GDPR Data Processing Agreement
Data processing agreement per GDPR art. 28.
Jurisdiction: Denmark. Written for Danish law and Danish contract practice.
What is a gdpr data processing agreement?
Data processing agreement per GDPR art. 28.
What the document must contain
- Identification of the responsible company with registration number and contact details.
- The processing activities, services or terms covered.
- Purposes and legal basis for processing personal data.
- Retention periods and recipients, including sub-suppliers.
- The rights of users or data subjects and how to exercise them.
- Complaints channel and the date of the latest update.
Relevant legislation
- GDPR artikel 28:
- Obligatorisk indhold i en databehandleraftale.
- Databeskyttelsesloven:
- Danske særregler og Datatilsynets praksis.
References are indicative. LegalDock provides templates, not individualized legal advice.
Frequently asked questions
Is a gdpr data processing agreement mandatory?
For businesses processing personal data or selling to consumers, the documentation is required. Missing documentation can lead to orders or fines from the supervisory authorities.
How often should it be updated?
Whenever processing activities, suppliers or terms change, and otherwise at least once a year. Always state the date of the latest update.
What about sub-processors?
They must be listed, and equivalent data protection obligations must be imposed on them. The customer must be notified before a new sub-processor is used.
How long may we keep the data?
Only as long as the purpose requires, or as long as other legislation requires retention, for example five years under the Danish Bookkeeping Act. State the period concretely.
Must the document be public?
Privacy policies, cookie policies and terms of sale must be available on the website before purchase or collection. A data processing agreement is concluded between the parties instead.