Data processing agreements: when you need one with your web partner

What a processing agreement is, when the GDPR requires one, what it must contain, and which of your website suppliers need one.

4 minread 818words last updated

The short answer

When another company processes personal data on your behalf, hosting your site, sending your email, holding your customer records, handling your form submissions, the regulation requires a written agreement between you setting out what they may do with that data. You remain the controller, deciding why and how the data is processed; they are the processor, acting on your instructions. The agreement has a required content list: the subject matter and duration, the nature and purpose, the types of data and categories of people, your obligations and rights, and then the processor’s commitments on instructions, confidentiality, security, sub-processors, assistance with people’s rights and with breaches, deletion or return at the end, and making information available for audit. In practice most reputable providers publish a standard agreement that meets this, often incorporated into their business terms. The work for a small business is therefore administrative: identify every supplier that touches personal data, collect the agreement from each, and keep the list current as suppliers change.

Who needs one and what it covers

Supplier typeProcessor agreement needed?Notes
Hosting platformYesUsually part of their business terms
Email sending serviceYesHandles recipient data on your behalf
CRM or ticketing systemYesCore customer data
Form, booking or scheduling serviceYesCheck where submissions are stored
AnalyticsYes, where personal data is processedSome consent-free tools claim not to; verify
Backup and storage providerYesOften overlooked
Web agency or freelancer with accessYesIncluding access through your accounts
AI service processing customer dataYesPlus terms on training and retention
Payment providerUsually a separate controller relationshipDocument it, but not as a processor agreement
Accountant, lawyerUsually independent controllersTheir own professional obligations apply

Doing it properly

  1. List every supplier that could touch personal data, from your record of processing.
  2. Find each provider’s agreement: business terms, account settings, or a request to their support.
  3. Check the sub-processor list each publishes, and whether you are notified of changes.
  4. Note the processing locations and any transfer mechanism outside the EU.
  5. Sign or accept, and store the document with its version and date.
  6. Add your web partner and any freelancer with access; use a standard agreement if they have none.
  7. Record the set alongside your record of processing.
  8. Review annually and whenever a supplier changes, including at renewal.

What to look for in the agreement

That the processor acts only on your instructions. That staff are bound by confidentiality. That security measures are described rather than asserted. That sub-processors are listed and changes are notified with a chance to object. That they help you respond to people’s rights requests and to breaches, with a notification deadline you can live with. That data is deleted or returned at the end, on your choice. And that you can obtain the information needed to demonstrate compliance. Standard agreements from established providers generally cover all of these; agreements offered by small suppliers sometimes do not.

What this means for you

Every supplier that processes personal data on your behalf needs a written processing agreement covering instructions, confidentiality, security, sub-processors, assistance, deletion and audit. Build the list from your record of processing, collect the published agreements, add your partner and freelancers, note processing locations, and review annually. It is administrative work rather than legal work, and it is the first thing an enterprise client or a regulator asks to see. This is general information rather than legal advice.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Do we need an agreement with our web developer?

If they can access personal data in the course of their work, which they usually can through the hosting platform, the CRM or the mailbox, then yes. The agreement sets out that they act on your instructions, keep it confidential, apply security measures, tell you about breaches and delete or return data at the end. A partner who resists signing one is telling you something useful about how they work.

Which suppliers need one?

Any that process personal data for you. In a typical website that means the hosting platform, the email sending service, the CRM or ticketing system, the form or booking service, analytics if it processes personal data, backup storage, and any agency or freelancer with access. Payment providers are usually controllers in their own right for parts of the processing, which is a different relationship and should be documented as such.

Where do we get them?

Most established providers publish a standard processing agreement, often accepted automatically as part of their business terms or available as a document in the account settings. Collect them, note the version and date, and store them together with your record of processing. The task is administrative rather than legal for the great majority of suppliers.

Sources

  1. EUR-Lex: Regulation (EU) 2016/679, Article 28 (accessed 2026-09-14)
  2. Autoriteit Persoonsgegevens: Verwerkersovereenkomst (accessed 2026-09-12)