A Data Processing Addendum is a contractual document that sets out how a supplier may process personal data on your behalf. It attaches to a main commercial agreement rather than standing alone, and it exists because Article 28 of the General Data Protection Regulation (GDPR) requires processing by a processor to be governed by a contract containing specific terms.
The short answer to when you need one: whenever a supplier processes personal data on your instructions. That is a much wider set of suppliers than most organizations first assume. It covers the obvious cases, such as a customer relationship platform or a payroll provider, and the less obvious ones, such as an email delivery service, a support ticketing tool, an analytics product, or a contractor who logs into your systems.
What the document actually does
A Data Processing Addendum does three jobs at once, and it is worth separating them because they fail differently.
First, it makes the processing lawful in the contractual sense. Article 28(3) requires a binding contract that sets out the subject matter, duration, nature and purpose of the processing, the types of personal data, the categories of data subjects, and the obligations and rights of the controller. Without that, the arrangement is defective regardless of how carefully the vendor operates.
Second, it allocates responsibility. It states what the processor may and may not do, what happens when a data subject exercises rights, who bears which duties when there is a security incident, and what the processor must do at the end of the relationship.
Third, it creates the evidence trail. Article 5(2) of the GDPR makes the controller responsible for demonstrating compliance, and a signed, dated document with a defined scope is the most basic form of that demonstration.
What has to be in it
Article 28(3) lists the mandatory content. A workable Data Processing Addendum will address each of the following, and a review should check them one by one rather than reading for general tone:
- A description of the processing, covering subject matter, duration, nature, purpose, data types, and data subject categories.
- A commitment to process only on documented instructions from the controller, including for international transfers.
- A confidentiality obligation binding the people authorized to process the data.
- Security measures appropriate to the risk, described specifically enough to be tested.
- The rules for engaging another processor, including authorization and notice.
- Assistance with responding to data subject rights requests.
- Assistance with security, breach notification, and impact assessments.
- Deletion or return of the data at the end of the service, with the deadlines that apply.
- Information and audit obligations that let the controller verify compliance.
Our GDPR Article 28 requirements guide works through each of these in detail, and the Data Processing Agreement review checklist turns them into a review sequence.
When you need one, and when you do not
You need a Data Processing Addendum when the supplier is a processor: it handles personal data for your purposes, under your instructions.
You do not need one when the supplier is an independent controller for the processing in question. A law firm advising you, an accountant filing statutory returns, or a bank executing a payment generally decides its own purposes and means for that processing and is not acting on your instructions. In those relationships, a confidentiality provision and a clear statement of roles is usually the right instrument, not a processor addendum.
The determination is factual. If a supplier decides why and how the data is used, calling it a processor in a document does not make it one. The European Data Protection Board's Guidelines 07/2020 on the concepts of controller and processor explain why the factual circumstances govern, and our article on controller, processor, and subprocessor roles walks through the practical tests.
There is also a middle case worth naming. Many suppliers act as processor for the core service and as controller for a narrow adjacent purpose, such as billing records or aggregate service statistics. A well-drafted document says so explicitly rather than leaving the boundary to be argued about later.
Who provides it, and what that means for review
In practice the vendor almost always supplies the document, often as a standard form published on its website and incorporated by reference into the main agreement. That has two consequences worth planning for.
The first is that the terms are drafted in the vendor's interest. This is unremarkable, but it means the review has to be substantive rather than confirmatory. The provisions that most often need attention are sub-processing notice periods, the practical workability of audit rights, and deletion commitments that lack deadlines or exclude backups without qualification.
The second is that an incorporated-by-reference document can change. If your contract points at a page on the vendor's site, the terms you agreed to are the terms on that page, and that page can be updated. Capture the version you signed, with a date, rather than relying on the link. Vendor disclosure pages move more often than most teams expect, as our article on why subprocessor lists change sets out.
The sub-processing provision deserves separate attention
Most Data Processing Addenda permit the vendor to engage other processors under a general authorization: you approve a described set of sub-processors up front, and the vendor commits to informing you of intended additions or replacements and giving you an opportunity to object.
That model scales, but it shifts a duty onto you. The right to object is only useful if the notification reaches someone who can act within the window. Understanding which model your addendum uses, and what the notice mechanics actually are, is covered in our comparison of general and specific authorization.
Frequently asked questions
Is a Data Processing Addendum the same as a Data Processing Agreement?
The terms are used interchangeably in the market, and both describe a document satisfying Article 28(3). The practical difference is structural: an addendum attaches to an existing agreement, while an agreement can stand alone. Our article on the agreement and addendum distinction covers when the difference matters.
Do we need one with every supplier?
Only with suppliers that process personal data on your behalf. Start from a list of suppliers, determine the role for each, and document the determination. Suppliers that never touch personal data need no such document, and recording why is part of the accountability trail.
Does signing one make us compliant?
No. It establishes the contractual framework the GDPR requires. The obligations it creates then have to be operated, and the facts it describes, particularly the sub-processor list and the transfer position, have to stay accurate as the vendor changes.
What if the supplier will not sign ours?
Large suppliers generally offer their standard form and decline bespoke drafting. Review the standard form against Article 28(3), identify the gaps, ask for the changes that matter most, and record what you asked for and what you accepted.
Where DPAFlow fits in
The part of this that decays after signature is the factual layer: which sub-processors the vendor uses, what its published terms say, and where the data goes. DPAFlow checks those vendor pages on a scheduled, recurring basis, records changes with dated evidence including captured page text and change differences, and sends email alerts when something moves, so the version you relied on is preserved and the change reaches a person.
Your team decides whether a change matters and what to do about it. DPAFlow does not draft or negotiate contracts and does not provide legal advice. You can see the underlying evidence model on the evidence page and the wider workflow on the product page.
This article explains a contractual instrument in general terms. It is not legal advice, and the drafting calls belong to your counsel.