You process personal data on behalf of your clients, and each of them sends you their own DPA template. Yet your record already holds much of the material. Here is what Article 30(2) gives you, what it does not, and how to close the gap.
Any provider processing data for its clients knows the scene: a new contract arrives with a twelve-page DPA drafted by the client’s lawyer, to be signed as is. Most sign. A few negotiate blindly. Almost nobody starts from what they already have.
The GDPR requires you to keep a record specific to your role as a processor, and the content of that record maps directly onto what the contract must set out. Kept properly, it becomes the raw material for your DPAs, and above all the instrument that lets you talk on equal terms with the lawyer across the table.
1. You may not be keeping the right record
First check, before anything else. Article 30 provides for two distinct records, rather than one record with two variants.
Paragraph 1 belongs to the controller, the one everybody knows, with purposes, categories of data subjects, categories of data and retention periods.
Paragraph 2 is yours. It requires each processor to maintain “a record of all categories of processing activities carried out on behalf of a controller”, containing four items and four only:
- (a) the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the representative and of the data protection officer;
- (b) the categories of processing carried out on behalf of each controller;
- (c) where applicable, transfers to a third country or an international organisation, including the identification of that third country, and for the transfers referred to in Article 49(1) second subparagraph, the documentation of suitable safeguards;
- (d) where possible, a general description of the technical and organisational security measures referred to in Article 32(1).
The mistake we correct most often at providers: a record modelled on the controller’s, organised by purpose, whereas paragraph 2 is organised by client. That distinction goes beyond presentation. A record organised by client converts straight into DPA schedules. A record organised by purpose has to be re-sorted for every new contract.
It is the first thing we look at when a provider calls us about a DPA. Nine times out of ten the record exists and it is structured from the wrong side.
2. What your record already covers of the contract
Article 28(3) requires a contract that “sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller”.
Here is the actual mapping, item by item.
| Required by Article 28(3) | In your record, Article 30(2) | What it gives you |
|---|---|---|
| Identification of the parties | (a), names and contact details of both parties, representative and DPO | Reusable as is at the head of the contract |
| Nature of the processing | (b), categories of processing per client | The basis of the descriptive schedule, to be refined |
| Subject-matter of the processing | (b), partly | To be reworded per service |
| Transfers outside the EU and safeguards | (c), with the country identified and the documentation | Feeds the documented instructions of point (a) |
| Security measures | (d), general description of the Article 32 measures | Feeds point (c), to be detailed |
| Duration of the processing | Missing | To be built |
| Type of personal data | Missing | To be built |
| Categories of data subjects | Missing | To be built |
| Obligations and rights of the controller | Missing | To be built |
So the record covers five of the nine items, including the three most tedious to reconstitute: who your clients are, what you do for each of them, and where the data goes. That is half the work, and the half nobody wants to redo for every contract.
3. The four items your record does not contain, and why
The point is worth understanding rather than merely enduring. Three of the four gaps come from the same place: they are pieces of information that belong to the controller, not to you.
The type of personal data and the categories of data subjects sit in paragraph 1(c), the controller’s record, and are deliberately absent from paragraph 2. The legislator does not ask you to document them, because your client decides which data it entrusts to you. You therefore need to obtain them from the client to complete the DPA, and that request is entirely legitimate.
The duration of the processing follows the duration of the service. It comes from your commercial contract, not from your record.
The obligations and rights of the controller are the counterpart of your own commitments. That is the only one of the four genuinely drafted from scratch, and it is where the negotiation happens.
In short: of the four gaps, three are closed by asking the client for information, and only one calls for drafting work.
4. The eight commitments the contract must contain, whatever happens
Beyond describing the processing, Article 28(3) lists eight obligations that must appear in the contract. None is optional, and none comes out of your record. In the order of the text, the processor:
- (a) processes the personal data only on documented instructions from the controller, including as regards transfers outside the EU, unless required to do so by law, in which case it informs the controller before processing;
- (b) ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation;
- (c) takes all measures required pursuant to Article 32;
- (d) respects the conditions of paragraphs 2 and 4 for engaging another processor;
- (e) assists the controller in responding to requests for exercising the data subject rights of Chapter III;
- (f) assists the controller in ensuring compliance with Articles 32 to 36, so security, personal data breaches and impact assessments;
- (g) at the end of the service, at the choice of the controller, deletes or returns the data and deletes existing copies, unless law requires storage;
- (h) makes available all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections.
The same paragraph adds an obligation rarely written into market DPAs: under point (h), you must immediately inform the controller if an instruction appears to infringe the GDPR. That is a protection for you as much as a constraint, and its absence from a template put in front of you is a good indicator of the quality of the document.
Two real negotiation points hide here. Point (g) forces a choice between deletion and return, and the choice belongs to the client: have it stated in the contract rather than discovering it at termination. Point (h) opens an audit right whose scope, frequency and cost allocation the Regulation leaves open, so it falls to you to frame them.
5. The two costliest traps
Sub-processing. Article 28(2) prohibits engaging another processor “without prior specific or general written authorisation of the controller”. Under a general authorisation you must inform the controller of any addition or replacement, which gives it the opportunity to object. And Article 28(4) requires the same data protection obligations to be imposed by contract on that other processor, while you “shall remain fully liable to the controller for the performance of that other processor’s obligations”.
In practice: your host, your backup tool, your support provider are sub-processors. They must appear in your DPA, and their own contracts must reproduce the obligations of paragraph 3. Your paragraph 2 record already lists them under item (a), which makes the exercise quick when the record is current.
Reclassification. Article 28(10) is short and heavy with consequences: if a processor infringes the Regulation “by determining the purposes and means of processing, the processor shall be considered to be a controller in respect of that processing”. Reusing a client’s data to improve your product, train a model or build a prospect base tips you over, with every obligation of a controller and the exposure that comes with it.
This is the point we check systematically at software vendors. The clause is often missing from the DPA, and actual data use goes beyond what the contract allows.
6. What you may not need, and what you always need
Article 30(5) exempts from the record, paragraph 1 and paragraph 2 alike, enterprises employing fewer than 250 persons. The exemption falls away as soon as the processing is likely to result in a risk to rights and freedoms, is not occasional, or involves special categories of data or criminal data. Processing your clients’ data is the core of your service, so nothing occasional about it. In practice, a provider is almost always bound to keep a record of processing activities.
The obligation to contract, on the other hand, has no threshold at all. Article 28(3) applies to a sole trader as much as to a group. A company exempt from the record remains bound by the DPA, and Article 28(9) requires it to be in writing, electronic form included.
One last point, the one that should settle it: Article 82(2) provides that a processor is liable for damage only where it has not complied with the obligations “specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller”. In other words, the documented instructions of point (a) act as your limit of liability. A precise DPA protects you as much as it binds you, and a vague one leaves you arguing after the fact about what you were supposed to do.
On the sanctions side, an infringement of Article 28 falls under the tier of Article 83(4), covering the obligations of Articles 25 to 39, up to 10 million euros or 2 % of total worldwide annual turnover.
Key takeaways
- Keep the paragraph 2 record, organised by client, not a copy of the controller’s record (Article 30(2)).
- That record covers five of the nine descriptive items required in the contract: parties, nature, subject-matter, transfers, security measures (Article 28(3)).
- Four are missing: duration, type of data, categories of data subjects, obligations of the controller. Three are obtained by asking the client, only one is drafted.
- The eight commitments of points (a) to (h) do not come from the record and must appear in the contract, including the duty to flag an unlawful instruction.
- Sub-processing: prior written authorisation and the same obligations passed down (Article 28(2) and (4)). You remain fully liable.
- Determining the purposes makes you a controller (Article 28(10)).
- The under-250 record exemption rarely applies, and never exempts you from the DPA (Article 30(5) against Article 28(3)).
- Documented instructions define the limit of your liability (Article 82(2)).
Signing your clients’ DPAs without negotiating them? We start from your record, draw a reference DPA that belongs to you, and you stop absorbing the other side’s templates. A 30-minute call is enough to see where you stand. Book a call with DPO-SPRING.
Pierre Cauvin, lawyer and outsourced DPO, advises service providers and software vendors on their GDPR compliance as processors.
Sources : Regulation (EU) 2016/679 (GDPR), Articles 28, 30, 32, 82 and 83, consolidated text on EUR-Lex.