Data Processing Agreement Guide for EU Small Businesses
A practical data processing agreement for an EU small business: map the service, compare terms, use the free Commission clauses, complete annexes and test it.

A data processing agreement for a small business begins with facts about one service, not a downloaded signature page. The task is to make the processor relationship binding and workable from procurement through termination.
Last updated: 26 August 2026
Quick Answer
A data processing agreement for a small business must bind the processor to the real service, complete every Article 28 duty, identify the processing chain and work after signature. Compare current provider terms first; if gaps remain, use the free Commission 2021/915 clauses or a focused amendment, then test the agreed procedures.
A signature page is not the starting point
The first decision is whether the supplier is actually a processor for the activity being documented. A processor handles personal data on the controller's behalf. If the supplier decides a separate purpose for that processing, or the parties jointly determine its purposes and essential means, forcing the relationship into an Article 28 form gives the wrong answer to the right paperwork question.
Role follows the activity, not the supplier's name or profession. A single supplier can be a processor for one service and act under a different role for another. The classification record should name the activity, the party deciding why it happens, the instructions that constrain it and any purpose the supplier claims for itself. If the role is not processor, stop this procedure and choose the instrument that matches the actual relationship.
When the role is controller and processor, Article 28 requires a binding written contract or other legal act. It does not require a separate file named “DPA”. Complete provider terms incorporated into the service contract can satisfy the requirement, provided they bind the parties and cover the complete relationship 1.
The European Commission's clauses adopted by Implementing Decision (EU) 2021/915 are official and free. They can be used in whole or in part, including within a wider agreement, but their choices and annexes must describe the real service 2. They are the sensible early option when provider terms are absent or incomplete; paid drafting belongs later, after a specific gap has been demonstrated.
Map the real service before choosing paper
Build a one-page service map while procurement facts are still available. The map fixes what the agreement must govern and exposes questions that a generic template hides. The most reliable unit is the smallest one that can be described honestly: one hosted payroll service, one support desk or one mailing platform, rather than “all supplier services”.
First confirm whether the supplier is a processor for the activity, then map the real service and compare the binding terms 1. If the terms are complete, preserve the accepted version; if gaps remain, choose the narrowest lawful route and complete its annexes. Make the result binding, assign owners and test the operating procedures.
| Service-map field | Record the operational fact | Question that reveals a gap |
|---|---|---|
| Purpose and operations | Why the service is used and what happens to the data | Is any operation performed for the supplier's own purpose? |
| People and data | Data-subject groups and personal-data types | Are sensitive or unexpectedly broad fields included? |
| Systems and access | Applications, interfaces, support access and user roles | Who can see live records, and under what instruction? |
| Locations and flows | Hosting, remote access, backups and onward destinations | Does any step cross the EEA boundary? |
| Duration and end event | Start, service term, retention trigger, return and deletion | What event starts deletion, and how is completion evidenced? |
| Processing chain | Processor, each known subprocessor and service supplied | How are additions or replacements notified? |
| Assistance routes | Contacts for rights, incidents, audits and changes | Can a request reach a responsible person within the needed time? |
The map describes the service as it exists today. Proposed changes belong in a separate field until approved and implemented. The signed annex should not promise data deletion after thirty days if backups, support copies or legal holds follow different events; a truthful exception, connected to its trigger and owner, is more useful than a precise but fictional deadline.
Compare every provider term and schedule
Build a contract inventory containing the current service contract, privacy or data terms, security schedule, subprocessor list, support rules and every document incorporated by reference. For each item, record its title, version or retrieval date, parties, covered service, method of acceptance and the clause that incorporates it. A reassuring summary page is not a binding term, and a schedule that procurement never opened can change the contract's meaning.
Resolve the document order before assessing coverage. Confirm the legal entity providing the service, the entity acting as controller, which terms prevail after a conflict and how future online changes become binding. If two documents make different promises about deletion, notice or evidence, classify that subject as conflicting even when each document looks complete on its own.
Create a gap ledger with one row for every required Article 28 subject. Mark the binding language and operational route as complete, incomplete, conflicting or absent. “Complete” means the provision applies to the mapped service, creates the duty and gives the business a usable way to invoke it. Beside every other status, name the missing fact or decision and the document that could repair it.
The completed ledger is the input to route selection. If existing terms bind the correct parties, cover the real processing and leave no required subject unresolved, another template can create conflict rather than protection. Preserve the accepted version and its incorporation evidence. If gaps remain, carry only those gaps into the Commission-clause or amendment route instead of restarting with a preferred form.
Choose among three lawful routes
Choose the narrowest route that produces one complete, coherent instrument. Cost or document length should not decide before coverage does.
| Route | Use it when | Work still required | Main failure to prevent |
|---|---|---|---|
| Complete provider terms | Current binding terms already cover the mapped service and all Article 28 duties | Preserve the version, complete any schedules and resolve conflicts | Trusting a marketing summary or missing incorporated document |
| Commission 2021/915 clauses | Terms are missing or a neutral official baseline is useful | Select options, identify parties, complete annexes and bind them to the service | Treating the free form as finished before its blanks and choices are resolved |
| Focused amendment or custom instrument | A demonstrated service-specific gap remains after comparison | Draft only what closes the gap, set precedence and negotiate the operational route | Paying for broad drafting that duplicates or contradicts working terms |
The 2021/915 clauses are designed for controller-processor relationships in the EU and EEA 3. The Commission also publishes practical material about the standard clauses 4. Their official status does not turn incomplete annexes into operational facts, and it does not change a supplier's role. The clauses provide a disciplined structure; the service map supplies the facts.
Paid legal or technical help can be proportionate where the processing is complex, negotiations are deadlocked or the service carries a risk the standard routes do not resolve. Define the question first: a conflict in deletion language, an unusual chain, missing audit evidence or a custom assistance workflow. A bounded question keeps the work tied to an identified gap.
Turn Article 28 duties into working clauses
The agreement must state the subject matter and duration of processing, its nature and purpose, the types of personal data, the categories of data subjects, and the controller's rights and duties. It must also bind the processor to documented instructions, confidentiality, security, controlled use of subprocessors, assistance, deletion or return, and audit or information duties 1.
The instruction route needs an exception path. If the processor believes an instruction infringes applicable EU or Member-State data protection law, it must inform the controller immediately. The annex should name the notification channel and controller decision owner, while the operating record preserves the affected instruction, notice time, legal concern, escalation, response and final disposition 1.
Assistance must also reach the controller's obligations under Articles 32–36, taking account of the processing and the information available to the processor. The agreed route should expressly cover security, personal-data breaches, data protection impact assessments and prior consultation. For each trigger, name the processor contact, controller owner, expected information, secure channel and evidence of the assistance provided 1.
Operational language answers who acts, through which channel, on what trigger and with what evidence. “The processor shall assist” states a duty. “The processor sends rights-request notices to [email protected], preserves the request identifier and identifies affected systems” makes the duty executable. Contact details, channels and response mechanics can sit in an annex if the binding clauses clearly incorporate it.
| Required subject | Annex detail that makes it usable | Evidence to retain |
|---|---|---|
| Documented instructions | Authorised operations, instruction channel and change approver | Approved order, ticket or change record |
| Unlawful-instruction notice | Immediate-notice trigger, escalation channel and controller decision owner | Instruction reference, notice, review and final disposition |
| Confidentiality | Access roles and the basis on which authorised people are bound | Role list and access review output |
| Security | Measures matched to the systems, access and data in the map | Control description and relevant test or review record |
| Rights assistance | Intake contact, identity of affected systems and hand-off route | Request identifier, search result and response log |
| Incident assistance | Notification channel, initial facts and update path | Incident notices, timestamps and investigation updates |
| Articles 32–36 assistance | Security, breach, DPIA and prior-consultation triggers, contacts and secure channel | Assistance request, supplied information, dates and outcome |
| Deletion or return | End trigger, formats, exceptions, backups and confirmation | Return receipt or deletion confirmation |
| Audit and information | Routine evidence, question route and escalation path | Evidence pack, answers and remediation record |
A clause that neither side can follow does not make the arrangement safer. If an audit right demands a site visit while the service is entirely remote, the agreement needs an evidence route that fits the service and a way to escalate material concerns. The legal duty remains; the operating mechanism should be proportionate and real.
Complete annexes with operational facts
Annexes are the working memory of the agreement. Complete them with the service owner, someone who understands the system and the person responsible for procurement or privacy. Legal wording alone cannot identify an API export, a support engineer's access path or the event that removes an archived account.
Annex completion begins with the service map and a reconciliation against the provider's technical documents. Define personal-data types at a useful level: “customer account identifiers, delivery address and support history” is actionable; “customer data” is not. Name data-subject groups plainly and connect each processing operation to its purpose.
Security entries should describe controls that apply to the mapped service, not an aspirational catalogue. A useful entry covers relevant access restrictions, transmission and storage protections, resilience or recovery arrangements, review mechanisms and incident handling, but never claims more than the available evidence supports. Where a detail changes frequently, specify the controlled source that holds it and how changes are notified.
End-of-service instructions deserve their own walk-through. A workable entry names who requests return, the required format, when routine copies are deleted, how backups age out, what an exception means and who receives confirmation. The result should let a new employee complete termination without reconstructing the negotiation.
Control subprocessors and evidence
The processor chain must remain visible enough for the controller to assess sufficient guarantees. General written authorisation can work when the agreement gives notice of intended additions or replacements and a meaningful route to object. Specific authorisation may suit a narrower service. Whichever model is selected, record it and connect notices to an owner rather than to an unattended inbox.
When a processor appoints a subprocessor, it must impose the same data-protection obligations through a contract or other legal act. If that subprocessor fails to perform those obligations, the initial processor remains fully liable to the controller for the subprocessor's performance under Article 28(4) 1. The agreement and evidence route should make both points verifiable without assuming that the controller must collect every downstream contract.
| Chain-register field | What to capture | Review trigger |
|---|---|---|
| Subprocessor and service | Legal name and the function it performs | New supplier, replacement or material scope change |
| Data and access | Data involved, access type and affected systems | Broader field set or new support access |
| Locations | Hosting, remote access and onward location | New country or routing change |
| Authorisation route | General or specific model, notice channel and objection period | Provider changes its published process |
| Evidence selected | Relevant control description, report, answers or downstream terms | Risk changes, evidence expires or a concern appears |
| Decision and owner | Accept, object, restrict or investigate; named internal owner | Notice arrives or periodic review date falls due |
Evidence depth is risk-based, not optional. A controller does not need to demand every downstream contract systematically. It must understand the chain and decide case by case what evidence is enough, considering the processing and the available assurances 6. A low-risk tool may support a lighter evidence set; a complex chain with broad access may justify targeted terms, reports or technical answers.
Route each change notice into a decision record. Silence should never happen because a notice went to the employee who originally bought the tool and has since left. Each record captures receipt, the changed fact, risk considered, evidence reviewed, decision, conditions and approver.
Keep transfers in a separate lane
Article 28 and international-transfer compliance answer different questions. The agreement governs processing on the controller's behalf. Chapter V governs certain transfers of personal data outside the EEA. Commission Decision 2021/915 supplies Article 28 controller-processor clauses; it does not by itself provide the answer to a Chapter V transfer requirement 2.
The service and chain maps locate hosting, remote support, backups and onward access. If a transfer question appears, open a separate assessment and record its mechanism and safeguards there. Link the outcome back to the agreement only where needed for instructions, locations, change control or termination.
A vague promise that the processor “complies with GDPR” does not perform the transfer analysis. The processor chain can change after signature, so location and onward-transfer notices need an owner and a review trigger. Keeping the lanes separate makes both easier to update without pretending one clause performs two legal jobs.
Make the agreement binding and assign owners
A finished draft must become binding on the correct entities. Confirm names, company details, authority to sign, effective date, service scope, incorporated schedules and order of precedence. Where provider terms are accepted online, preserve the version and the evidence that the controller accepted them for the service.
Assign an internal service owner and a privacy or compliance contact. The operating record identifies processor contacts for rights requests, incidents, security evidence, subprocessor notices and termination. One contact can cover several routes, but each route needs a named channel, an alternative if it fails and an internal person responsible for watching it.
Brief the people who will operate the terms. Procurement needs the change and renewal triggers. The support team needs the rights and incident routes. The system owner needs deletion, access and evidence duties. A signature creates enforceable commitments; it does not prove that a mailbox is monitored or a return process works.
Test it after signature
Test the agreement with short tabletop exercises before a real request, incident or termination makes the first attempt urgent. Tabletop exercises use invented records; testing a channel does not justify exposing live personal data.
| Test | Walk through | Record a usable result |
|---|---|---|
| Rights request | Send a simulated request reference and identify affected systems | Route, owner, acknowledgement, search result and delay found |
| Personal-data breach | Send an incident scenario through the agreed notification channel | Receipt time, initial facts, update route and missing contact |
| Subprocessor change | Review a sample notice against the authorisation model | Evidence sought, objection route, decision and approver |
| Evidence request | Ask for one risk-relevant control explanation or record | Material received, reviewer, gap and follow-up |
| End of service | Simulate return, account closure, routine deletion and backup ageing | Instructions, formats, exceptions, confirmation and owner |
A failed tabletop is useful when it identifies a repair before harm occurs. Update the contact, clause, annex or internal procedure that caused the failure, then repeat that test. Preserve the result with the agreement so the next reviewer can distinguish an untested promise from a route that has worked.
If the supplier refuses, climb a fixed ladder
Refusal is a gap to diagnose, not a cue to invent consent or accept an unsigned template. The EDPB's small-business materials recognise the practical supplier problem and the need to resolve the processor arrangement 5. A fixed sequence prevents commercial pressure from erasing the legal question.
| Ladder step | Action | Exit condition |
|---|---|---|
| Verify | Ask for the current binding data terms and all incorporated schedules | Stop if they are complete and match the service |
| Identify | List the exact missing or conflicting Article 28 subjects | Continue with a bounded gap, not “we need our paper” |
| Offer | Propose the free 2021/915 clauses or a focused amendment | Stop when one coherent instrument closes the gap |
| Escalate | Put the gap to a supplier decision-maker and the controller's business owner | Record the response, risk and decision deadline |
| Redesign | Remove personal data, restrict access, change the feature or choose another supplier | Stop if the supplier is no longer a processor for that activity |
| Stop | Do not start, or discontinue, the processing through that supplier | Use when the Article 28 gap remains |
A supplier can reject the controller's preferred document and still offer complete binding terms. Duplicating those terms can create ambiguity. Conversely, a security page, privacy notice or statement of good intentions is not a substitute if it does not form a binding, complete processor arrangement.
Keep the agreement alive
Review on change, not only on an annual calendar. Triggers include a new service feature, broader personal-data fields, new access roles, a subprocessor notice, a location change, updated provider terms, an incident, failed evidence, renewal or termination. A light periodic review can still catch silent drift where no one reported an event.
One agreement record should contain the service map, binding terms and version, completed annexes, chain register, selected evidence, owner and contact list, test results, changes and unresolved actions. It should show what changed, why it matters, who decided and when the next action is due.
The practical finish line is not a document labelled “DPA”. It is a mapped processor service governed by complete binding terms, with a known chain, usable evidence, assigned contacts and tested procedures. If those elements remain true as the service changes, the agreement is operating rather than merely stored.
Frequently Asked Questions
Does every small business need a data processing agreement?
Is the European Commission data processing agreement free?
Must the agreement be a separate document called a DPA?
Can Commission 2021/915 clauses cover international transfers?
What belongs in a data processing agreement annex?
Does a controller need every subprocessor contract?
What should a small business do when a supplier refuses to sign?
Is signing the agreement enough for GDPR compliance?
Sources
- 1.Regulation (EU) 2016/679 — EUR-Lex · 2016
- 2.Commission Implementing Decision (EU) 2021/915 — EUR-Lex · 2021
- 3.European Commission: Standard contractual clauses between controllers and processors in the EU/EEA — European Commission
- 4.European Commission: Questions and Answers on Standard Contractual Clauses — European Commission
- 5.European Data Protection Board: SME data protection guide FAQ — EDPB
- 6.European Data Protection Board Opinion 22/2024 — EDPB · 2024
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.