Tool Documents

The Processing Agreement

This site takes no affiliate commissions and ranks no products. This is not legal advice — it is a summary of a published provision.

Almost every business tool processes personal data: customer contacts, employee records, user activity. Where it does, a written agreement is required and its contents are specified. For a related operational perspective, Monitask also publishes a reference on fireable offenses in the workplace.

Reviewed August 9, 2026.

When you need one

When the vendor processes personal data on your behalf, which covers most tools in most categories.

Under GDPR this is Article 28, and it applies wherever EU residents' data is involved regardless of where the vendor sits.

For broader context, see NIST.

And increasingly outside the EU. As of 2026 more than twenty US states have comprehensive privacy laws with processor agreement requirements, so a US-only vendor does not remove the obligation if the people in your data are covered.

You are the controller. The vendor is the processor. The obligation to have the agreement is yours, not theirs.

The eight items Article 28(3) requires

Check the vendor's document against this list. It takes ten minutes.

Subject matter and duration of the processing.

Nature and purpose of the processing.

Type of personal data and categories of data subject.

Processing only on documented instructions from you, including on transfers.

Confidentiality obligations on personnel.

Security measures under Article 32.

Subprocessor rulesauthorisation, and notice of changes.

And deletion or return of the data at the end of the contract, at your choice.

Plus: assistance with data subject rights, breach notification, and audit rights.

A published DPA missing several of these is a document rather than an agreement, and it is a reasonable thing to raise before signing.

What to actually look at

Is there a published DPA at all? A vendor selling to businesses in Europe without one has told you something.

Is it incorporated by reference into the main terms, or does it need separate signature?

Where does processing happen, and if outside the EEA, what transfer mechanism applies — standard contractual clauses, an adequacy decision, or binding corporate rules.

What are the deletion terms, and do they match your export window? A thirty-day deletion against a sixty-day export window is a conflict somebody should notice before it matters.

And who is the counterparty — the entity you contract with is not always the entity that holds the data.

The pattern worth noticing

The DPA is usually the best-drafted document a vendor publishes, because it is written by lawyers against a checklist.

The main terms are frequently weakerrenewal, price changes, liability, IP, the parts with no statutory template.

So a strong DPA is not evidence of a strong contract, and reading the DPA and skipping the terms is the common mistake.

What to ask

"Where is your DPA, and is it incorporated automatically?"

"Where is data processed and stored?"

"What is the deletion timeline after termination?"

Three questions, one email, answered by any vendor who sells to organisations.

The short version