can they assess whether Article 28 GDPR and section 48 of the Austrian Data Protection Act provide the right legal structure.
The firm's detailed guide to processor agreements and liability risks focuses on the contractual detail. This focus page adds the wider process, from role classification and provider selection to ongoing controls.
Mag. Bernhard Brandauer, Rechtsanwalt
Which role does the provider take?
Answer the questions based on the actual business model. The result is an initial orientation and does not replace a review of the agreement, data flow and working practice.
Does the provider decide the purpose and essential means of processing?
Do not rely only on the contract. Consider who actually determines the processing in daily operations.
Ihre Orientierung
The processor agreement needs practical clarification.
The provider chain and control model need to be completed.
The essential elements are in place.
Controller and processor compared
The roles depend on actual decisions about purpose and essential means. One provider may take different roles for different services.
| Question | Controller | Processor |
|---|---|---|
| Purpose of processing | Decides why personal data is processed. | Processes data on behalf of the controller and generally has no separate purpose for that processing. |
| Essential means | Determines the essential framework of processing. | Implements technical or organisational details within the instructions. |
| Legal relationship | Takes responsibility for the processing towards data subjects and the authority. | Needs an agreement or other legal instrument under Article 28 GDPR. |
| Subprocessors | Must organise the provider's selection and oversight. | Needs the required authorisation and passes on equivalent duties. |
The role cannot be determined from the agreement heading or technical description alone.
How to identify processing on behalf of a controller
Articles 4(7) and 4(8) GDPR distinguish between controller and processor. A controller decides the purposes and means of processing. A processor is a person, public authority or other body that processes personal data on behalf of the controller.
A typical example is an IT provider that stores customer data in a cloud application selected by the business. Payroll, newsletter delivery, hosting, support and document destruction may also involve processing on behalf of a controller. The word service provider does not answer the legal question.
The distinction from providers acting under their own purposes or legal duties is important. A provider may be a processor for one service and a controller for another. With complex platforms, review which decisions the business makes and which essential means the provider determines.
- What specific purpose is pursued by the processing?
- Who sets data types, data subjects and recipients?
- Which decisions may the provider make independently?
- Which data is processed for the provider's own billing, security or legal duties?
Selecting and assessing a provider before engagement
Under Article 28(1) GDPR, a controller may use only processors that provide sufficient guarantees for appropriate technical and organisational measures. This is not merely a paperwork exercise. Before engagement, the business should understand the data flow, access groups, security measures and provider chain.
Depending on the risk, selection may involve encryption, access management, logging, backups, deletion, business continuity and incident response. Certifications and audit reports can be useful indicators, but they do not answer whether the concrete service and agreed controls fit the processing at issue.
The processor assessment checklist structures due diligence. For an existing agreement, the processor agreement check helps make missing terms and controls visible.
What an Article 28 agreement must address
The agreement or other legal instrument must set out the subject matter and duration, nature and purpose, type of personal data, categories of data subjects and the controller's obligations and rights. These details create the framework in which instructions and controls can work.
The minimum content includes documented instructions, confidentiality, appropriate security measures, rules for subprocessors, assistance with data subject rights and breaches, support for compliance evidence and audits, and deletion or return after the service ends. The processor must also tell the controller if it believes an instruction infringes data protection law.
Article 28(9) GDPR requires the agreement to be in writing, including electronic form. Section 48(5) of the Austrian Data Protection Act confirms this for processors under Austrian law. A concise schedule can be sufficient when it fully describes the actual process. A long agreement can still be incomplete when essential data flows are missing.
- Processing only on documented instructions
- Confidentiality and access limited to authorised people
- Technical and organisational measures under Article 32 GDPR
- Assistance with rights, incidents and evidence duties
- Deletion or return and traceable audit rights
Instructions, security measures and evidence
Instructions do not have to anticipate every technical detail. They should make the permitted framework clear. This includes purpose, data types, data subjects, recipients and transfers, as well as the limits of the provider's own decisions. Changes should follow a traceable process.
Article 32 GDPR requires controllers and processors to implement a level of security appropriate to the risk. The required measures depend on the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the likelihood and severity of risks. A general promise of security without usable evidence is weak in a review.
Do not request every conceivable document automatically. Define which evidence is needed for the concrete processing, how long it remains current and who evaluates deviations. This connects with privacy governance and prevents contracts and controls from being managed separately.
Subprocessors and chains of service providers
Where a processor engages another processor, Article 28(2) and (4) GDPR apply. The controller may provide specific authorisation or general written authorisation with information about planned changes. With general authorisation, the controller must have the opportunity to object to changes.
In practice, the chain should not end with a link to an online list that changes without a usable process. The business needs a current view, a responsible function, a notice route and a decision on what happens after an objection. Location, access possibilities and transfers to third countries also require attention.
The first processor must impose essentially the same data protection duties on the further processor. If the further processor fails to meet its duties, the first processor remains responsible towards the controller for compliance with those duties.
Ongoing monitoring and changes in the business
The review does not end when the agreement is signed. The controller must continue to direct the processing and request evidence or audits where appropriate. The processor must provide the agreed assistance and may not use the data outside the instruction framework.
A workable control model connects risk, trigger and evidence. For lower-risk processing, current self-assessments and spot checks may be enough. Sensitive data, large volumes, critical systems or cross-border chains may require deeper review. Record scope, result, deviation and follow-up measure.
New software, new purposes, a change of subprocessors, a security incident or a material contract change should trigger a new review. An incident process must also explain how the provider informs the controller without undue delay. The focus page on personal data breaches explains the joint response.
Common mistakes with external providers
Many problems arise because the provider is treated as a purely technical matter. The following mistakes can be reduced through clear ownership and a shared process.
- The heading processor agreement is used although the provider pursues its own purposes.
- The agreement describes the provider but not the actual processing.
- Subprocessors appear only in an outdated schedule or are not recorded.
- Certificates are collected without assessing the concrete service and risk.
- Instructions are given orally and cannot later be reconstructed.
- Deletion, return, audits and assistance with data subject rights remain open.
Questions businesses ask about processors
Is every IT provider automatically a processor? +
Does every processor have to sign an Article 28 agreement? +
May a processor use further providers? +
How often should a processor be audited? +
Is there always a fixed deadline for a provider to report a breach? +
Related topics
Provider classification connects with contracts, governance, controls and incident management.
Processor agreement check
Review required terms, instructions, subprocessors and controls in a structured way.
Assess a processor
Assess providers before engagement and during the service relationship.
Privacy governance
Connect responsibilities, processing records, policies and evidence.
GDPR processing for SMEs
The firm's detailed guide to processor agreements and liability risks.
BRANDaktuelle Legal News
Subscribe to legal news
Receive new articles and legal information from the firm with BRANDaktuelle Legal News.
Subscribe to legal newsReview your provider and processor agreement
We help you assess roles, data flows, contract terms and controls for the provider you actually use.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000