Skip to content
Law & data protection

Data processing agreements: what a website really needs

Which services behind a website count as processing on your behalf, what the Article 28 GDPR contract must contain and how the record of activities follows.

15 min read DSGVOAuftragsverarbeitungRechtWebsite-Betrieb

The call usually comes on a Monday. The supervisory authority has written, not because of an incident but because of a complaint: someone used the contact form and wanted to know where their message ends up and who can read it on the way. The answer is written down nowhere. The website runs with one provider, the form sends through a second, appointments sit in a third, the newsletter in a fourth, and the map on the contact page loads from a fifth. Five places where visitor data is processed, and for three of them no contractual arrangement exists. This article shows which of these services count as processing on your behalf, what the contract has to contain, how sub-processors fit in, and how the same list turns into the record you can hand to an authority.

Key takeaways

  • Not every service provider behind a website is a processor. What matters is whether it processes personal data on your instructions or pursues purposes of its own.
  • Article 28(3) GDPR lists eight points the contract has to cover at minimum: from documented instructions through confidentiality to deletion once the service ends.
  • If the contract is missing, the guidelines of the European Data Protection Board treat that as an infringement in itself, regardless of whether anything happened to the data.
  • Sub-processors need authorisation. Under the usual general authorisation the provider has to announce every change and leave you the opportunity to object.
  • The record of processing activities under Article 30 GDPR falls out almost as a by-product once the services are listed cleanly. The exemption for businesses under 250 employees rarely applies to a live website.

Five services, five contracts

A website is rarely a single piece of technology today. It is a set of services running in different places and connected through the page. To the visitor it looks like one thing. In legal terms there are as many relationships as there are services involved. Someone filling in the form hands their name to the business, their message to its form provider, their network address to the data centre and, if a map is embedded, their page request to the map service as well. Four recipients for one click.

For each of those recipients the first question is the same: is it acting on your instructions, or is it acting for itself? That is not an academic distinction. It decides whether a data processing agreement is needed, whether a separate legal basis is required, and who is liable when something goes wrong. In its short paper on processing on behalf of a controller, the German data protection conference explicitly names the outsourcing of email administration or of other data services for websites, giving the operation of contact forms or user enquiries as its example (Datenschutzkonferenz), as a typical case. The form on the contact page is therefore not a borderline case but the textbook one.

The topic looks technical but has a very practical side. The Hamburg Commissioner for Data Protection and Freedom of Information examined 1,000 randomly selected websites of operators based in Hamburg without any specific trigger. In 185 out of 1,000 cases (HmbBfDI) the operators had to make corrections. The authority describes the reason plainly: many operators do not know the requirements for embedding external services, or do not implement them. Anyone who has already sorted out consent in the cookie banner has done one half. The other half is the contract with whoever processes the data afterwards.

The number of complaints is rising noticeably. In Hamburg alone more than 4,200 data protection complaints (HmbBfDI) were received in 2025, a good sixty percent more than the year before according to the authority. A complaint is not a fine procedure, but it leads to an enquiry, and that enquiry wants an answer. Anyone able to present a list of their services together with the contracts has a short case. Anyone who has to assemble it first has a long one. The mandatory details in the legal notice are the visible part of these duties, the contracts the invisible one.

Processing on behalf of a controller is not a permission in itself. The contract does not replace the legal basis, it supplements it. The processing still needs a ground under Article 6 GDPR, for instance the steps prior to entering into a contract in the case of an enquiry, or consent in the case of a newsletter. The data processing agreement only governs the conditions under which a third party may carry out that processing for you.

When a provider counts as a processor

A processor processes personal data on behalf of a controller. The controller determines purposes and means, the processor carries them out. As soon as a service provider starts pursuing purposes of its own, the relationship flips. Article 28(10) GDPR is clear on this point: a processor that infringes the regulation by determining the purposes and means of processing is considered a controller in respect of that processing (GDPR) and carries a controller's duties accordingly.

In practice the distinction is easier than it sounds once you know two edge cases. The first: anyone working exclusively on the infrastructure, without access to content, is not a processor. The data protection conference names work on power supply, cooling and heating as its example (Datenschutzkonferenz). The second: professionals bound by secrecy such as tax advisers, lawyers or auditors are, according to the same paper, generally controllers in their own right rather than processors (Datenschutzkonferenz). Almost everything attached to a website sits between those two poles, and most of it sits closer to the first case than to the second.

The hosting provider is the clearest case. It stores your database, your log files and your mailboxes, it sees your visitors' network addresses, and it does so for you, not for itself. Anyone working through server location and backup arrangements while choosing a hosting provider should tick off the data processing agreement in the same pass. Reputable providers keep it ready in the customer account, where it only needs to be accepted and filed.

  • The service processes data originating from your visitors or customers.
  • It does so because you commissioned it, not on its own initiative.
  • You determine what the data is used for and how long it stays.
  • The service may not use the data for its own analyses, its own advertising or its own products.
  • If one of these statements falls away, it is not processing on your behalf but something else that needs its own assessment.

Since the Regulation establishes a clear obligation to enter into a written contract, where no other relevant legal act is in force, the absence thereof is an infringement of the GDPR.

European Data Protection Board, Guidelines 07/2020, paragraph 103

What the contract has to contain

Article 28(3) GDPR describes the frame first and the content second. The frame: subject matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. Then follow eight points (GDPR) the contract has to stipulate in addition. Those eight points are the actual yardstick, and they can be held against any template contract in a few minutes.

In the order of the law they are: processing only on documented instructions, a commitment to confidentiality from the people involved, the measures required under Article 32, the conditions for engaging another processor, assistance with data subject rights, assistance with notification duties and impact assessments, deletion or return once the service ends, and finally the proof. The last point is the one most often overlooked and the most important in practice.

  • Processing only on documented instructions, including for transfers to a third country.
  • A confidentiality commitment from everyone with access to the data.
  • Technical and organisational measures under Article 32 GDPR.
  • Compliance with the conditions for engaging another processor.
  • Assistance with data subject requests for access, rectification or erasure.
  • Assistance with notification duties, security measures and data protection impact assessments.
  • Deletion or return of all data once the service ends, at your choice.
  • Provision of all proof and facilitation of audits, including inspections.

The eighth point gives you a right many businesses rarely exercise and still need in the contract: the processor has to make available all information necessary to demonstrate compliance and to allow for and contribute to audits, including inspections (GDPR). In practice that rarely means a visit to the data centre. It means the provider describes its measures on request and makes existing audit reports accessible. A contract that excludes this right, or ties it to conditions nobody can meet, does not satisfy Article 28(3).

Formally, electronic form is enough: the contract has to be in writing, including in electronic form (GDPR). An accepted agreement in the customer account therefore suffices, as long as it remains retrievable. The European Data Protection Board additionally recommends bringing the elements implementing Article 28 together in one place, for example in an annex, so that demonstrating compliance becomes easier (European Data Protection Board). That is exactly how we set it up in projects covered by our services: one folder, one overview, one date per contract.

A common misunderstanding: “we do have a privacy policy”. The privacy policy informs the data subjects. The data processing agreement binds the service provider. One does not replace the other, and both have to name the same services, otherwise they contradict each other at the first inspection.

Sub-processors: the second row

Hardly any service provider works alone. The form provider sends through a mail dispatcher, the mail dispatcher runs in a data centre, the data centre buys in storage. The regulation calls this chain “another processor”, everyday language calls it a sub-processor. Article 28(2) GDPR requires prior specific or general written authorisation of the controller for it (GDPR). Without that authorisation the second row may not touch the data.

In practice almost every provider works with the general authorisation. It usually appears as a list in the contract or on a linked subpage. To serve its purpose, the law attaches a condition: the processor has to inform the controller of any intended changes so that the controller has the opportunity to object (GDPR). Anyone who does not read those announcements loses the right in fact, without ever having given it up.

The second row deserves attention for a practical reason too: this is often where the question of the processing location is decided. A provider with a German server location may use a sub-processor for backups that sits elsewhere. That is precisely why the list of sub-processors belongs to every contract we hand over for hosting in Germany, and why it is checked rather than merely supplied.

Specific authorisationGeneral authorisation
How it comes aboutYou expressly agree to one individual sub-processorYou agree to a list that is allowed to change
How common it isRare, mostly for sensitive processingThe normal case for standard services
Your duty afterwardsAgree again when a provider is addedRead and assess the change notifications
The provider's dutyAsk beforehandAnnounce every intended change
Your leverage in a disputeWithhold agreementObject, and terminate if necessary

The five services of a typical website

The following five services appear on almost every local business website. They differ in how visible they are, but all five process personal data, and all five belong in the same list. A sixth row is usually added by your own provider for backups and maintenance, the one nobody sees from outside. Once these rows have been written down completely, the larger part of the work is behind you.

Web hosting

Stores files, database and logs. Sees network addresses, timestamps and requested pages. A classic case of processing on your behalf; most providers keep the contract ready in the customer account.

Contact form

Receives names, messages and often attachments and forwards them. Explicitly named by the German data protection conference as processing on behalf. Check: where is the message stored in the meantime, and for how long?

Appointment booking

Processes name, contact route and time slot, and for medical practices health-related context as well. Needs a contract and a clear rule on which reminders are permissible without separate consent.

Newsletter

Stores address, sign-up time and proof of consent, usually open and click data too. That proof is part of the commissioned data and has to come back when the contract ends.

Map service

Loads from an external source on page view and transmits network address and browser data in the process. Often not plain processing on behalf but a transfer requiring its own assessment.

Backups and maintenance

Anyone creating backups, applying updates or hunting for faults sees data while doing so. Your own service provider therefore needs a contract too, not only a password.

The map service is the case most often classified incorrectly. If a map is loaded directly into the page, the visitor's network address goes to the provider before anyone has clicked. Whether that still counts as processing on your behalf or already as a transfer to an independent controller depends on what the provider does with the data. In both cases the same holds: the request needs a basis, and the map belongs in the list. A static directions graphic with a link to a map service avoids that request and costs less loading time.

Appointment booking has an edge of its own where health data is involved. The Hamburg Commissioner for Data Protection and Freedom of Information notes that the German data protection conference adopted a position paper on the use of service providers for online appointment booking on 16 June 2025 (HmbBfDI). Among other things it follows from that paper that arranging an appointment is part of the treatment, whereas sending appointment messages is to be permitted only with express consent (HmbBfDI). Anyone running a practice website should be able to trace that separation in the booking tool.

With the newsletter the core lies elsewhere. Here the sending is not the problem, the proof is: who consented when and how has to remain demonstrable, and that evidence sits with the service provider. When the contract ends it has to come back or be deleted, at your choice rather than theirs. That is exactly the seventh of the eight points. Incidentally, anyone who publishes prices on the website receives fewer but clearer enquiries. It changes nothing about the data route: they run through the same services and belong in the same list.

The record under Article 30

Once the five services are on the table, the record of processing activities is no longer a separate project but a different view of the same data. Article 30(1) GDPR requires, for each processing activity, details of the controller, the purposes, the categories of data subjects and of data, the recipients, transfers to third countries, erasure periods and a general description of the measures (GDPR). That is a table with seven columns, no more.

Many businesses hope for the exemption at this point. Article 30(5) GDPR exempts enterprises with fewer than 250 employees (GDPR) from the obligation, but under three conditions that all have to be met at once: the processing must not pose a risk to rights and freedoms, it must be occasional only, and it must not include special categories of data. A website that receives enquiries every day does not process occasionally. In a running operation the exemption therefore usually ends at the second condition.

The record has to be kept in writing, including in electronic form, and made available to the supervisory authority on request (GDPR). “On request” means at short notice. A table that sits in the folder and is touched once a year serves that purpose. A table that only comes into being after the enquiry does not, and it shows. Anyone who wants to clarify who owns the domain and the access credentials anyway can do both in one pass: the list of credentials and the list of processing activities concern the same services.

The exemption that rarely applies

The exemption in Article 30(5) GDPR is not a size threshold but a combination of three conditions. It falls away as soon as the processing is more than occasional. A contact form receiving enquiries every week is not occasional. The practical answer for most businesses with an active website is therefore: keep the record, even below 250 employees.
record-of-processing.txt
Processing: contact enquiries through the form
Purpose: answering enquiries, steps prior to entering into a contract
Legal basis: Article 6(1)(b) GDPR
Data subjects: prospects, customers
Data categories: name, e-mail, phone, message text, attachments
Recipients: form provider (processor), hosting provider (processor)
Third country: no
Erasure period: 6 months after the matter is closed
Measures: transport encryption, office access only, daily backup
Contract: data processing agreement of 12 March 2026, filed under Legal/DPA/

Checking instead of signing

A contract nobody has read is a file reference, not a safeguard. Checking a standard contract typically takes a quarter of an hour, and it pays off because the deviations repeat themselves. Most frequently missing or shortened is the proof point, followed by the arrangement for deletion and the list of sub-processors. Anyone laying the eight points beside the contract as a checklist finds the gaps without legal training.

The second part of the check is technical and goes faster. You need a list of every external address your page contacts when it loads. That list is the counter-check to the contract folder: every external address needs either a contract, a legal basis of its own, or a reason why it is still embedded. Not seldom a service surfaces that somebody added three years ago and then forgot.

Terminal
$ curl -s https://www.beispielbetrieb.invalid/ | grep -oE 'https?://[^"\x27]+' | cut -d/ -f3 | sort -u
cdn.formularanbieter.invalid karten.dienst.invalid schrift.anbieter.invalid www.beispielbetrieb.invalid ; Three external targets besides your own address, each needs a decision.
$ grep -RiEl 'iframe|script src="https' seiten/ | wc -l
7 ; Seven pages actively embed external content. Check those seven first.
  • Is there a contract for every external service, dated and filed?
  • Does the contract name all eight points from Article 28(3) GDPR?
  • Is there a list of sub-processors, and how are changes announced?
  • Is it settled what happens to the data at the end, and who chooses between deletion and return?
  • Does the privacy policy match the contract folder, or does one of the two name services the other does not know?
  • Does every service appear in the record with its purpose, data categories and erasure period?

What a missing contract sets off

The consequences of a missing contract tend to be taken seriously too late because they sound abstract. They are not. Infringements of the obligations under Article 28 fall within the frame of Article 83(4) GDPR: administrative fines of up to 10 million euros (GDPR) or, in the case of an undertaking, up to 2 percent (GDPR) of its total worldwide annual turnover of the preceding financial year, whichever is higher. For a local business the upper limit is not the relevant figure, but the fact that an authority has the choice certainly is.

More important day to day is the second consequence. Under Article 82(1) GDPR any person who has suffered material or non-material damage as a result of an infringement has the right to compensation from the controller or the processor (GDPR). The controller is liable for damage caused by processing that does not comply with the regulation, whereas the processor answers only under narrower conditions. Without a contract that allocation is hard to set out in a dispute.

The third consequence is the quietest and hits most often: without a contract there is no claim to information and handover. If a service provider is no longer reachable or a switch is due, the contract decides whether you get your data back. It is the same mechanism as with moving website and mailboxes: what is settled in writing beforehand is a matter of hours afterwards. What is not settled becomes a matter of weeks.

According to the guidelines of the European Data Protection Board, a missing contract is an infringement in itself, even if nothing happened to the data. Both sides are responsible for the processing being governed contractually, and depending on the individual case the supervisory authority can turn to either of them. The repair is cheaper than the procedure: a contract signed after the fact costs a signature.

The yearly rhythm

Having the contracts is one part, keeping them current is the other. Providers change their sub-processors, businesses embed new services, old tools disappear. A data protection setup without upkeep typically goes stale within a year, and precisely at the points that were worked through most thoroughly at the start.

With us that hangs off website maintenance and runs in a fixed rhythm: once a quarter the list of embedded services is checked against the page source, once a year the contracts and the record are worked through, and with every change to the site the question is asked whether a new recipient has appeared. Anyone who sets up seasonal pages before the season often embeds an additional form or booking route while doing so. That is exactly where the next entry in the record comes from.

For businesses that would rather not keep it themselves, it is part of maintenance and included in the website subscription from the start: the data processing agreement for hosting and support is in place, the list of sub-processors is named, and the record is handed over as a table you can continue yourself. The website subscription starts at 109 euros net per month for the one-pager on the 24-month minimum term, plus a one-off setup from 390 euros net; on a twelve-month minimum term the monthly price is higher.

The effort the first time round is manageable and occurs only once. Write down five services, collect five contracts, set up a table, put a date on it. After that it is typically half an hour per quarter. If you would like to know what is actually embedded in your site, we will look at it in a short conversation and send you the list afterwards.

This article draws on data from: Regulation (EU) 2016/679 (GDPR), Articles 28, 30, 82 and 83; Guidelines 07/2020 of the European Data Protection Board on the concepts of controller and processor; short paper no. 13 of the German data protection conference on processing on behalf of a controller; 34th activity report on data protection 2025 of the Hamburg Commissioner for Data Protection and Freedom of Information. Retrieved: September 2026.

Related Articles

Hosting, security & operations

Hacked website: first steps, reporting duties, recovery

Take it offline instead of deleting, preserve traces, rotate access: the order after an attack, the Article 33 GDPR deadline and the way back into search.

13 min read
Law & data protection

Business Name and Domain: Check Trademarks First

A business name can be covered at once by a registered mark, a company sign, a personal name right and a registered firm. How to check before you commit.

14 min read
Online marketing & ads

Email Newsletters for Local Businesses Done Right

Newsletters for local businesses: consent, double opt-in, existing customers under Section 7 UWG, unsubscribe, SPF, DKIM and DMARC - and a rhythm that holds.

13 min read