Module 06 · GDPR in Procurement

DPA and DPIA - GDPR contractual obligations

The DPA - Data Processing Agreement (Art. 28 GDPR)

Objective: Know how to draft a DPA compliant with Article 28 and determine when a Data Protection Impact Assessment (DPIA) is required.

When a supplier acts as a data processor under the GDPR, Article 28 requires a Data Processing Agreement (DPA). This is not optional - it is a legal obligation.

Sources

✅ Mandatory DPA provisions (Art. 28.3 GDPR):

✅ Processing only on documented instructions
✅ Confidentiality guarantee for persons processing the data
✅ Technical and organisational security measures (Art. 32)
✅ No sub-processing without prior written consent of the buyer
✅ Assistance to the controller for data subject rights
✅ Deletion or return of data at end of contract
✅ Communication of all information needed to demonstrate compliance
✅ Right of audit by the data controller

The DPIA - Data Protection Impact Assessment (Art. 35 GDPR)

A Data Protection Impact Assessment (DPIA) is mandatory before any processing likely to result in a high risk to the rights and freedoms of individuals.

📋 When is a DPIA mandatory?

  • Large-scale processing of sensitive data (health, biometric)
  • Systematic monitoring of a publicly accessible area
  • Systematic evaluation/scoring (profiling, supplier scoring based on personal data)
  • Large-scale cross-referencing or combination of datasets
  • Any processing on the CNIL list of processing activities requiring a DPIA

Practical case - DPA and DPIA in procurement

A buyer selects a SaaS provider to manage supplier performance evaluations. The SaaS processes names, emails, and rating scores of supplier contacts.

  • DPA mandatory: the SaaS is a processor within the meaning of Art. 28 GDPR
  • ⚠️ DPIA probably required: systematic evaluation with scoring of individuals
  • ✅ The buyer must verify: data location, the SaaS provider's sub-processors, Art. 32 security measures
⚠️ Impact on procurement: Any contract with an IT provider, cloud provider, HR service, digital marketing agency, advanced logistics provider, or any service involving personal data must include a DPA. The absence of a DPA exposes the buyer to CNIL sanctions as the data controller. Also consider conducting a DPIA for high-risk processing activities.
Open in the appSaved progress, quizzes and certificate