TL;DR, Quick Answer
6 min readA GDPR data processing agreement is required when a processor handles personal data for a controller. It should define scope, instructions, security, subprocessors, assistance, deletion, audits, and transfer safeguards.
This overview puts the topic Employee survey GDPR data processing agreement into useful context. A data processing agreement, usually called a DPA, is the contract that governs how a vendor processes personal data on behalf of a customer. If your website, SaaS product, CRM, analytics tool, email platform, cloud provider, or support desk touches personal data, you need to know whether a DPA is required.
Under GDPR, the core rule is in Article 28: processing by a processor must be governed by a contract or other legal act that binds the processor to the controller and sets out key details about the processing (GDPR Article 28).
Controller, Processor, or Third Party?
The first step is role mapping.
Controller: Decides why and how personal data is processed. A company running a website and choosing an analytics provider is often the controller for its visitor analytics.
Processor: Processes personal data on behalf of the controller and under its instructions. A privacy-first analytics provider, email delivery tool, or cloud host may be a processor when it only uses data to provide the contracted service.
Independent controller: Decides its own purposes. Some advertising platforms and data-sharing arrangements may involve independent controller roles rather than pure processing.
Role labels should match reality, not marketing language. If a vendor uses customer data for its own advertising, enrichment, or cross-customer profiling, a standard processor DPA may not describe the relationship accurately.

What a GDPR DPA Must Cover
Article 28 requires the contract to address:
- Subject matter and duration of processing.
- Nature and purpose of processing.
- Type of personal data.
- Categories of data subjects.
- Controller obligations and rights.
- Processing only on documented instructions.
- Confidentiality commitments.
- Security measures.
- Subprocessor rules.
- Assistance with data subject rights.
- Assistance with security, breach, DPIA, and consultation obligations.
- Deletion or return of personal data at the end of services.
- Information needed to demonstrate compliance.
- Audit and inspection rights.
In practical terms, the DPA should let you answer: what data does the vendor receive, why, where is it stored, who else touches it, how is it protected, and what happens when the contract ends?
Why Analytics Vendors Need Review
Analytics vendors can process personal data even when reports are aggregate. Data may include IP addresses, cookie IDs, device information, URL paths, referrers, campaign parameters, approximate location, and account-linked events.
For each analytics tool, ask:
- Is the vendor a processor, service provider, or independent controller?
- Does the vendor combine data across customers?
- Are cookies or persistent identifiers used?
- Is data used for advertising or product improvement beyond the contracted service?
- Where is data hosted?
- Which subprocessors are involved?
- Can raw data be deleted?
- What retention settings are available?
- Does the vendor provide a DPA?
Privacy-first analytics reduces the data footprint, but a DPA may still be needed if any personal data is processed.

Subprocessors and International Transfers
Most SaaS vendors rely on subprocessors: cloud hosts, email providers, support tools, monitoring services, and payment systems. A DPA should say whether subprocessors are allowed, how customers are notified of changes, and how objections work.
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
International transfers need separate attention. If personal data moves outside the EEA or UK, teams may need standard contractual clauses, transfer risk assessments, supplementary measures, or another valid transfer mechanism. The DPA is not always enough by itself.
A Vendor Review Checklist
Before approving a tool:
- Identify what personal data the tool receives.
- Confirm the vendor role.
- Review the DPA and subprocessors.
- Check hosting region and transfer mechanism.
- Review security documentation.
- Set retention limits.
- Disable unnecessary data sharing.
- Confirm deletion/export workflows.
- Document the business purpose.
- Add the tool to the privacy notice if needed.
Common DPA Mistakes
- Signing a DPA but never configuring the product safely.
- Ignoring event properties and URL parameters that contain personal data.
- Assuming a US vendor's DPA resolves EU transfer risk automatically.
- Failing to review subprocessors.
- Keeping raw analytics data forever.
- Letting agencies add tools outside procurement.
- Treating all vendors as processors when some are independent controllers.
A DPA is not paperwork to file away. It is the operating manual for a data relationship. The more privacy-first your stack is, the easier that relationship is to explain, secure, and end cleanly.
How to Review an Analytics DPA
For analytics vendors, compare the DPA against the actual event payload. A contract may say the processor follows instructions, but the implementation may still send full URLs, identifiers, IP addresses, search terms, or ad click IDs. The GDPR's Article 28 processor requirements are the baseline: documented instructions, confidentiality, security, subprocessor controls, assistance with rights, deletion or return, audits, and clear liability boundaries.
Ask five practical questions. Can the vendor use data for its own product, benchmarking, advertising, or AI training? Where is data hosted and which subprocessors can access it? How quickly can data be deleted after termination? Are support and engineering logs covered by the same terms? Does the DPA match the public privacy notice and security page? If the answer depends on a sales promise, get it into the contract or reduce the data sent. A privacy-first analytics vendor should make this review shorter because the service is built around limited, purpose-specific data instead of broad behavioral profiles.
- Documented instructions and confidentiality
- Security measures and subprocessor controls
- Deletion or return, plus audit rights
- Full URLs and query strings
- Identifiers and IP addresses
- Search terms and ad click IDs
DPA Review Checklist
Compare the DPA with the actual analytics payload. The contract should cover documented instructions, confidentiality, security, subprocessors, international transfers, assistance with rights, deletion or return, audit rights, and incident notice, but those clauses only help if the implementation avoids unnecessary personal data.
Before signing, test whether full URLs, query strings, IP addresses, IDs, form values, or campaign parameters could expose personal data. If a vendor can reuse data for advertising, benchmarking, AI training, or unrelated product improvement, get the role and limits clear in writing or reduce the data sent.
Frequently Asked Questions
What is a data processing agreement?
A DPA is the contract that governs how a vendor processes personal data on behalf of a customer. It exists because GDPR Article 28 requires processing by a processor to be governed by a contract or other legal act binding the processor to the controller. Any website, SaaS product, CRM, analytics tool, email platform, cloud provider, or support desk that touches personal data needs one.
Who counts as a data controller versus a processor?
A controller decides why and how personal data is processed, such as a company choosing an analytics provider for its website. A processor handles that data under the controller's instructions and only to provide the contracted service.
When is a vendor an independent controller instead of a processor?
A vendor becomes an independent controller when it decides its own purposes for the data, such as using it for advertising, enrichment, or cross customer profiling. Some advertising platforms and data sharing arrangements fall into this category rather than a standard processor role.
What must a GDPR-compliant DPA include?
Article 28 requires the contract to cover the subject matter, duration, nature, and purpose of processing, plus the type of data and categories of data subjects involved. It also has to address processing on documented instructions, confidentiality, security measures, subprocessor rules, assistance with rights and breaches, deletion or return of data, and audit rights.
Do analytics tools need a DPA even with aggregate reporting?
Yes, analytics vendors can process personal data even when the reports they produce are aggregate. That data can include IP addresses, cookie IDs, device information, URL paths, referrers, campaign parameters, approximate location, and account linked events, so a DPA may still be required.
What should a DPA say about subprocessors?
The DPA should state whether subprocessors are allowed, how customers are notified when the vendor adds or changes one, and how objections work. Most SaaS vendors rely on subprocessors such as cloud hosts, email providers, support tools, monitoring services, and payment systems.
Does a signed DPA cover international data transfers on its own?
Not always. If personal data moves outside the EEA or UK, teams may still need standard contractual clauses, transfer risk assessments, supplementary measures, or another valid transfer mechanism alongside the DPA.
What should be on a vendor review checklist before approving a tool?
Identify what personal data the tool receives, confirm the vendor's role, and review the DPA and its subprocessors. Then check the hosting region and transfer mechanism, review security documentation, set retention limits, and confirm deletion and export workflows before adding the tool to the privacy notice if needed.
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
What are the most common DPA mistakes teams make?
Common mistakes include signing a DPA and never configuring the product safely, and ignoring event properties and URL parameters that carry personal data. Another is assuming a US vendor's DPA resolves EU transfer risk automatically. Teams also skip reviewing subprocessors, keep raw analytics data forever, or let agencies add tools outside procurement. Some treat every vendor as a processor when a few are actually independent controllers.
How do you check whether an analytics DPA matches the real data being sent?
Compare the DPA against the actual event payload rather than the contract language alone. Test whether full URLs, query strings, IP addresses, IDs, form values, or campaign parameters could expose personal data, and check if the vendor can reuse data for advertising, benchmarking, or AI training beyond the contracted service.
Was This Article Helpful?
Let us know what you think!
See us more often in Google
One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.
Before you go...
Flowsery
Revenue-first analytics for your website
Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.
Real-time dashboard
Goal tracking
Cookie-free tracking
Related Articles


Key Insights - GDPR Summary Principles
The 7 principles of GDPR shape everything from lawful processing to storage limits. This guide explains what each principle means in practice.


A Practical Guide to GDPR Checklist
Data mapping, legal bases, notices, subject rights, security, vendors and transfers: a GDPR checklist you can run as an operational review.


A Practical Guide to GDPR Legal Bases Explained
Consent is rarely the right pick. The GDPR six legal bases processing personal data, when each one genuinely fits, and how the choice changes user rights.

