The data processing agreement almost always arrives at the same moment: at the end of the negotiation, as an annex, once the price is settled and nobody wants to reopen anything. It is signed without being read.
That is a misjudgement about who carries the risk. Where there is a breach, the controller — you — answers for its choice of processor. The agreement is not administrative paperwork: it is the only document recording what you required.
What Article 28 actually requires
The text sets out a minimum content. An agreement that does not cover every one of these is not compliant, however long it runs:
- the subject matter, duration, nature and purpose of the processing
- the categories of data and of data subjects
- the obligation to act only on documented instructions
- confidentiality undertakings from authorised personnel
- security measures, by reference to Article 32
- the regime for sub-processing, subject to authorisation
- assistance in responding to data subject requests
- notification of personal data breaches, and the deadline for it
- what happens to the data at the end: return or deletion
- making available what is needed for an audit
None of these clauses is decorative. Each corresponds to a moment when, not having written it, you will have no leverage.
The costliest point: classification
Before negotiating clauses, you have to agree on what is being bought. Hosted software and a managed service do not carry the same obligations: in one, the supplier provides a tool you administer; in the other, it runs the processing on your behalf.
That distinction moves the scope of regulatory validation, the split of responsibilities when something goes wrong, and even the list of sub-processors to declare. It is settled at the start, not at inspection.
Before arguing over clauses, you need to know what you are buying. Classification governs everything else.
Three frequent omissions
- Sub-processing. Your supplier almost always relies on others. Without an authorisation clause, you discover the chain at the moment of the incident.
- Audit. A right to audit with no mechanics — notice, frequency, scope, who pays — is a right nobody will exercise.
- The end of the contract. Return in what format, within what time, at what cost. Unwritten, it gets negotiated at the worst moment: when you are leaving.
What this changes in practice
A well-drafted processing agreement does not protect you from a failure — it determines who bears it, and what you can demand to put it right. It is a contractual exercise before it is a legal one, and it is conducted with the same instinct as any negotiation: knowing what you are asking for, and recognising an inadequate answer.