The call usually comes on a Monday. The supervisory authority has written, not because of an incident but because of a complaint: someone used the contact form and wanted to know where their message ends up and who can read it on the way. The answer is written down nowhere. The website runs with one provider, the form sends through a second, appointments sit in a third, the newsletter in a fourth, and the map on the contact page loads from a fifth. Five places where visitor data is processed, and for three of them no contractual arrangement exists. This article shows which of these services count as processing on your behalf, what the contract has to contain, how sub-processors fit in, and how the same list turns into the record you can hand to an authority.
Key takeaways
- Not every service provider behind a website is a processor. What matters is whether it processes personal data on your instructions or pursues purposes of its own.
- Article 28(3) GDPR lists eight points the contract has to cover at minimum: from documented instructions through confidentiality to deletion once the service ends.
- If the contract is missing, the guidelines of the European Data Protection Board treat that as an infringement in itself, regardless of whether anything happened to the data.
- Sub-processors need authorisation. Under the usual general authorisation the provider has to announce every change and leave you the opportunity to object.
- The record of processing activities under Article 30 GDPR falls out almost as a by-product once the services are listed cleanly. The exemption for businesses under 250 employees rarely applies to a live website.
Five services, five contracts
A website is rarely a single piece of technology today. It is a set of services running in different places and connected through the page. To the visitor it looks like one thing. In legal terms there are as many relationships as there are services involved. Someone filling in the form hands their name to the business, their message to its form provider, their network address to the data centre and, if a map is embedded, their page request to the map service as well. Four recipients for one click.
For each of those recipients the first question is the same: is it acting on your instructions, or is it acting for itself? That is not an academic distinction. It decides whether a data processing agreement is needed, whether a separate legal basis is required, and who is liable when something goes wrong. In its short paper on processing on behalf of a controller, the German data protection conference explicitly names the outsourcing of email administration or of other data services for websites, giving the operation of contact forms or user enquiries as its example (Datenschutzkonferenz), as a typical case. The form on the contact page is therefore not a borderline case but the textbook one.
The topic looks technical but has a very practical side. The Hamburg Commissioner for Data Protection and Freedom of Information examined 1,000 randomly selected websites of operators based in Hamburg without any specific trigger. In 185 out of 1,000 cases (HmbBfDI) the operators had to make corrections. The authority describes the reason plainly: many operators do not know the requirements for embedding external services, or do not implement them. Anyone who has already sorted out consent in the cookie banner has done one half. The other half is the contract with whoever processes the data afterwards.
The number of complaints is rising noticeably. In Hamburg alone more than 4,200 data protection complaints (HmbBfDI) were received in 2025, a good sixty percent more than the year before according to the authority. A complaint is not a fine procedure, but it leads to an enquiry, and that enquiry wants an answer. Anyone able to present a list of their services together with the contracts has a short case. Anyone who has to assemble it first has a long one. The mandatory details in the legal notice are the visible part of these duties, the contracts the invisible one.
When a provider counts as a processor
A processor processes personal data on behalf of a controller. The controller determines purposes and means, the processor carries them out. As soon as a service provider starts pursuing purposes of its own, the relationship flips. Article 28(10) GDPR is clear on this point: a processor that infringes the regulation by determining the purposes and means of processing is considered a controller in respect of that processing (GDPR) and carries a controller's duties accordingly.
In practice the distinction is easier than it sounds once you know two edge cases. The first: anyone working exclusively on the infrastructure, without access to content, is not a processor. The data protection conference names work on power supply, cooling and heating as its example (Datenschutzkonferenz). The second: professionals bound by secrecy such as tax advisers, lawyers or auditors are, according to the same paper, generally controllers in their own right rather than processors (Datenschutzkonferenz). Almost everything attached to a website sits between those two poles, and most of it sits closer to the first case than to the second.
The hosting provider is the clearest case. It stores your database, your log files and your mailboxes, it sees your visitors' network addresses, and it does so for you, not for itself. Anyone working through server location and backup arrangements while choosing a hosting provider should tick off the data processing agreement in the same pass. Reputable providers keep it ready in the customer account, where it only needs to be accepted and filed.
- The service processes data originating from your visitors or customers.
- It does so because you commissioned it, not on its own initiative.
- You determine what the data is used for and how long it stays.
- The service may not use the data for its own analyses, its own advertising or its own products.
- If one of these statements falls away, it is not processing on your behalf but something else that needs its own assessment.
Since the Regulation establishes a clear obligation to enter into a written contract, where no other relevant legal act is in force, the absence thereof is an infringement of the GDPR.
What the contract has to contain
Article 28(3) GDPR describes the frame first and the content second. The frame: subject matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. Then follow eight points (GDPR) the contract has to stipulate in addition. Those eight points are the actual yardstick, and they can be held against any template contract in a few minutes.
In the order of the law they are: processing only on documented instructions, a commitment to confidentiality from the people involved, the measures required under Article 32, the conditions for engaging another processor, assistance with data subject rights, assistance with notification duties and impact assessments, deletion or return once the service ends, and finally the proof. The last point is the one most often overlooked and the most important in practice.
- Processing only on documented instructions, including for transfers to a third country.
- A confidentiality commitment from everyone with access to the data.
- Technical and organisational measures under Article 32 GDPR.
- Compliance with the conditions for engaging another processor.
- Assistance with data subject requests for access, rectification or erasure.
- Assistance with notification duties, security measures and data protection impact assessments.
- Deletion or return of all data once the service ends, at your choice.
- Provision of all proof and facilitation of audits, including inspections.
The eighth point gives you a right many businesses rarely exercise and still need in the contract: the processor has to make available all information necessary to demonstrate compliance and to allow for and contribute to audits, including inspections (GDPR). In practice that rarely means a visit to the data centre. It means the provider describes its measures on request and makes existing audit reports accessible. A contract that excludes this right, or ties it to conditions nobody can meet, does not satisfy Article 28(3).
Formally, electronic form is enough: the contract has to be in writing, including in electronic form (GDPR). An accepted agreement in the customer account therefore suffices, as long as it remains retrievable. The European Data Protection Board additionally recommends bringing the elements implementing Article 28 together in one place, for example in an annex, so that demonstrating compliance becomes easier (European Data Protection Board). That is exactly how we set it up in projects covered by our services: one folder, one overview, one date per contract.
Sub-processors: the second row
Hardly any service provider works alone. The form provider sends through a mail dispatcher, the mail dispatcher runs in a data centre, the data centre buys in storage. The regulation calls this chain “another processor”, everyday language calls it a sub-processor. Article 28(2) GDPR requires prior specific or general written authorisation of the controller for it (GDPR). Without that authorisation the second row may not touch the data.
In practice almost every provider works with the general authorisation. It usually appears as a list in the contract or on a linked subpage. To serve its purpose, the law attaches a condition: the processor has to inform the controller of any intended changes so that the controller has the opportunity to object (GDPR). Anyone who does not read those announcements loses the right in fact, without ever having given it up.
The second row deserves attention for a practical reason too: this is often where the question of the processing location is decided. A provider with a German server location may use a sub-processor for backups that sits elsewhere. That is precisely why the list of sub-processors belongs to every contract we hand over for hosting in Germany, and why it is checked rather than merely supplied.
| Specific authorisation | General authorisation | |
|---|---|---|
| How it comes about | You expressly agree to one individual sub-processor | You agree to a list that is allowed to change |
| How common it is | Rare, mostly for sensitive processing | The normal case for standard services |
| Your duty afterwards | Agree again when a provider is added | Read and assess the change notifications |
| The provider's duty | Ask beforehand | Announce every intended change |
| Your leverage in a dispute | Withhold agreement | Object, and terminate if necessary |
The five services of a typical website
The following five services appear on almost every local business website. They differ in how visible they are, but all five process personal data, and all five belong in the same list. A sixth row is usually added by your own provider for backups and maintenance, the one nobody sees from outside. Once these rows have been written down completely, the larger part of the work is behind you.
Web hosting
Stores files, database and logs. Sees network addresses, timestamps and requested pages. A classic case of processing on your behalf; most providers keep the contract ready in the customer account.
Contact form
Receives names, messages and often attachments and forwards them. Explicitly named by the German data protection conference as processing on behalf. Check: where is the message stored in the meantime, and for how long?
Appointment booking
Processes name, contact route and time slot, and for medical practices health-related context as well. Needs a contract and a clear rule on which reminders are permissible without separate consent.
Newsletter
Stores address, sign-up time and proof of consent, usually open and click data too. That proof is part of the commissioned data and has to come back when the contract ends.
Map service
Loads from an external source on page view and transmits network address and browser data in the process. Often not plain processing on behalf but a transfer requiring its own assessment.
Backups and maintenance
Anyone creating backups, applying updates or hunting for faults sees data while doing so. Your own service provider therefore needs a contract too, not only a password.
The map service is the case most often classified incorrectly. If a map is loaded directly into the page, the visitor's network address goes to the provider before anyone has clicked. Whether that still counts as processing on your behalf or already as a transfer to an independent controller depends on what the provider does with the data. In both cases the same holds: the request needs a basis, and the map belongs in the list. A static directions graphic with a link to a map service avoids that request and costs less loading time.
Appointment booking has an edge of its own where health data is involved. The Hamburg Commissioner for Data Protection and Freedom of Information notes that the German data protection conference adopted a position paper on the use of service providers for online appointment booking on 16 June 2025 (HmbBfDI). Among other things it follows from that paper that arranging an appointment is part of the treatment, whereas sending appointment messages is to be permitted only with express consent (HmbBfDI). Anyone running a practice website should be able to trace that separation in the booking tool.
With the newsletter the core lies elsewhere. Here the sending is not the problem, the proof is: who consented when and how has to remain demonstrable, and that evidence sits with the service provider. When the contract ends it has to come back or be deleted, at your choice rather than theirs. That is exactly the seventh of the eight points. Incidentally, anyone who publishes prices on the website receives fewer but clearer enquiries. It changes nothing about the data route: they run through the same services and belong in the same list.
The record under Article 30
Once the five services are on the table, the record of processing activities is no longer a separate project but a different view of the same data. Article 30(1) GDPR requires, for each processing activity, details of the controller, the purposes, the categories of data subjects and of data, the recipients, transfers to third countries, erasure periods and a general description of the measures (GDPR). That is a table with seven columns, no more.
Many businesses hope for the exemption at this point. Article 30(5) GDPR exempts enterprises with fewer than 250 employees (GDPR) from the obligation, but under three conditions that all have to be met at once: the processing must not pose a risk to rights and freedoms, it must be occasional only, and it must not include special categories of data. A website that receives enquiries every day does not process occasionally. In a running operation the exemption therefore usually ends at the second condition.
The record has to be kept in writing, including in electronic form, and made available to the supervisory authority on request (GDPR). “On request” means at short notice. A table that sits in the folder and is touched once a year serves that purpose. A table that only comes into being after the enquiry does not, and it shows. Anyone who wants to clarify who owns the domain and the access credentials anyway can do both in one pass: the list of credentials and the list of processing activities concern the same services.
The exemption that rarely applies
Processing: contact enquiries through the form
Purpose: answering enquiries, steps prior to entering into a contract
Legal basis: Article 6(1)(b) GDPR
Data subjects: prospects, customers
Data categories: name, e-mail, phone, message text, attachments
Recipients: form provider (processor), hosting provider (processor)
Third country: no
Erasure period: 6 months after the matter is closed
Measures: transport encryption, office access only, daily backup
Contract: data processing agreement of 12 March 2026, filed under Legal/DPA/Checking instead of signing
A contract nobody has read is a file reference, not a safeguard. Checking a standard contract typically takes a quarter of an hour, and it pays off because the deviations repeat themselves. Most frequently missing or shortened is the proof point, followed by the arrangement for deletion and the list of sub-processors. Anyone laying the eight points beside the contract as a checklist finds the gaps without legal training.
The second part of the check is technical and goes faster. You need a list of every external address your page contacts when it loads. That list is the counter-check to the contract folder: every external address needs either a contract, a legal basis of its own, or a reason why it is still embedded. Not seldom a service surfaces that somebody added three years ago and then forgot.
- Is there a contract for every external service, dated and filed?
- Does the contract name all eight points from Article 28(3) GDPR?
- Is there a list of sub-processors, and how are changes announced?
- Is it settled what happens to the data at the end, and who chooses between deletion and return?
- Does the privacy policy match the contract folder, or does one of the two name services the other does not know?
- Does every service appear in the record with its purpose, data categories and erasure period?
What a missing contract sets off
The consequences of a missing contract tend to be taken seriously too late because they sound abstract. They are not. Infringements of the obligations under Article 28 fall within the frame of Article 83(4) GDPR: administrative fines of up to 10 million euros (GDPR) or, in the case of an undertaking, up to 2 percent (GDPR) of its total worldwide annual turnover of the preceding financial year, whichever is higher. For a local business the upper limit is not the relevant figure, but the fact that an authority has the choice certainly is.
More important day to day is the second consequence. Under Article 82(1) GDPR any person who has suffered material or non-material damage as a result of an infringement has the right to compensation from the controller or the processor (GDPR). The controller is liable for damage caused by processing that does not comply with the regulation, whereas the processor answers only under narrower conditions. Without a contract that allocation is hard to set out in a dispute.
The third consequence is the quietest and hits most often: without a contract there is no claim to information and handover. If a service provider is no longer reachable or a switch is due, the contract decides whether you get your data back. It is the same mechanism as with moving website and mailboxes: what is settled in writing beforehand is a matter of hours afterwards. What is not settled becomes a matter of weeks.
The yearly rhythm
Having the contracts is one part, keeping them current is the other. Providers change their sub-processors, businesses embed new services, old tools disappear. A data protection setup without upkeep typically goes stale within a year, and precisely at the points that were worked through most thoroughly at the start.
With us that hangs off website maintenance and runs in a fixed rhythm: once a quarter the list of embedded services is checked against the page source, once a year the contracts and the record are worked through, and with every change to the site the question is asked whether a new recipient has appeared. Anyone who sets up seasonal pages before the season often embeds an additional form or booking route while doing so. That is exactly where the next entry in the record comes from.
For businesses that would rather not keep it themselves, it is part of maintenance and included in the website subscription from the start: the data processing agreement for hosting and support is in place, the list of sub-processors is named, and the record is handed over as a table you can continue yourself. The website subscription starts at 109 euros net per month for the one-pager on the 24-month minimum term, plus a one-off setup from 390 euros net; on a twelve-month minimum term the monthly price is higher.
The effort the first time round is manageable and occurs only once. Write down five services, collect five contracts, set up a table, put a date on it. After that it is typically half an hour per quarter. If you would like to know what is actually embedded in your site, we will look at it in a short conversation and send you the list afterwards.
Related Articles
Hacked website: first steps, reporting duties, recovery
Take it offline instead of deleting, preserve traces, rotate access: the order after an attack, the Article 33 GDPR deadline and the way back into search.
Business Name and Domain: Check Trademarks First
A business name can be covered at once by a registered mark, a company sign, a personal name right and a registered firm. How to check before you commit.
Email Newsletters for Local Businesses Done Right
Newsletters for local businesses: consent, double opt-in, existing customers under Section 7 UWG, unsubscribe, SPF, DKIM and DMARC - and a rhythm that holds.