The DPA - Data Processing Agreement (Art. 28 GDPR)
Objective: Know how to draft a DPA compliant with Article 28 and determine when a Data Protection Impact Assessment (DPIA) is required.
When a supplier acts as a data processor under the GDPR, Article 28 requires a Data Processing Agreement (DPA). This is not optional - it is a legal obligation.
Sources
- Art. 28 GDPR - Processor obligations (DPA mandatory)
- Art. 35 GDPR - Data Protection Impact Assessment (DPIA)
- CNIL - DPIA Guide
✅ Mandatory DPA provisions (Art. 28.3 GDPR):
✅ Processing only on documented instructions
✅ Confidentiality guarantee for persons processing the data
✅ Technical and organisational security measures (Art. 32)
✅ No sub-processing without prior written consent of the buyer
✅ Assistance to the controller for data subject rights
✅ Deletion or return of data at end of contract
✅ Communication of all information needed to demonstrate compliance
✅ Right of audit by the data controller
The DPIA - Data Protection Impact Assessment (Art. 35 GDPR)
A Data Protection Impact Assessment (DPIA) is mandatory before any processing likely to result in a high risk to the rights and freedoms of individuals.
📋 When is a DPIA mandatory?
- Large-scale processing of sensitive data (health, biometric)
- Systematic monitoring of a publicly accessible area
- Systematic evaluation/scoring (profiling, supplier scoring based on personal data)
- Large-scale cross-referencing or combination of datasets
- Any processing on the CNIL list of processing activities requiring a DPIA
Practical case - DPA and DPIA in procurement
A buyer selects a SaaS provider to manage supplier performance evaluations. The SaaS processes names, emails, and rating scores of supplier contacts.
- ✅ DPA mandatory: the SaaS is a processor within the meaning of Art. 28 GDPR
- ⚠️ DPIA probably required: systematic evaluation with scoring of individuals
- ✅ The buyer must verify: data location, the SaaS provider's sub-processors, Art. 32 security measures
⚠️ Impact on procurement: Any contract with an IT provider, cloud provider, HR service, digital marketing agency, advanced logistics provider, or any service involving personal data must include a DPA. The absence of a DPA exposes the buyer to CNIL sanctions as the data controller. Also consider conducting a DPIA for high-risk processing activities.