Skip to content
Topic Contested in court

Processing Agreement

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Contract between controller and processor defining processing terms

1,247 linked items 2 Laws21 Case Law51 Guidance1114 Enforcement37 News

Overview

23 sources · Sep 8, 2026

Legal Framework

A processing agreement under GDPR binds a controller and processor to specific terms governing the processing of personal data. Where the processor is located outside the EEA, the agreement must incorporate appropriate safeguards for international transfers under Article 46 GDPR. Article 46(2)(c) recognizes Commission-adopted standard contractual clauses as a valid safeguard:

"standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93(2)"
— GDPR Art. 46(2)(c)

Recital 109 clarifies that SCCs may be embedded within broader contractual frameworks:

"Controllers and processors should be encouraged to provide additional safeguards via contractual commitments that supplement standard protection clauses."
— GDPR Recital 109

Supervisory authorities retain broad corrective powers under Article 58 GDPR to address failures in processing agreements, including ordering compliance within specified periods.

Key Developments

Enforcement actions confirm that the absence of a valid processing agreement constitutes a standalone infringement. The Croatian DPA (AZOP) fined a hospital €190,000 partly for failing to enter into a data processing agreement. The Irish DPC, in the Midlands Regional Hospital investigation, rejected the notion that a service level agreement and confidentiality agreement sufficed:

Dutch courts have addressed whether a processing agreement was actually concluded. In a case involving ActiveCampaign, the claimant argued the AP should have enforced against both the absence of a valid processing agreement and missing SCCs. The Rechtbank held that formation of an agreement is a civil law question extending beyond mere signatures:

"de totstandkoming van een overeenkomst een civielrechtelijke vraag is, die meer omvat dan alleen of er handtekeningen zijn gezet"
— Rechtbank, §3.15

The court upheld the AP's decision to close the case where signed agreements and SCCs existed, noting the AP's prioritization policy could justify not pursuing further investigation.

Status of the Debate

This topic is contested in court. Courts have diverged on whether the existence of a signed document suffices to demonstrate a valid processing agreement or whether full civil law formation requirements must be assessed. The Dutch ruling that agreement formation involves more than signatures—and that supervisory authorities may exercise discretion to deprioritize enforcement—leaves the practical threshold unclear. No court split is on record yet, but a ruling clarifying what evidentiary standard applies to processing agreement formation under Article 28 would resolve the open question.

Practical Guidance

  • Execute written processing agreements before any processing begins; service level agreements or confidentiality provisions alone do not satisfy Article 28 requirements.
  • Where the processor transfers data outside the EEA, incorporate approved SCCs and ensure both parties have signed them before the transfer occurs.
  • Do not rely on a processor's general GDPR compliance posture to cover your controller obligations; the DPC has explicitly rejected this argument.
  • Document the full contractual formation process, not just signatures, given that courts treat agreement formation as a civil law question involving more than execution.
  • Where agreements are missing or incomplete, document remediation promptly; supervisory authorities apply prioritization criteria and may exercise discretion not to pursue enforcement.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Guidance EDPB Jul 2021 Processor agreement requirements
why this is here
Any processing of personal data by a processor must be governed by a contract or other legal act which shall be in writing, including in electronic form, and be binding

The document extensively describes the required content and nature of controller-processor contracts.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems Schrems II CJEU Case Law CJEU Jul 2020 standard contractual clauses as agreement
why this is here
the standard data protection clauses adopted by the Commission on the basis of Article 46(2)(c) of the GDPR are solely intended to provide contractual guarantees

The document discusses SCCs as a contractual mechanism between controller and processor, relevant to processing agreements.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 07/2022 certification as a tool for transfers Guidelines on certification and identifying certification criteria Guidelines ·EDPB Guidance EDPB Feb 2023 Contractual element for transfers
why this is here
the data exporter should refer to using the certification as a tool for transfer in the data processing contract pursuant to Article 28 GDPR

The document briefly mentions the data processing contract for transfers, but it is not the central focus.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Is the new ICT vendor liable for loss of data from old ICT environment? District Court of North Holland February 15, 2023, IT 4241; ECLI:NL:RBNHO:2023:2471 (Pit v. OfficeGrip Holding c.s.) This case deals with the question of whether a new ICT… News IT en Recht Mar 2023 mention of processor agreement
why this is here
Pit's argument that the processor agreement ehttps://www.itenrecht.nl/artikelen/is-de-nieuwe-ict-leverancier-aansprakelijk-bij-verlies-van-data-uit-oude-ict-omgeving

The document mentions the processor agreement as part of a legal argument, but the case outcome is not based on it; the agreement was not central to the court's ruling on liability.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 51 Guidance · all 1114 Enforcement · all 22 Literature · all 37 News