If a vendor handles personal data for you, GDPR requires a written DPA that limits the vendor to your instructions and sets security, confidentiality and deletion duties.
Key points
- Under GDPR Article 28(3), processing by a processor must be governed by a contract or other legal act that is binding on the processor [1].
- The contract must set out the subject matter, duration, nature and purpose of processing, the types of Personal Data and categories of data subjects, and the controller's rights [1].
- Mandatory terms include acting only on documented instructions, confidentiality, security measures, rules for sub-processors, help with data subject rights, and deletion or return of data at the end [1][2].
- The European Commission has published standard contractual clauses that controllers and processors can use to meet Article 28 [3].
- Typical processors in Outbound Sales include a CRM (Customer Relationship Management), an Email Service Provider (ESP), and enrichment or Workflow Automation tools [2].
- The EDPB guidelines on controller and processor roles explain how to decide who is which, which determines whether a DPA is needed [4].
Controllers, processors and why a DPA is needed
The GDPR separates the organization that decides why and how data is processed, the controller, from one that processes data on its behalf, the processor [4]. A sales team that uploads its Lead List to a CRM (Customer Relationship Management) is the controller; the CRM vendor is usually a processor. Article 28 says a controller may only use processors that give sufficient guarantees of appropriate technical and organizational measures, and that the relationship must be governed by a binding contract [1]. That contract is the DPA. It protects the people whose data is shared, since the processor cannot reuse the data for its own purposes, and it protects the controller, which remains accountable for how its vendors behave. The ICO notes that processors also have direct obligations and can be held liable [2].
What a DPA must contain
Article 28(3) lists the required terms [1]. The processor must process data only on the controller's documented instructions, including for international transfers. Staff with access must be bound by confidentiality. The processor must apply the security measures in Article 32, and it may use a sub-processor only with the controller's authorization and on the same terms. It must help the controller respond to data subject requests, such as access or the Right to Erasure, and assist with security, breach notification and impact assessments. At the end of the service it must delete or return the data. Finally, it must provide the information needed to show compliance and allow audits. The Commission's standard contractual clauses cover all of these and can be adopted as they are [3].
Reviewing DPAs for your sales stack
Most software vendors publish a standard DPA, often built into their terms. When reviewing one, check the list of sub-processors and how you are notified of changes, where data is stored and how international transfers are covered, the security measures described, breach notification timelines, and what happens to data when you cancel [1][2]. Map every tool that touches prospect data, from the Email Service Provider (ESP) and CRM (Customer Relationship Management) to enrichment and Webhook integrations, and keep a copy of each DPA with your record of processing. A DPA does not make processing lawful by itself; you still need a lawful basis such as Legitimate Interest and should apply Data Minimization to what you share. This is general information, not legal advice.
- Art. 28 GDPR — Processor — gdpr-info.eu
- Contracts and liabilities between controllers and processors — Information Commissioner's Office
- Standard contractual clauses for controllers and processors in the EU/EEA — European Commission
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR — European Data Protection Board
Related terms
Outreach without the busywork.
PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.
Start free with 100 credits →