In brief: A data processing agreement (DPA) is mandatory as soon as a service provider processes personal data on your behalf and on your instructions, for example hosting, cloud storage, a newsletter tool or payroll. The legal basis is Article 28 GDPR. The agreement must be concluded in writing, an electronic format counts as written, and it must set out the subject matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects and the rights and obligations of the controller. It has to be signed by whoever is authorised to represent your company.

When is a data processing agreement mandatory?

Whenever an external service provider processes personal data for you without deciding on the purposes and means itself. The Austrian Economic Chamber (WKO) defines the processor as a body that processes personal data on behalf of the controller, and requires a written contract for that relationship (source: wko.at, as of 27 May 2025). What decides the matter is the role in the actual data flow, not the industry of the provider and not the question of who issues an invoice.

Typical processors in day to day SME life:

  • web hosting, server operations, content management systems
  • email, cloud storage and collaboration services
  • newsletter tools, CRM and ticketing systems
  • external IT support with remote access, backup and maintenance providers
  • payroll or accounting software operated as a cloud service
  • call centres as well as print and mailing providers working with address data

In my data protection projects the final list is almost always longer than the assumption at the start. The fastest route to a reliable overview runs through three sources: the supplier list in accounting, the installed software and the access rights on your systems.

When do you not need a DPA?

If the other side decides on the purposes and means of the processing itself, it is a controller in its own right, and Article 28 GDPR is not the right frame. In Austria, tax advisers and lawyers typically take exactly that position, based on the recommendation of their professional bodies. Do not assume the classification, clarify it actively with the provider and record the outcome in writing. It costs one email and saves an uncomfortable discussion later.

The reverse also holds: if a processor determines the purposes and means of a processing operation contrary to the agreement, it becomes the controller for that processing under Article 28(10) GDPR, with all the duties that come with it (source: dsb.gv.at). The agreement is therefore not paperwork for the archive, it draws the line at which responsibility shifts.

What must a data processing agreement contain?

Article 28(3) GDPR sets the frame. The contract binds the processor to the controller and stipulates the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data, the categories of data subjects and the obligations and rights of the controller (source: wko.at, as of 27 May 2025).

Added to that are the obligations the processor has to take on. The Austrian data protection authority summarises them as follows: processing only on documented instructions from the controller, confidentiality of the authorised persons, security measures under Article 32, compliance with the conditions for engaging further processors under Article 28(2) and (4), support for the controller in handling data subject rights, support with security, notification duties and data protection impact assessments, and deletion or return of the data once the engagement ends. On top of that comes the duty to make all necessary evidence available and to allow audits (source: dsb.gv.at).

Two practical additions that good contracts contain and weak ones lack: a concrete description of the technical and organisational measures instead of a stock phrase, and a clear rule on the format in which data is returned at the end. That return format is one of the points where the Austrian WKO model differs from the EU standard contractual clauses.

Who may sign a data processing agreement?

The GDPR does not name a role, it only requires a form: the contract must be concluded in writing, and an electronic format counts as written (Article 28(9), source: wko.at). Who may sign therefore does not follow from data protection law but from your company's rules on representation: managing director, board member, holder of a commercial power of attorney or a person with express authorisation.

The data protection officer is not that person. The Austrian data protection authority describes the role as advisory and supervisory, free from instructions, and as a bridge between data protection and management level. The officer prepares and reviews the contract, but the signature and the responsibility stay with management. A signed approval by email or an electronic signature satisfies the form, a verbal agreement does not.

Sub-processors: the point most often overlooked

Your provider may not engage another processor, that is a sub-processor, without the prior written authorisation of the controller. If you work with a general authorisation, the processor must inform you of any intended change and you can object (Article 28(2), source: wko.at). This is where the quiet classic sits: the general authorisation is signed, the change notifications land in a mailbox nobody reads, and after two years the list of providers actually involved is unknown.

My pragmatic approach: pull the sub-processor list of every important provider once a year, reconcile it with your own records, and route change notifications to an address that belongs to an accountable person. That is half an hour a year, and it keeps the documentation honest.

Which template fits: the WKO model or the EU standard contractual clauses?

Both are workable, they simply have different cuts. The WKO publishes a model contract under Article 28 GDPR tailored to processing in Austria, in Word, as a PDF and in an English version (as of 18 June 2024). For processing within the EU, the EEA or in countries with an adequate level of data protection, the WKO recommends the EU standard contractual clauses under Implementing Decision (EU) 2021/915. It also points out the differences: the Austrian model lacks classic contractual clauses and the third party beneficiary clause, while it does account for specifics such as the format of the data on return.

In practice the question is usually settled anyway, because larger providers present their own document. The task is then not to look for a template but to check the document you were given against the list in Article 28(3) and to name the gaps. One example of what such a document can look like is our own data processing agreement, which builds on the WKO model.

What does a data processing agreement cost?

There is no fee for the agreement itself, and the common templates are freely available. What costs effort is the work before and after: listing your providers in full, clarifying roles, checking third country transfers, adapting the template to the actual case, filing the contracts and keeping them current. Anyone currently setting up their records of processing activities gets most of this done in one pass, because both documents rest on the same inventory.

The most common mistakes in practice

  • A DPA without an inventory. Three contracts in the folder, twelve providers in the business. Without a list the gap stays invisible.
  • The role was never clarified. An Article 28 contract with someone who is a controller in their own right describes a reality that does not exist.
  • Stock phrases instead of measures. An annex on technical and organisational measures that only contains generic wording helps nobody when it matters.
  • Sub-processors ignored. General authorisation granted, change notifications never read.
  • Signed once, never looked at again. Providers change, tools are added. Without an annual pass the whole set quietly goes stale.

Conclusion

The data processing agreement is not a formality, it is the place where you define who may do what with your data. The effort stays manageable if you work in the right order: first list the providers, then clarify the roles, then conclude the contracts, and after that review them once a year. How this step fits into the wider implementation is covered in GDPR for SMEs: the pragmatic 7-step roadmap. How we support it is set out on the service page data protection and compliance, documented projects are listed under GDPR references and in the project archive. If the website is your next open item, the cookie banner check helps you sort it out.

Sources used: wko.at (as of 27 May 2025, model contract as of 18 June 2024) and dsb.gv.at. This article is current as of July 2026.

Frequently asked questions about data processing agreements

When must a data processing agreement be concluded?

As soon as a service provider processes personal data on your behalf and on your instructions, for example hosting, cloud storage, a newsletter tool, external IT support with remote access or payroll software running as a cloud service. The legal basis is Article 28 GDPR. What matters is the role, not the industry: anyone who decides on the purposes and means of processing is a controller in their own right and not a processor.

What must a data processing agreement contain?

The agreement sets out the subject matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects and the rights and obligations of the controller. Added to that are the processor obligations under Article 28(3): documented instructions, confidentiality, security under Article 32, rules for sub-processors, support for the controller, deletion or return at the end, and evidence including the option to audit.

Who may sign a data processing agreement?

The GDPR does not prescribe a role, it requires written form, and an electronic format counts as written (Article 28(9)). So it can be signed by whoever is authorised to represent the company: managing director, board member, holder of a commercial power of attorney or a person with express authorisation. The data protection officer advises and monitors, but does not step into the place of management.

Is there a data processing agreement template for Austria?

Yes. The Austrian Economic Chamber (WKO) publishes a model contract under Article 28 GDPR tailored to processing in Austria, available in Word, as a PDF and in an English version (as of 18 June 2024). For processing within the EU and the EEA, and in countries with an adequate level of data protection, the WKO recommends the EU standard contractual clauses under Implementing Decision (EU) 2021/915.

What does a data processing agreement cost?

There is no fee for the agreement itself, and the common templates from the WKO and the European Commission are freely available. The cost sits in the work around it: listing your providers, clarifying roles, checking sub-processors and third country transfers, adapting the template to the actual case. In small companies that is usually a manageable effort once the inventory is clean.

Note: this article is a practitioner's assessment and does not replace legal advice in an individual case.