Processing Agreement
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Contract between controller and processor defining processing terms
Overview
23 sources · Sep 8, 2026Legal Framework
A processing agreement under GDPR binds a controller and processor to specific terms governing the processing of personal data. Where the processor is located outside the EEA, the agreement must incorporate appropriate safeguards for international transfers under Article 46 GDPR. Article 46(2)(c) recognizes Commission-adopted standard contractual clauses as a valid safeguard:
"standard data protection clauses adopted by the Commission in accordance with the examination procedure referred to in Article 93(2)"
— GDPR Art. 46(2)(c)
Recital 109 clarifies that SCCs may be embedded within broader contractual frameworks:
"Controllers and processors should be encouraged to provide additional safeguards via contractual commitments that supplement standard protection clauses."
— GDPR Recital 109
Supervisory authorities retain broad corrective powers under Article 58 GDPR to address failures in processing agreements, including ordering compliance within specified periods.
Key Developments
Enforcement actions confirm that the absence of a valid processing agreement constitutes a standalone infringement. The Croatian DPA (AZOP) fined a hospital €190,000 partly for failing to enter into a data processing agreement. The Irish DPC, in the Midlands Regional Hospital investigation, rejected the notion that a service level agreement and confidentiality agreement sufficed:
Dutch courts have addressed whether a processing agreement was actually concluded. In a case involving ActiveCampaign, the claimant argued the AP should have enforced against both the absence of a valid processing agreement and missing SCCs. The Rechtbank held that formation of an agreement is a civil law question extending beyond mere signatures:
"de totstandkoming van een overeenkomst een civielrechtelijke vraag is, die meer omvat dan alleen of er handtekeningen zijn gezet"
— Rechtbank, §3.15
The court upheld the AP's decision to close the case where signed agreements and SCCs existed, noting the AP's prioritization policy could justify not pursuing further investigation.
Status of the Debate
This topic is contested in court. Courts have diverged on whether the existence of a signed document suffices to demonstrate a valid processing agreement or whether full civil law formation requirements must be assessed. The Dutch ruling that agreement formation involves more than signatures—and that supervisory authorities may exercise discretion to deprioritize enforcement—leaves the practical threshold unclear. No court split is on record yet, but a ruling clarifying what evidentiary standard applies to processing agreement formation under Article 28 would resolve the open question.
Practical Guidance
- Execute written processing agreements before any processing begins; service level agreements or confidentiality provisions alone do not satisfy Article 28 requirements.
- Where the processor transfers data outside the EEA, incorporate approved SCCs and ensure both parties have signed them before the transfer occurs.
- Do not rely on a processor's general GDPR compliance posture to cover your controller obligations; the DPC has explicitly rejected this argument.
- Document the full contractual formation process, not just signatures, given that courts treat agreement formation as a civil law question involving more than execution.
- Where agreements are missing or incomplete, document remediation promptly; supervisory authorities apply prioritization criteria and may exercise discretion not to pursue enforcement.
why this is here
Any processing of personal data by a processor must be governed by a contract or other legal act which shall be in writing, including in electronic form, and be binding
The document extensively describes the required content and nature of controller-processor contracts.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
the standard data protection clauses adopted by the Commission on the basis of Article 46(2)(c) of the GDPR are solely intended to provide contractual guarantees
The document discusses SCCs as a contractual mechanism between controller and processor, relevant to processing agreements.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
the data exporter should refer to using the certification as a tool for transfer in the data processing contract pursuant to Article 28 GDPR
The document briefly mentions the data processing contract for transfers, but it is not the central focus.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Pit's argument that the processor agreement ehttps://www.itenrecht.nl/artikelen/is-de-nieuwe-ict-leverancier-aansprakelijk-bij-verlies-van-data-uit-oude-ict-omgeving
The document mentions the processor agreement as part of a legal argument, but the case outcome is not based on it; the agreement was not central to the court's ruling on liability.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 51 Guidance · all 1114 Enforcement · all 22 Literature · all 37 News