Blog
Business20 June 2026 13 min🇩🇰 Denmark

GDPR data processing agreement for businesses

What businesses need to know about data processing agreements (DPAs): when one is required, what it must contain (Article 28), third-country transfers and B2B considerations.

Karoline, Dokumentkonsulent

Written for Danish law and Danish contract practice.

Does your business use a CRM system, a payroll service, an email platform or an analytics tool? Then there is a good chance you are required to enter into a data processing agreement with the supplier, and an even better chance that you have not done so.

Missing data processing agreements are one of the most frequent causes of GDPR sanctions. And it is not a problem reserved for large companies. Datatilsynet has also enforced the requirements against SMEs and sole proprietorships.

This guide explains when a data processing agreement is required, what it must contain, and what characterises a GDPR-compliant agreement.

What is a data processing agreement?

A data processing agreement (DPA) is a legally binding contract between two parties:

  • The data controller: the business that determines the purpose and means of processing personal data, typically you as the business owner
  • The data processor: a third party that processes personal data on the controller's behalf, typically your supplier

The agreement governs precisely what the processor may do with personal data, which security measures they must observe, and what happens in the event of a breach.

When is a data processing agreement required?

Article 28 of the GDPR requires a data processing agreement whenever a processor processes personal data on the controller's behalf. The key phrase is "on behalf of": the processor acts on the controller's instructions, not for its own purposes.

You must have a data processing agreement with, among others:

A payroll bureau or HR system. Processes employees' pay data, CPR numbers, sick days and more.

A CRM system and sales platforms. HubSpot, Salesforce, Pipedrive and others store your customers' contact details, history and behaviour.

Email marketing platforms. Mailchimp, ActiveCampaign, Klaviyo process names, email addresses and behavioural data for your subscribers.

Cloud hosting and server providers. AWS, Azure, Google Cloud are processors if your database is hosted with them and contains personal data.

Accounting software. E-conomic, Dinero, Billy and others can process customer data and transactions with personal data.

IT support companies. If your IT supplier has access to systems containing personal data, they are probably a processor.

Analytics and tracking tools. Google Analytics, Hotjar and similar collect visitor data that can constitute personal data.

Booking and administration systems. Systems that handle customer data, booking history and payment information.

You do not need a data processing agreement with:

A supplier is not a processor if they process personal data for their own purposes. Example: a bank processes payment data in its own right and is an independent controller, not your processor. Supplier relationships that only involve anonymous data (data that cannot be attributed to a person) are also not covered.

What must a data processing agreement contain?

Article 28(3) of the GDPR specifies what a data processing agreement must contain as a minimum:

1. A description of the processing

  • The subject matter and duration of the processing
  • The nature and purpose of the processing
  • The type of personal data (which categories: name, address, health data and more)
  • The categories of data subjects (customers, employees, users)

2. Processing only on instructions

The processor may only process personal data on the controller's documented instructions. If the processor departs from the instructions and determines the purpose and means itself, it may be regarded as an independent controller for that processing.

3. Confidentiality

Everyone at the processor with access to personal data must be under a duty of confidentiality.

4. Security measures

The processor must implement appropriate technical and organisational security measures under Article 32. The agreement should address, among other things, encryption, access control, regular security assessment and the procedure for a personal data breach.

5. Sub-processors

If the processor uses sub-suppliers with access to personal data, that requires your approval. The agreement must state:

  • Whether sub-processors are used
  • Whether specific approval is required per sub-processor, or a general approval is acceptable
  • That the processor is responsible for the sub-processor's compliance

Many SaaS suppliers ask for a general approval and give notice of changes. That is acceptable under the GDPR if you have the option to object.

6. Assistance to the controller

The processor must assist you in meeting your obligations, including answering data subjects' rights (access, erasure, portability), security measures and breach notification, and any impact assessments (DPIA).

7. Deletion or return on termination

When the collaboration ends, the processor must, at your choice, delete or return all personal data. The processor may, however, keep personal data to the extent EU or national law requires.

8. Audit access

The controller (or an auditor) must be able to carry out audits and inspections of the processor's processing. The processor must contribute to and enable such inspections.

9. Transfer to third countries

If personal data is processed in countries outside the EU and EEA, a transfer basis is required:

  • The Commission's standard contractual clauses (SCCs)
  • An adequacy decision for the country in question (for example the USA via the EU-US Data Privacy Framework, where the conditions are met)
  • Binding corporate rules (BCR)

Important: the use of US cloud services (Google, Microsoft, AWS, Salesforce and others) as a rule requires a valid transfer basis. Make sure it is covered in the data processing agreement.

Who enters into the data processing agreement?

The data processing agreement is entered into between you (as controller) and your supplier (as processor).

In practice, most large SaaS suppliers issue their own standardised agreements, which you accept as part of using their service (typically in the user agreement or as an addendum). It is important actually to review and accept these agreements formally. For smaller, local suppliers you should produce or require an agreement yourself.

B2B and the data processing agreement

For businesses in the B2B segment, data processing agreements are not only a legal requirement but also a competitive parameter.

Your B2B customers require it. Larger companies and public authorities almost always require a data processing agreement before they can use your service.

GDPR compliance as a sales argument. Document your processing activities, keep an updated privacy policy, and offer a clear agreement. This signals a professional approach and reduces customers' legal risk.

Offer an agreement proactively. Many customers spend time evaluating suppliers' agreements. A clear and easy-to-understand agreement that you offer proactively makes the collaboration easier.

What happens if you do not have a data processing agreement?

Sanctions. A breach of Article 28 can lead to a fine of up to EUR 10 million or 2% of global turnover, the lowest fine level under the GDPR. In Denmark the fine is imposed by the courts after a police report from Datatilsynet.

Compensation claims. If a person suffers harm as a result of unlawful processing, they can claim compensation from you as the controller.

Loss of customer relationships. Customers and partners, especially in B2B, can refuse to work with you if you do not have your agreements in order.

Reputational damage. Datatilsynet's decisions are published on datatilsynet.dk.

Practical: map your data processors

The first step is to map who processes personal data for you:

Supplier What is processed? Agreement in place?
Payroll bureau (e.g. Visma) Employee data, pay, CPR Yes/No
CRM (e.g. HubSpot) Customer data, contacts Yes/No
Email (e.g. Mailchimp) Subscriber data Yes/No
Hosting (e.g. AWS) All database data Yes/No
IT support Systems with personal data Yes/No

Review the list and ensure an agreement with all suppliers that are processors.

Record of processing activities (ROPA)

A data processing agreement is only one part of GDPR compliance. In addition to the agreement, your business should have a record of processing activities (ROPA), under Article 30.

The record documents which personal data you process, for what purpose, who has access, which processors you use, and when data is deleted.

Businesses with fewer than 250 employees are as a rule only required to keep a record for processing that is not occasional, that entails a risk, or that involves special categories. In practice it is recommended for all businesses.

Frequently asked questions about data processing agreements

Must I have an agreement with all my suppliers?

No, only with suppliers that process personal data on your behalf. A supplier that only delivers physical goods without access to personal data is not a processor.

My supplier is large (Google, Microsoft, Mailchimp). What do I do?

Large SaaS suppliers offer standardised agreements as part of their service terms. Typically you accept the agreement as part of the sign-up process. Make sure this has actually happened, and keep the documentation.

Can we use a standardised template?

Yes. A standardised data processing agreement can cover the GDPR's minimum requirements. Always adapt the appendix with the processing description to the specific relationship.

What is the difference between a data processing agreement and a privacy policy?

A privacy policy informs your customers and users about how you process their personal data. A data processing agreement governs what your suppliers may do with the personal data you entrust to them. The two are complementary.

What happens if my processor has a data breach?

The processor must notify you without undue delay after becoming aware of the breach. There is no fixed 72-hour deadline for the processor's notification to you. It is instead you, as controller, who has a duty to notify a notifiable breach to Datatilsynet within 72 hours. The agreement should govern the notification process precisely.

Can we enter into an agreement orally?

No. The GDPR requires the data processing agreement to be in writing, including in electronic form.

Does the GDPR apply to my business even though we are a small SME?

Yes. The GDPR applies to all businesses, regardless of size, that process personal data. There is no SME exemption, but the extent of the requirements is scaled to the business's activities.

Conclusion

A GDPR-compliant data processing agreement is not just a compliance box to be ticked. It is a concrete protection of your business, your customers and yourself. Map your data processors, ensure an agreement with all of them, and use an updated template that covers the requirements of Article 28.


The content of this article is for guidance only and does not constitute legal advice. The GDPR rules and Datatilsynet's practice develop continually. Contact a legal adviser for specific advice on GDPR compliance.

This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.