Blog
Business9 August 2026 5 min🇩🇰 Denmark

Data processing agreement: requirements, content and template (GDPR 2026)

Data processing agreement guide: understand when you are required to have a DPA, what it must contain under GDPR article 28, and the rules on third-country transfers.

Karoline, Dokumentkonsulent

Written for Danish law and Danish contract practice.

Does your business use a payroll service, a CRM system, an email platform or a cloud provider, and do they process personal data on your behalf? Then you are obliged to enter into a data processing agreement (DPA). It is not optional. It is a legal requirement under GDPR, and a missing DPA is one of the most frequent reasons for orders and fines from Datatilsynet.

What is a data processing agreement?

A data processing agreement (DPA) is a legally binding agreement between a data controller and a data processor that specifies the terms for how the processor may process personal data on the controller's behalf.

Data controller vs. data processor

Role Definition
Data controller The business or person that determines the purposes and means of the processing of personal data. This is typically you, the business owner.
Data processor A business or person that processes personal data on the controller's behalf. This is typically your supplier.

Examples of data processors:

  • Payroll bureaus (process employee data)
  • Cloud hosting (stores personal data for you)
  • Email systems such as Mailchimp, HubSpot (process customer data)
  • IT support companies (with access to systems containing personal data)
  • Accounting software (may process customer data)

If the supplier can access personal data, they are probably your data processor.

When is a DPA mandatory?

GDPR article 28 requires you to have a DPA before you hand over personal data to a processor. This applies regardless of:

  • The size of the business (no minimum threshold)
  • Whether the processor is in Denmark, the EU or third countries
  • Whether the volume of data is small or large

If no DPA exists, Datatilsynet can sanction both the controller and the processor.

What must a data processing agreement contain?

GDPR article 28(3) lists precisely what a DPA must contain:

1. The purpose and nature of the processing

Describe precisely:

  • What is being processed for? ("Handling payroll for the controller's employees")
  • What type of processing is carried out? (Storage, transfer, deletion, etc.)

2. Categories of data subjects

Who are the persons whose data is processed?

  • Customers
  • Employees
  • Suppliers' contact persons
  • Website users

3. Types of personal data

What type of data is processed?

  • Name, address, email
  • CPR numbers
  • Health data (special category)
  • Financial data
  • Technical data (IP addresses, cookies)

Special categories of data (health, trade-union membership, race, religion, etc.) require special precautions.

4. Instructions from the controller

The processor may only process personal data on the controller's documented instructions. Any deviations must be reported.

5. Confidentiality

The processor, and all employees with access to the data, are bound by confidentiality.

6. Security measures (GDPR art. 32)

The processor must implement appropriate technical and organisational measures, including:

  • Encryption of data in transit and at rest
  • Access control
  • Procedures for recovery in the event of data loss
  • Regular testing of security measures

7. Sub-processors

If the processor itself uses subcontractors (sub-processors), this requires:

  • The controller's general or specific approval
  • That sub-processors are subject to the same obligations

Most DPAs use a general-approval model that requires prior notice of changes, so the controller can object.

8. Assistance to the controller

The processor must assist the controller in:

  • Responding to requests from data subjects (access, erasure, data portability)
  • Complying with GDPR's other obligations (impact assessment, handling of security breaches, etc.)

9. Deletion or return of data

On termination of the agreement, the processor must:

  • Delete or return all personal data at the controller's choice
  • Confirm the deletion in writing

10. Review and audit

The controller has the right to inspect and audit the processor's activities, either directly or via a third party.

Transfer of data to third countries

If your processor is located outside the EU/EEA (for example the USA, India, etc.), special rules apply:

  • The transfer must take place on a lawful basis (for example the EU's standard contractual clauses, SCC)
  • A Transfer Impact Assessment (TIA) is recommended
  • GDPR Chapter V governs this

Important: Datatilsynet handles cases about unlawful transfer to third countries on an ongoing basis. Use suppliers that can provide a GDPR-compliant DPA, or ensure correct SCC and any supplementary measures.

What happens if you do not have a DPA?

Datatilsynet has issued orders and fines to businesses that:

  • Had no DPA at all
  • Had a DPA that did not meet GDPR art. 28
  • Chose processors without sufficient guarantees

Fines can amount to up to 4% of global annual turnover or EUR 20 million, whichever is higher.

In addition to fines, a missing DPA entails:

  • Reputational risk
  • Liability for damages towards data subjects
  • A possible order to stop the processing

Data processing agreement or joint controllers?

Some situations are not processor/controller, but joint controllers (GDPR art. 26). This happens when two parties jointly determine the purposes and means of the processing.

Example: two businesses that jointly share a CRM system and both decide what data is registered and for what purposes are joint controllers and must enter into a joint-controller arrangement (not a data processing agreement).

What is a record of processing activities?

A record of processing activities (GDPR article 30) is internal documentation of your business's processing of personal data.

The starting point is that all controllers and processors must keep a record. There is an exemption for businesses with fewer than 250 employees, but only if the processing at the same time:

  • is occasional,
  • does not involve a risk to the rights of data subjects, and
  • does not include special categories of data or data on criminal offences.

In practice, the processing of employee and customer data is ongoing (not occasional), and therefore the vast majority of businesses must keep a record, regardless of the number of employees.

The record documents, among other things:

  • The purposes of the processing
  • Categories of data subjects and data
  • Data processors
  • Any transfers to third countries

The record does not have to be submitted to Datatilsynet, but must be capable of being shown on an audit.

Frequently asked questions

Do I need a DPA with my auditor?

It depends on the auditor's role. If the auditor performs a statutory audit, the auditor acts as an independent controller, and no DPA is required. If, on the other hand, the auditor processes personal data on your behalf as part of, for example, bookkeeping or payroll administration, they are a processor, and a DPA is necessary.

Can I use the supplier's DPA?

Many processors (Google Workspace, Microsoft, Mailchimp, etc.) have standardised DPAs that you can accept. Review them to ensure GDPR compliance before you accept.

What is the difference between a DPA and an NDA?

A DPA governs the processing of personal data under GDPR. An NDA (confidentiality agreement) governs the secrecy of business information. Both can be relevant in a supplier relationship, but they serve different purposes.

How long should a DPA be kept?

GDPR does not require a specific retention period for DPAs, but documentation of compliance should be kept for as long as the processing continues and for a suitable period afterwards, so you can document compliance in the event of an audit.

Who is liable if a processor makes a mistake?

Both parties can be held liable. The processor is directly liable towards data subjects and supervisory authorities if they act in breach of GDPR or the DPA. The controller is liable, among other things, for having chosen a processor with sufficient guarantees.

Conclusion

A data processing agreement is not a formality, it is a legal requirement that protects you, your customers and your employees. Review all your suppliers that have access to personal data, and make sure you have valid DPAs in place.


The content of this article is for guidance only and does not constitute legal advice. Consult a lawyer or data protection officer (DPO) for advice on your specific situation.

This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.