Skip to content
Law

Transferring customers' personal data to an external processor

– what a DPA must contain

Your customer data sits in a cloud CRM, payroll is handled by an external accountant and a marketing agency sends out your e-mails. Each of them works with personal data of your people and customers, and you are responsible for whom you entrust it to and on what terms. The regulation therefore requires a written agreement with prescribed content. The lawyers of ARROWS law firm will set it up so that it actually protects you in the event of a data breach.

Právní tým ARROWS diskutuje o obsahu DPA při předávání osobních údajů externímu zpracovateli.

Key takeaways

The party that determines the purpose of the processing, i.e., you, is responsible for its lawfulness. A supplier that processes data according to your instructions is a processor and must have a contract with you.
The content of the data processing agreement is directly stipulated by the regulation. If mandatory points are missing, the agreement does not meet the requirements, regardless of its length.
The processor may not engage another processor without your prior written authorization. It is fully liable to you for any failure on the part of such other processor.
A limitation of liability in the agreement is subject to statutory limits. It does not apply to damage caused intentionally or by gross negligence.
When you and a partner jointly determine why and how data is processed in a joint campaign, this is not processing on instruction but joint controllership, which requires a different type of agreement.

DO YOU DEAL WITH RELATIONSHIPS WITH PERSONAL DATA PROCESSORS?

Contact us, we will be happy to assist you in setting up these relationships.

ARROWS law firm

When a supplier is a processor and when they are not

The decisive question is who determines why and how data is processed. Whoever determines the purposes and means of processing is the controller. Whoever works with the data only according to the controller's instructions and for their needs is the processor. A cloud CRM provider, an external payroll accountant, an e-shop platform operator, or a call centre are typical processors if they only work with data according to your instructions; a bank or insurance company that handles your employees' data for its own purposes is not a processor.

If processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures (Article 28 of the General Data Protection Regulation). The choice of a supplier is therefore not just a business decision: you are responsible for who you choose and should be able to document how you assessed their guarantees.

The line is not fixed. A processor who infringes the Regulation by determining the purposes and means of processing on their own is considered a controller in relation to that processing. An agency that also uses your contacts for another client's campaign ceases to be your processor and becomes a separate controller with all the obligations that entails.

In practice, it is good to have an overview of how many such relationships a company has at all. The average medium-sized company tends to have more processors than the legal department records: in addition to the main systems, there is also a meeting booking tool, a survey service, external IT support with access to databases, or an archiving company. Each of them needs a contract and for each of them, you need to know where the data is physically located.

What a data processing agreement must contain

A data processing agreement, often abbreviated as DPA, is the contract required by the Regulation between a controller and a processor. It must set out the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. It must be in writing, with an electronic form being sufficient.

The Regulation further lists what the contract must stipulate in particular about the processor's obligations. The processor shall process the data only on the documented instructions of the controller, including with regard to transfers to a third country. It shall ensure that persons authorised to work with the data are committed to confidentiality. It shall take the required security measures and comply with the conditions for engaging another processor. It shall inform the controller if, in its opinion, a particular instruction infringes data protection regulations.

The second set of obligations relates to cooperation. The processor shall assist the controller in handling requests from data subjects, for example for access or erasure, and in fulfilling obligations in the areas of security, breach notification and impact assessment. As soon as it becomes aware of a personal data breach, it shall notify the controller without undue delay. This deadline is crucial for you, because without timely information from the supplier, you cannot meet your own obligations to the authority or to the people whose data has been breached.

The third group deals with the end of the cooperation and control. Upon termination of the services, the processor shall, at your discretion, either delete or return all data and delete existing copies, unless the law requires their storage. At the same time, it shall provide you with all information necessary to demonstrate compliance with its obligations and allow for audits, including inspections, conducted by you or an auditor appointed by you. The context of inspections by the authority is discussed in the text on GDPR inspections in practice.

The list in the Regulation is a minimum, not a ceiling. The contract should also include what the Regulation does not explicitly require, but without which the obligations cannot be enforced: a specific deadline for breach notification in hours, a list of sub-processors in an appendix, the location of data storage, contact persons and penalties for breach. Which of these additional clauses is essential for a particular supplier depends on the volume and sensitivity of the data you transfer to them — which is why the Prague-based lawyers at ARROWS law firm set the scope of the contract according to the type of processing, not according to a template.

Frequently asked questions about concluding a data processing agreement

1. Is it sufficient if the supplier has processing terms in their terms and conditions?

It may be sufficient if they contain all the mandatory requirements and are binding on both parties. This is a common form for large cloud service providers; however, it is always necessary to verify that they do indeed cover all the points required by the Regulation.

2. Does the data processing agreement have to be a separate document?

It does not. It can be an appendix to the main contract or part of it. What is decisive is the content and the written form, not whether it is a separate document.

3. Do we also need a contract with a supplier who may only have access to the data?

If they systematically or necessarily process personal data according to your instructions when providing the service, then as a rule, yes. This typically involves external IT support that regularly works with the content of databases during servicing; a one-off intervention with only incidental access to data is assessed differently.

ARROWS law firm

Sub-processors: a chain that doesn't end with your supplier

A processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general authorisation, you must be informed of any intended changes concerning the addition or replacement of other processors, giving you the opportunity to object to them. Specific authorisation gives you more control over each change, but is virtually unenforceable with larger suppliers as they change their chain on an ongoing basis.

For companies, the second half of this rule is more important, namely liability. If a processor engages another processor, it must contractually impose on it the same data protection obligations as it has towards you. If the other processor fails to fulfil its obligations, the initial processor remains fully liable to you for their performance. Your supplier cannot therefore pass on the failure of its sub-supplier to you.

In practice, it is therefore necessary to know who is in the chain. A cloud supplier commonly uses data centres, customer support tools and monitoring services from other companies, often based outside the European Union. Each such link is a place where data can be breached or transferred to a third country. The conditions for transfers to third countries are governed by separate rules and must be explicitly included in the contract.

A reasonable standard is a general authorisation with a list of existing sub-processors in an appendix. In addition, an obligation to notify of a change with sufficient notice and your right to terminate the contract if you do not agree with the change. How these rules apply to mobile applications and platforms is discussed in the text on personal data processing in applications.

Liability: who pays when a processor fails

Towards the people whose data has been breached, you as the controller bear broad liability, even for processing carried out on your behalf. The processor is directly liable for the damage if it has not complied with the obligations laid down in the Regulation specifically for processors, or if it has acted outside or contrary to your instructions. The data subject can therefore turn to both you and the supplier. If both are liable for the same damage, the data subject can claim full compensation from either of them, and you will then settle the shares between yourselves.

Between you and the supplier, liability is then dealt with according to the contract and the Civil Code. If the supplier breaches a contractual obligation, it will compensate for the damage arising from it (under Czech legislation, Section 2913 of the Civil Code). It is only released from its obligations if it can prove an extraordinary, unforeseeable and insurmountable obstacle that arose independently of its will. The costs of investigating an incident, informing customers and legal defence are items that will cost you dearly without a well-drafted contract.

Suppliers defend against this with a limitation of liability, usually in the amount of the annual payments for the service. However, such a limit has legal boundaries. An agreement that excludes or limits in advance the obligation to compensate for damage caused to a person's natural rights, or caused intentionally or by gross negligence, is disregarded (under Czech legislation, Section 2898 of the Civil Code). The limit therefore does not cover a case where the supplier ignored basic security rules to such an extent that it constitutes gross negligence. Where exactly this line lies is assessed according to the circumstances of the specific incident.

Whether the liability limit for a particular supplier corresponds to the risk is assessed according to the volume and sensitivity of the data transferred and the damage a breach would actually cause — which is why the Prague-based lawyers at ARROWS law firm calculate it based on the type of processing, not the price of the service.

Penalties and limitation of liability in the contract

Many data processing agreements contain a contractual penalty for breach of obligations, for example for late notification of a breach or for engaging another processor without consent. A penalty motivates compliance, but there is a catch. If a contractual penalty is agreed, the creditor is not entitled to compensation for damage arising from the breach of the obligation to which the penalty relates (under Czech legislation, Section 2050 of the Civil Code).

In the case of a data breach, the damage is usually an order of magnitude higher than any reasonably agreed penalty. Unless the contract provides that, in addition to the penalty, damages can also be claimed in full, the penalty paradoxically narrows your claim. This one sentence belongs in every data processing agreement where you agree on penalties, and without it, the penalty becomes more of a protection for the supplier than for you.

Moreover, the amount of the penalty is not certain in itself. A court may, at the debtor's request, reduce an unreasonably high contractual penalty, taking into account the value and importance of the secured obligation (under Czech legislation, Section 2051 of the Civil Code). The court does not assess the agreed amount as such, but the specific claim: how and under what circumstances the breach occurred and how it affected the interests that the penalty was intended to protect.

A reasonable compromise that is accepted in the market is a combination of a penalty and full compensation for damages. The penalty applies to procedural errors such as late notification or failure to notify a change of sub-processor, while full compensation for damages applies to the breach itself. In addition, a liability limit that applies separately and at a higher amount for data breaches than for normal service defects. It is also worthwhile to keep a record of the costs and impacts that the incident caused you, as these will show what interest the penalty was protecting.

Our specialists for you

Mgr. Petr Hanzel, LL.M.

Mgr. Petr Hanzel, LL.M.

advokát

hanzel@arws.cz
JUDr. Jakub Dohnal, Ph.D., LL.M.

JUDr. Jakub Dohnal, Ph.D., LL.M.

advokát, řídící partner

dohnal@arws.cz
ARROWS law firm

Joint campaign: when you share data with a partner

A different situation arises when you do not send data to a processor, but share it with a business partner for a common purpose, typically for a joint marketing campaign, competition or loyalty programme. Where two or more controllers jointly determine the purposes and means of processing, they are joint controllers (Article 26 of the General Data Protection Regulation). Sharing contacts alone does not mean this; the decisive factor is whether you both actually decide on the purpose and manner of processing.

Joint controllers must, by means of a transparent arrangement between them, determine their respective responsibilities, in particular as regards the exercise of the data subject's rights and the duty to inform people about the processing. The arrangement may designate a contact point. The arrangement must reflect the respective roles and relationships of the controllers vis-à-vis the people whose data they process, and the substance of the arrangement must be made available to those people.

The fundamental difference from a processing agreement is the position vis-à-vis people. Regardless of how you divide the responsibility, a data subject may exercise his or her rights in respect of and against each of the controllers. The internal division thus only protects the relationship between you and your partner, not you against the customer, who can choose from whom to enforce their rights.

In practice, this situation is often recognised too late. Companies conclude a business contract with a partner for a joint event, share contacts, and there is nothing in it about data protection. If the partner then uses the data in a way other than agreed, you have no contractual basis and may still find yourself in the role of the one responsible for the processing towards the customers.

How to negotiate a data processing agreement with a large supplier

With large cloud service providers, the data processing agreement is usually non-negotiable and offered in a standard version. This does not mean you should just sign it. You should read it and check whether it contains all the mandatory requirements, where the data is located, what the list of sub-processors is, and how quickly a breach is reported.

If the standard version is not sufficient, the solution is to choose the service, not to negotiate the text. Large suppliers offer different levels of service with different conditions, including data location in the European Union or extended audit rights. The difference in price is usually less than the costs that non-compliance would cause you.

With small and medium-sized suppliers, the situation is the opposite. There, it is worthwhile to have your own template for a data processing agreement and to insist on it, because suppliers often do not have their own template or use an incomplete one. How to proceed when ordering software or a cloud service in general is discussed in the text on ordering custom software or SaaS.

The Regulation also offers you a simplification. The contract may be based in whole or in part on standard contractual clauses adopted by the European Commission. Their use simplifies negotiations, as there is then no dispute about the content of the mandatory provisions, leaving only the commercial parts to be negotiated, i.e. deadlines, limits and penalties.

Mistakes that only become apparent during a breach

The most common mistake is a data processing agreement signed as a formality that no one has read. The company has it, but does not know how quickly the supplier must contact them in the event of a breach, where the data is located, or who is in the chain of sub-processors. In the event of an incident, it then deals with basic questions under time pressure.

The second mistake is a lack of an overview of which suppliers you have a contract with at all. Tools introduced by individual departments without the knowledge of management, trial versions of software, or services paid for with a company card often do not have a contract. This is where data breaches are most common, because no one monitors their settings or who has access to them.

The third mistake is a contract that does not specify what happens to the data after the cooperation ends. The supplier continues to store the data because it has no instruction to delete it, and you lose track of it. In the event of a later breach from its system, you may then be held responsible for data you did not know still existed. Therefore, the contract should also include an obligation to confirm the deletion in writing.

The fourth mistake is overlooked joint controllership. A company considers a partner to be a processor and concludes a processing agreement with them, even though in reality both determine why the data is being processed. Which type of contract is correct for your cooperation is assessed according to who actually decides on the purpose — and this is what the entire division of responsibility is based on, which is why the Prague-based lawyers at ARROWS law firm evaluate it before signing.

Where a data processing agreement fails

Risk in the contract

How ARROWS secures it contractually

Missing mandatory requirements under the Regulation: the contract does not meet the requirements regardless of its length.

We will add all mandatory points and verify their wording. We will prepare and review the data processing agreement.

The deadline for breach notification is not specific: you learn about the incident late and your deadlines are already running.

We will agree on a deadline in hours and a notification procedure. We will negotiate the terms directly with the supplier.

The chain of sub-processors is unknown: data is going to companies you don't know about.

We will introduce a list of sub-processors and the right to terminate the contract in case of a change. We will vet the business partner before signing.

The penalty excludes compensation for damages from a breach: the sanction is an order of magnitude lower than the actual damage.

We will add a reservation for compensation for damages in addition to the penalty and a separate limit for breaches. We will provide an expert legal opinion on the scope of liability.

Joint campaign without a controllers' arrangement: the partner uses the data differently and you have no recourse.

We will prepare a joint controllers' arrangement on the shares of responsibility. We will provide expert training for marketing and sales.

ARROWS law firm

Final summary

The article has shown that a data processing agreement is not a formality, but the main tool by which you can control what a supplier does with the data of your customers and employees. The Regulation sets out its mandatory content, and towards the people whose data you transfer, you as the controller bear broad liability, even for processing carried out on your behalf. The contract therefore determines what you will be able to claim back from the supplier.

For a company's management, two overviews that can be quickly prepared are essential. The first is a list of all suppliers who work with personal data, including tools introduced by individual departments. The second is, for each of them, the answer to three questions: where the data is located, how quickly they report a breach, and whether the liability limit covers the real damage.

Procrastination does not pay off here, because the contract must be in place before you transfer the data, and you cannot amend it after an incident. Every month without a contract is a month of processing that does not meet the requirements of the Regulation. Companies that have handled a breach without major losses had contracts with specific deadlines and knew who was in the chain.

The Prague-based lawyers at ARROWS law firm will prepare and review data processing agreements and joint controller arrangements, vet your suppliers and their chain of sub-processors, negotiate terms with the other party, and represent you in asserting claims after a breach. Write to us at consultation@arws.cz or browse our GDPR and Personal Data Protection service.

Frequently asked questions about data processing agreements

1. What if a supplier refuses to sign a data processing agreement?

Then you cannot share personal data with them in compliance with the Regulation, as the contract is mandatory. The refusal is also a signal that the supplier does not have data protection under control, which should be a factor in the decision to select them.

2. Does a company that only processes data within a group also need a data processing agreement?

Yes, if one company in the group processes data for another according to its instructions. A group is not a single controller, and the relationships between its members are assessed in the same way as relationships with external suppliers.

3. How often does a data processing agreement need to be updated?

Whenever the scope of processing, the type of data changes, the supplier changes sub-processors, or the location of data storage. A regular annual check helps to catch changes that the supplier has not informed you about.

4. Can we reserve the right to audit the supplier in the contract?

Yes, the Regulation directly provides for the right to audits, including inspections. With large suppliers, this is usually replaced by the submission of independent audit reports and certifications, which is often more practical than conducting your own inspection.

5. What if the supplier is based outside the European Union?

Then, in addition to the data processing agreement, you must also address the conditions for transferring personal data to a third country. These are governed by separate rules of the Regulation, and compliance with them must be verified before starting the cooperation.

6. Are we liable for a breach even if it was caused by the supplier?

You can be, but not automatically. As the controller, you are responsible for the proper setup of the processing and for selecting a supplier with sufficient guarantees, but the processor has its own obligations and is directly liable for their breach. Who bears the compensation for damages or the fine depends on who breached which obligation and under what circumstances.

DO YOU HAVE MORE QUESTIONS? GET IN TOUCH

ARROWS law firm

About the author

JUDr. Jakub Dohnal, Ph.D., LL.M.
JUDr. Jakub Dohnal, Ph.D., LL.M.

Associate, managing partner

Jakub Dohnal is an attorney-at-law and managing partner of ARROWS. He focuses on company sales, investor entries into private companies and real estate transactions — most often acting for the owner who is selling a business built over many years and needs the deal to close on the agreed terms.