Data processing agreements: when you need one with your web partner
What a processing agreement is, when the GDPR requires one, what it must contain, and which of your website suppliers need one.
The short answer
When another company processes personal data on your behalf, hosting your site, sending your email, holding your customer records, handling your form submissions, the regulation requires a written agreement between you setting out what they may do with that data. You remain the controller, deciding why and how the data is processed; they are the processor, acting on your instructions. The agreement has a required content list: the subject matter and duration, the nature and purpose, the types of data and categories of people, your obligations and rights, and then the processor’s commitments on instructions, confidentiality, security, sub-processors, assistance with people’s rights and with breaches, deletion or return at the end, and making information available for audit. In practice most reputable providers publish a standard agreement that meets this, often incorporated into their business terms. The work for a small business is therefore administrative: identify every supplier that touches personal data, collect the agreement from each, and keep the list current as suppliers change.
Who needs one and what it covers
| Supplier type | Processor agreement needed? | Notes |
|---|---|---|
| Hosting platform | Yes | Usually part of their business terms |
| Email sending service | Yes | Handles recipient data on your behalf |
| CRM or ticketing system | Yes | Core customer data |
| Form, booking or scheduling service | Yes | Check where submissions are stored |
| Analytics | Yes, where personal data is processed | Some consent-free tools claim not to; verify |
| Backup and storage provider | Yes | Often overlooked |
| Web agency or freelancer with access | Yes | Including access through your accounts |
| AI service processing customer data | Yes | Plus terms on training and retention |
| Payment provider | Usually a separate controller relationship | Document it, but not as a processor agreement |
| Accountant, lawyer | Usually independent controllers | Their own professional obligations apply |
Doing it properly
- List every supplier that could touch personal data, from your record of processing.
- Find each provider’s agreement: business terms, account settings, or a request to their support.
- Check the sub-processor list each publishes, and whether you are notified of changes.
- Note the processing locations and any transfer mechanism outside the EU.
- Sign or accept, and store the document with its version and date.
- Add your web partner and any freelancer with access; use a standard agreement if they have none.
- Record the set alongside your record of processing.
- Review annually and whenever a supplier changes, including at renewal.
What to look for in the agreement
That the processor acts only on your instructions. That staff are bound by confidentiality. That security measures are described rather than asserted. That sub-processors are listed and changes are notified with a chance to object. That they help you respond to people’s rights requests and to breaches, with a notification deadline you can live with. That data is deleted or returned at the end, on your choice. And that you can obtain the information needed to demonstrate compliance. Standard agreements from established providers generally cover all of these; agreements offered by small suppliers sometimes do not.
What this means for you
Every supplier that processes personal data on your behalf needs a written processing agreement covering instructions, confidentiality, security, sub-processors, assistance, deletion and audit. Build the list from your record of processing, collect the published agreements, add your partner and freelancers, note processing locations, and review annually. It is administrative work rather than legal work, and it is the first thing an enterprise client or a regulator asks to see. This is general information rather than legal advice.
Frequently asked questions
Do we need an agreement with our web developer?
If they can access personal data in the course of their work, which they usually can through the hosting platform, the CRM or the mailbox, then yes. The agreement sets out that they act on your instructions, keep it confidential, apply security measures, tell you about breaches and delete or return data at the end. A partner who resists signing one is telling you something useful about how they work.
Which suppliers need one?
Any that process personal data for you. In a typical website that means the hosting platform, the email sending service, the CRM or ticketing system, the form or booking service, analytics if it processes personal data, backup storage, and any agency or freelancer with access. Payment providers are usually controllers in their own right for parts of the processing, which is a different relationship and should be documented as such.
Where do we get them?
Most established providers publish a standard processing agreement, often accepted automatically as part of their business terms or available as a document in the account settings. Collect them, note the version and date, and store them together with your record of processing. The task is administrative rather than legal for the great majority of suppliers.
Sources
- EUR-Lex: Regulation (EU) 2016/679, Article 28 (accessed 2026-09-14)
- Autoriteit Persoonsgegevens: Verwerkersovereenkomst (accessed 2026-09-12)