Privacy
Focus topic

Processors and service providers

Organise roles, selection, contracts, instructions and controls for external providers.

BRANDAUER Rechtsanwälte
Contact person

Mag. Bernhard Brandauer, Rechtsanwalt

BRANDAUER Rechtsanwälte

Mag. Bernhard Brandauer advises businesses on the legal classification and practical implementation of data protection requirements.

A service agreement is not automatically a processor agreement. Processing on behalf of a controller typically exists where a provider processes personal data for the controller and on documented instructions. The controller decides the purpose and the essential means of the processing.

The review should therefore begin before signing. Businesses should map the actual data flow, the provider's decision-making powers, security measures and possible subprocessors. Only then can they assess whether Article 28 GDPR and section 48 of the Austrian Data Protection Act provide the right legal structure.

The firm's detailed guide to processor agreements and liability risks focuses on the contractual detail. This focus page adds the wider process, from role classification and provider selection to ongoing controls.

Mag. Bernhard Brandauer, Rechtsanwalt

Initial orientation

Which role does the provider take?

Answer the questions based on the actual business model. The result is an initial orientation and does not replace a review of the agreement, data flow and working practice.

01 Question 1

Does the provider decide the purpose and essential means of processing?

Do not rely only on the contract. Consider who actually determines the processing in daily operations.

Ergebnis

Ihre Orientierung

01

The provider is not automatically a processor.

If the provider determines its own purposes or essential means, it may be a controller or joint controller. Review the actual decisions, recipients, legal obligations and information provided to data subjects.
Review responsibilities in governance →
02

The processor agreement needs practical clarification.

Connect purpose, duration, data categories, data subjects, instruction routes, assistance duties and audit rights to the actual process. Avoid clauses that merely repeat the heading processor agreement.
Check the processor agreement →
03

The provider chain and control model need to be completed.

Clarify whether specific or general authorisation applies, how changes are announced and how the business handles objections, security evidence and audits. A long provider list alone does not complete the responsibility.
Assess the processor with the checklist →
04

The essential elements are in place.

Keep the classification current. New data types, purposes, countries, subprocessors or security risks can trigger a new role and contract review.
Organise ongoing review →
Roles and duties

Controller and processor compared

The roles depend on actual decisions about purpose and essential means. One provider may take different roles for different services.

Controller and processor compared
Question Controller Processor
Purpose of processing Decides why personal data is processed. Processes data on behalf of the controller and generally has no separate purpose for that processing.
Essential means Determines the essential framework of processing. Implements technical or organisational details within the instructions.
Legal relationship Takes responsibility for the processing towards data subjects and the authority. Needs an agreement or other legal instrument under Article 28 GDPR.
Subprocessors Must organise the provider's selection and oversight. Needs the required authorisation and passes on equivalent duties.

The role cannot be determined from the agreement heading or technical description alone.

How to identify processing on behalf of a controller

Articles 4(7) and 4(8) GDPR distinguish between controller and processor. A controller decides the purposes and means of processing. A processor is a person, public authority or other body that processes personal data on behalf of the controller.

A typical example is an IT provider that stores customer data in a cloud application selected by the business. Payroll, newsletter delivery, hosting, support and document destruction may also involve processing on behalf of a controller. The word service provider does not answer the legal question.

The distinction from providers acting under their own purposes or legal duties is important. A provider may be a processor for one service and a controller for another. With complex platforms, review which decisions the business makes and which essential means the provider determines.

  • What specific purpose is pursued by the processing?
  • Who sets data types, data subjects and recipients?
  • Which decisions may the provider make independently?
  • Which data is processed for the provider's own billing, security or legal duties?

Selecting and assessing a provider before engagement

Under Article 28(1) GDPR, a controller may use only processors that provide sufficient guarantees for appropriate technical and organisational measures. This is not merely a paperwork exercise. Before engagement, the business should understand the data flow, access groups, security measures and provider chain.

Depending on the risk, selection may involve encryption, access management, logging, backups, deletion, business continuity and incident response. Certifications and audit reports can be useful indicators, but they do not answer whether the concrete service and agreed controls fit the processing at issue.

The processor assessment checklist structures due diligence. For an existing agreement, the processor agreement check helps make missing terms and controls visible.

What an Article 28 agreement must address

The agreement or other legal instrument must set out the subject matter and duration, nature and purpose, type of personal data, categories of data subjects and the controller's obligations and rights. These details create the framework in which instructions and controls can work.

The minimum content includes documented instructions, confidentiality, appropriate security measures, rules for subprocessors, assistance with data subject rights and breaches, support for compliance evidence and audits, and deletion or return after the service ends. The processor must also tell the controller if it believes an instruction infringes data protection law.

Article 28(9) GDPR requires the agreement to be in writing, including electronic form. Section 48(5) of the Austrian Data Protection Act confirms this for processors under Austrian law. A concise schedule can be sufficient when it fully describes the actual process. A long agreement can still be incomplete when essential data flows are missing.

  • Processing only on documented instructions
  • Confidentiality and access limited to authorised people
  • Technical and organisational measures under Article 32 GDPR
  • Assistance with rights, incidents and evidence duties
  • Deletion or return and traceable audit rights

Instructions, security measures and evidence

Instructions do not have to anticipate every technical detail. They should make the permitted framework clear. This includes purpose, data types, data subjects, recipients and transfers, as well as the limits of the provider's own decisions. Changes should follow a traceable process.

Article 32 GDPR requires controllers and processors to implement a level of security appropriate to the risk. The required measures depend on the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the likelihood and severity of risks. A general promise of security without usable evidence is weak in a review.

Do not request every conceivable document automatically. Define which evidence is needed for the concrete processing, how long it remains current and who evaluates deviations. This connects with privacy governance and prevents contracts and controls from being managed separately.

Subprocessors and chains of service providers

Where a processor engages another processor, Article 28(2) and (4) GDPR apply. The controller may provide specific authorisation or general written authorisation with information about planned changes. With general authorisation, the controller must have the opportunity to object to changes.

In practice, the chain should not end with a link to an online list that changes without a usable process. The business needs a current view, a responsible function, a notice route and a decision on what happens after an objection. Location, access possibilities and transfers to third countries also require attention.

The first processor must impose essentially the same data protection duties on the further processor. If the further processor fails to meet its duties, the first processor remains responsible towards the controller for compliance with those duties.

Ongoing monitoring and changes in the business

The review does not end when the agreement is signed. The controller must continue to direct the processing and request evidence or audits where appropriate. The processor must provide the agreed assistance and may not use the data outside the instruction framework.

A workable control model connects risk, trigger and evidence. For lower-risk processing, current self-assessments and spot checks may be enough. Sensitive data, large volumes, critical systems or cross-border chains may require deeper review. Record scope, result, deviation and follow-up measure.

New software, new purposes, a change of subprocessors, a security incident or a material contract change should trigger a new review. An incident process must also explain how the provider informs the controller without undue delay. The focus page on personal data breaches explains the joint response.

Common mistakes with external providers

Many problems arise because the provider is treated as a purely technical matter. The following mistakes can be reduced through clear ownership and a shared process.

  • The heading processor agreement is used although the provider pursues its own purposes.
  • The agreement describes the provider but not the actual processing.
  • Subprocessors appear only in an outdated schedule or are not recorded.
  • Certificates are collected without assessing the concrete service and risk.
  • Instructions are given orally and cannot later be reconstructed.
  • Deletion, return, audits and assistance with data subject rights remain open.
Frequently asked questions

Questions businesses ask about processors

Is every IT provider automatically a processor? +
No. The question is whether the provider processes personal data on behalf of the controller and under the controller's instructions. If it determines its own purposes or essential means, it may be a controller or joint controller. Actual working practice matters more than the agreement heading.
Does every processor have to sign an Article 28 agreement? +
Where processing on behalf of a controller exists, Article 28 GDPR requires an agreement or other legal instrument. The subject matter, duration, purposes, data types, instructions, security, assistance, controls and deletion duties must fit the concrete process.
May a processor use further providers? +
This is possible if the requirements for specific or general authorisation are met. With general authorisation, the controller must receive information about planned changes and have an opportunity to object. The duties must be passed on to the further processor.
How often should a processor be audited? +
The GDPR does not set one review interval for every provider. Frequency and depth depend on the processing, risk, data types, changes and available evidence. New systems, subprocessors, security incidents and material changes are typical triggers.
Is there always a fixed deadline for a provider to report a breach? +
The GDPR requires a processor to inform the controller without undue delay. It does not create one general 24-hour deadline for every contract. Specific internal reporting routes and shorter contractual timeframes can be useful so that the controller can meet its own duties.

BRANDaktuelle Legal News

Subscribe to legal news

Receive new articles and legal information from the firm with BRANDaktuelle Legal News.

Subscribe to legal news

Review your provider and processor agreement

We help you assess roles, data flows, contract terms and controls for the provider you actually use.

Contact

Clarify a data protection question

Address

BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich