Skip to content

Data Processing Agreement Guide for EU Small Businesses

A practical data processing agreement for an EU small business: map the service, compare terms, use the free Commission clauses, complete annexes and test it.

An icon-only workflow moves a small data-processing agreement through scope, instructions, safeguards, suppliers and review.
By AI Priority Map Editorial

A data processing agreement for a small business begins with facts about one service, not a downloaded signature page. The task is to make the processor relationship binding and workable from procurement through termination.

Last updated: 26 August 2026

Quick Answer

A data processing agreement for a small business must bind the processor to the real service, complete every Article 28 duty, identify the processing chain and work after signature. Compare current provider terms first; if gaps remain, use the free Commission 2021/915 clauses or a focused amendment, then test the agreed procedures.

A signature page is not the starting point

The first decision is whether the supplier is actually a processor for the activity being documented. A processor handles personal data on the controller's behalf. If the supplier decides a separate purpose for that processing, or the parties jointly determine its purposes and essential means, forcing the relationship into an Article 28 form gives the wrong answer to the right paperwork question.

Role follows the activity, not the supplier's name or profession. A single supplier can be a processor for one service and act under a different role for another. The classification record should name the activity, the party deciding why it happens, the instructions that constrain it and any purpose the supplier claims for itself. If the role is not processor, stop this procedure and choose the instrument that matches the actual relationship.

When the role is controller and processor, Article 28 requires a binding written contract or other legal act. It does not require a separate file named “DPA”. Complete provider terms incorporated into the service contract can satisfy the requirement, provided they bind the parties and cover the complete relationship 1.

The European Commission's clauses adopted by Implementing Decision (EU) 2021/915 are official and free. They can be used in whole or in part, including within a wider agreement, but their choices and annexes must describe the real service 2. They are the sensible early option when provider terms are absent or incomplete; paid drafting belongs later, after a specific gap has been demonstrated.

Map the real service before choosing paper

Build a one-page service map while procurement facts are still available. The map fixes what the agreement must govern and exposes questions that a generic template hides. The most reliable unit is the smallest one that can be described honestly: one hosted payroll service, one support desk or one mailing platform, rather than “all supplier services”.

First confirm whether the supplier is a processor for the activity, then map the real service and compare the binding terms 1. If the terms are complete, preserve the accepted version; if gaps remain, choose the narrowest lawful route and complete its annexes. Make the result binding, assign owners and test the operating procedures.

Service-map fieldRecord the operational factQuestion that reveals a gap
Purpose and operationsWhy the service is used and what happens to the dataIs any operation performed for the supplier's own purpose?
People and dataData-subject groups and personal-data typesAre sensitive or unexpectedly broad fields included?
Systems and accessApplications, interfaces, support access and user rolesWho can see live records, and under what instruction?
Locations and flowsHosting, remote access, backups and onward destinationsDoes any step cross the EEA boundary?
Duration and end eventStart, service term, retention trigger, return and deletionWhat event starts deletion, and how is completion evidenced?
Processing chainProcessor, each known subprocessor and service suppliedHow are additions or replacements notified?
Assistance routesContacts for rights, incidents, audits and changesCan a request reach a responsible person within the needed time?

The map describes the service as it exists today. Proposed changes belong in a separate field until approved and implemented. The signed annex should not promise data deletion after thirty days if backups, support copies or legal holds follow different events; a truthful exception, connected to its trigger and owner, is more useful than a precise but fictional deadline.

Compare every provider term and schedule

Build a contract inventory containing the current service contract, privacy or data terms, security schedule, subprocessor list, support rules and every document incorporated by reference. For each item, record its title, version or retrieval date, parties, covered service, method of acceptance and the clause that incorporates it. A reassuring summary page is not a binding term, and a schedule that procurement never opened can change the contract's meaning.

Resolve the document order before assessing coverage. Confirm the legal entity providing the service, the entity acting as controller, which terms prevail after a conflict and how future online changes become binding. If two documents make different promises about deletion, notice or evidence, classify that subject as conflicting even when each document looks complete on its own.

Create a gap ledger with one row for every required Article 28 subject. Mark the binding language and operational route as complete, incomplete, conflicting or absent. “Complete” means the provision applies to the mapped service, creates the duty and gives the business a usable way to invoke it. Beside every other status, name the missing fact or decision and the document that could repair it.

The completed ledger is the input to route selection. If existing terms bind the correct parties, cover the real processing and leave no required subject unresolved, another template can create conflict rather than protection. Preserve the accepted version and its incorporation evidence. If gaps remain, carry only those gaps into the Commission-clause or amendment route instead of restarting with a preferred form.

Choose among three lawful routes

Choose the narrowest route that produces one complete, coherent instrument. Cost or document length should not decide before coverage does.

RouteUse it whenWork still requiredMain failure to prevent
Complete provider termsCurrent binding terms already cover the mapped service and all Article 28 dutiesPreserve the version, complete any schedules and resolve conflictsTrusting a marketing summary or missing incorporated document
Commission 2021/915 clausesTerms are missing or a neutral official baseline is usefulSelect options, identify parties, complete annexes and bind them to the serviceTreating the free form as finished before its blanks and choices are resolved
Focused amendment or custom instrumentA demonstrated service-specific gap remains after comparisonDraft only what closes the gap, set precedence and negotiate the operational routePaying for broad drafting that duplicates or contradicts working terms

The 2021/915 clauses are designed for controller-processor relationships in the EU and EEA 3. The Commission also publishes practical material about the standard clauses 4. Their official status does not turn incomplete annexes into operational facts, and it does not change a supplier's role. The clauses provide a disciplined structure; the service map supplies the facts.

Paid legal or technical help can be proportionate where the processing is complex, negotiations are deadlocked or the service carries a risk the standard routes do not resolve. Define the question first: a conflict in deletion language, an unusual chain, missing audit evidence or a custom assistance workflow. A bounded question keeps the work tied to an identified gap.

Turn Article 28 duties into working clauses

The agreement must state the subject matter and duration of processing, its nature and purpose, the types of personal data, the categories of data subjects, and the controller's rights and duties. It must also bind the processor to documented instructions, confidentiality, security, controlled use of subprocessors, assistance, deletion or return, and audit or information duties 1.

The instruction route needs an exception path. If the processor believes an instruction infringes applicable EU or Member-State data protection law, it must inform the controller immediately. The annex should name the notification channel and controller decision owner, while the operating record preserves the affected instruction, notice time, legal concern, escalation, response and final disposition 1.

Assistance must also reach the controller's obligations under Articles 32–36, taking account of the processing and the information available to the processor. The agreed route should expressly cover security, personal-data breaches, data protection impact assessments and prior consultation. For each trigger, name the processor contact, controller owner, expected information, secure channel and evidence of the assistance provided 1.

Operational language answers who acts, through which channel, on what trigger and with what evidence. “The processor shall assist” states a duty. “The processor sends rights-request notices to [email protected], preserves the request identifier and identifies affected systems” makes the duty executable. Contact details, channels and response mechanics can sit in an annex if the binding clauses clearly incorporate it.

Required subjectAnnex detail that makes it usableEvidence to retain
Documented instructionsAuthorised operations, instruction channel and change approverApproved order, ticket or change record
Unlawful-instruction noticeImmediate-notice trigger, escalation channel and controller decision ownerInstruction reference, notice, review and final disposition
ConfidentialityAccess roles and the basis on which authorised people are boundRole list and access review output
SecurityMeasures matched to the systems, access and data in the mapControl description and relevant test or review record
Rights assistanceIntake contact, identity of affected systems and hand-off routeRequest identifier, search result and response log
Incident assistanceNotification channel, initial facts and update pathIncident notices, timestamps and investigation updates
Articles 32–36 assistanceSecurity, breach, DPIA and prior-consultation triggers, contacts and secure channelAssistance request, supplied information, dates and outcome
Deletion or returnEnd trigger, formats, exceptions, backups and confirmationReturn receipt or deletion confirmation
Audit and informationRoutine evidence, question route and escalation pathEvidence pack, answers and remediation record

A clause that neither side can follow does not make the arrangement safer. If an audit right demands a site visit while the service is entirely remote, the agreement needs an evidence route that fits the service and a way to escalate material concerns. The legal duty remains; the operating mechanism should be proportionate and real.

Complete annexes with operational facts

Annexes are the working memory of the agreement. Complete them with the service owner, someone who understands the system and the person responsible for procurement or privacy. Legal wording alone cannot identify an API export, a support engineer's access path or the event that removes an archived account.

Annex completion begins with the service map and a reconciliation against the provider's technical documents. Define personal-data types at a useful level: “customer account identifiers, delivery address and support history” is actionable; “customer data” is not. Name data-subject groups plainly and connect each processing operation to its purpose.

Security entries should describe controls that apply to the mapped service, not an aspirational catalogue. A useful entry covers relevant access restrictions, transmission and storage protections, resilience or recovery arrangements, review mechanisms and incident handling, but never claims more than the available evidence supports. Where a detail changes frequently, specify the controlled source that holds it and how changes are notified.

End-of-service instructions deserve their own walk-through. A workable entry names who requests return, the required format, when routine copies are deleted, how backups age out, what an exception means and who receives confirmation. The result should let a new employee complete termination without reconstructing the negotiation.

Control subprocessors and evidence

The processor chain must remain visible enough for the controller to assess sufficient guarantees. General written authorisation can work when the agreement gives notice of intended additions or replacements and a meaningful route to object. Specific authorisation may suit a narrower service. Whichever model is selected, record it and connect notices to an owner rather than to an unattended inbox.

When a processor appoints a subprocessor, it must impose the same data-protection obligations through a contract or other legal act. If that subprocessor fails to perform those obligations, the initial processor remains fully liable to the controller for the subprocessor's performance under Article 28(4) 1. The agreement and evidence route should make both points verifiable without assuming that the controller must collect every downstream contract.

Chain-register fieldWhat to captureReview trigger
Subprocessor and serviceLegal name and the function it performsNew supplier, replacement or material scope change
Data and accessData involved, access type and affected systemsBroader field set or new support access
LocationsHosting, remote access and onward locationNew country or routing change
Authorisation routeGeneral or specific model, notice channel and objection periodProvider changes its published process
Evidence selectedRelevant control description, report, answers or downstream termsRisk changes, evidence expires or a concern appears
Decision and ownerAccept, object, restrict or investigate; named internal ownerNotice arrives or periodic review date falls due

Evidence depth is risk-based, not optional. A controller does not need to demand every downstream contract systematically. It must understand the chain and decide case by case what evidence is enough, considering the processing and the available assurances 6. A low-risk tool may support a lighter evidence set; a complex chain with broad access may justify targeted terms, reports or technical answers.

Route each change notice into a decision record. Silence should never happen because a notice went to the employee who originally bought the tool and has since left. Each record captures receipt, the changed fact, risk considered, evidence reviewed, decision, conditions and approver.

Keep transfers in a separate lane

Article 28 and international-transfer compliance answer different questions. The agreement governs processing on the controller's behalf. Chapter V governs certain transfers of personal data outside the EEA. Commission Decision 2021/915 supplies Article 28 controller-processor clauses; it does not by itself provide the answer to a Chapter V transfer requirement 2.

The service and chain maps locate hosting, remote support, backups and onward access. If a transfer question appears, open a separate assessment and record its mechanism and safeguards there. Link the outcome back to the agreement only where needed for instructions, locations, change control or termination.

A vague promise that the processor “complies with GDPR” does not perform the transfer analysis. The processor chain can change after signature, so location and onward-transfer notices need an owner and a review trigger. Keeping the lanes separate makes both easier to update without pretending one clause performs two legal jobs.

Make the agreement binding and assign owners

A finished draft must become binding on the correct entities. Confirm names, company details, authority to sign, effective date, service scope, incorporated schedules and order of precedence. Where provider terms are accepted online, preserve the version and the evidence that the controller accepted them for the service.

Assign an internal service owner and a privacy or compliance contact. The operating record identifies processor contacts for rights requests, incidents, security evidence, subprocessor notices and termination. One contact can cover several routes, but each route needs a named channel, an alternative if it fails and an internal person responsible for watching it.

Brief the people who will operate the terms. Procurement needs the change and renewal triggers. The support team needs the rights and incident routes. The system owner needs deletion, access and evidence duties. A signature creates enforceable commitments; it does not prove that a mailbox is monitored or a return process works.

Test it after signature

Test the agreement with short tabletop exercises before a real request, incident or termination makes the first attempt urgent. Tabletop exercises use invented records; testing a channel does not justify exposing live personal data.

TestWalk throughRecord a usable result
Rights requestSend a simulated request reference and identify affected systemsRoute, owner, acknowledgement, search result and delay found
Personal-data breachSend an incident scenario through the agreed notification channelReceipt time, initial facts, update route and missing contact
Subprocessor changeReview a sample notice against the authorisation modelEvidence sought, objection route, decision and approver
Evidence requestAsk for one risk-relevant control explanation or recordMaterial received, reviewer, gap and follow-up
End of serviceSimulate return, account closure, routine deletion and backup ageingInstructions, formats, exceptions, confirmation and owner

A failed tabletop is useful when it identifies a repair before harm occurs. Update the contact, clause, annex or internal procedure that caused the failure, then repeat that test. Preserve the result with the agreement so the next reviewer can distinguish an untested promise from a route that has worked.

If the supplier refuses, climb a fixed ladder

Refusal is a gap to diagnose, not a cue to invent consent or accept an unsigned template. The EDPB's small-business materials recognise the practical supplier problem and the need to resolve the processor arrangement 5. A fixed sequence prevents commercial pressure from erasing the legal question.

Ladder stepActionExit condition
VerifyAsk for the current binding data terms and all incorporated schedulesStop if they are complete and match the service
IdentifyList the exact missing or conflicting Article 28 subjectsContinue with a bounded gap, not “we need our paper”
OfferPropose the free 2021/915 clauses or a focused amendmentStop when one coherent instrument closes the gap
EscalatePut the gap to a supplier decision-maker and the controller's business ownerRecord the response, risk and decision deadline
RedesignRemove personal data, restrict access, change the feature or choose another supplierStop if the supplier is no longer a processor for that activity
StopDo not start, or discontinue, the processing through that supplierUse when the Article 28 gap remains

A supplier can reject the controller's preferred document and still offer complete binding terms. Duplicating those terms can create ambiguity. Conversely, a security page, privacy notice or statement of good intentions is not a substitute if it does not form a binding, complete processor arrangement.

Keep the agreement alive

Review on change, not only on an annual calendar. Triggers include a new service feature, broader personal-data fields, new access roles, a subprocessor notice, a location change, updated provider terms, an incident, failed evidence, renewal or termination. A light periodic review can still catch silent drift where no one reported an event.

One agreement record should contain the service map, binding terms and version, completed annexes, chain register, selected evidence, owner and contact list, test results, changes and unresolved actions. It should show what changed, why it matters, who decided and when the next action is due.

The practical finish line is not a document labelled “DPA”. It is a mapped processor service governed by complete binding terms, with a known chain, usable evidence, assigned contacts and tested procedures. If those elements remain true as the service changes, the agreement is operating rather than merely stored.

Frequently Asked Questions

Does every small business need a data processing agreement?
No. A small business needs an Article 28 agreement for an activity when another organisation processes personal data on its behalf as a processor. The role is decided per activity. If the supplier determines a separate purpose, or both parties jointly determine the processing, an Article 28 processor agreement is not the correct instrument.
Is the European Commission data processing agreement free?
Yes. The clauses adopted by Commission Implementing Decision (EU) 2021/915 are an official, free option for controller-processor relationships in the EU and EEA. They still require work: select the relevant options, complete the annexes for the actual service, and place them within a binding arrangement between the correct parties.
Must the agreement be a separate document called a DPA?
No. Article 28 requires a binding written contract or other legal act, not a particular filename. A service agreement, incorporated provider terms or another binding instrument can be enough when it contains the complete required terms and clearly applies to the service. Check every incorporated schedule and referenced policy before relying on that route.
Can Commission 2021/915 clauses cover international transfers?
Not by themselves. The 2021/915 clauses govern the Article 28 relationship between a controller and a processor. A transfer of personal data outside the European Economic Area raises a separate Chapter V question. Record locations and onward transfers, then assess and document the relevant transfer mechanism in its own workstream.
What belongs in a data processing agreement annex?
The annex should describe the real service: subject matter, duration, purposes, processing operations, personal-data types, data-subject categories, systems, locations, access roles, deletion or return events, security measures, subprocessors, assistance contacts and evidence routes. Generic labels are rarely enough to operate access requests, incidents, audits or termination safely.
Does a controller need every subprocessor contract?
Not systematically. The controller must understand the processor chain, assess sufficient guarantees and decide what evidence is needed for the particular risk. That may include selected downstream terms, independent reports, control descriptions or targeted answers. Low risk can justify lighter verification, but it does not remove the controller's responsibility to make the assessment.
What should a small business do when a supplier refuses to sign?
First check whether complete binding provider terms already exist. If they do not, offer the official free Commission clauses or a focused amendment that closes the identified gaps. Escalate to a commercial decision-maker, consider redesigning the service to remove the processing, and stop using the supplier for that activity if the Article 28 gap remains.
Is signing the agreement enough for GDPR compliance?
No. A signature makes agreed terms binding; it does not prove that the described controls exist or that the parties follow them. Assign owners, record contacts and notice periods, then test rights requests, breach notification, subprocessor changes, evidence access and deletion or return. Review the agreement whenever the service or processor chain changes.

Sources

  1. 1.Regulation (EU) 2016/679EUR-Lex · 2016
  2. 2.Commission Implementing Decision (EU) 2021/915EUR-Lex · 2021
  3. 3.European Commission: Standard contractual clauses between controllers and processors in the EU/EEAEuropean Commission
  4. 4.European Commission: Questions and Answers on Standard Contractual ClausesEuropean Commission
  5. 5.European Data Protection Board: SME data protection guide FAQEDPB
  6. 6.European Data Protection Board Opinion 22/2024EDPB · 2024

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.