Skip to content

Service providers

Processing on behalf of a controller: vetting service providers beyond the contract

A data processing agreement is the frame. Robustness comes from selection checks, concrete instructions, evidence of measures and ongoing oversight.

Back to Data protection

9 minute read · Content as of 21.07.2026

First classify the roles cleanly

Not every external data processing arrangement is automatically processing on behalf of a controller. What matters is who determines the purposes and the essential means. The classification should be documented before the contract is signed.

Evidence must match the concrete risk

General certificates can help, but they do not replace an assessment of the commissioned service. Critical topics include access, tenant separation, deletion, incident notification, sub-processors and international transfers.

  • Role and service description
  • Data processing agreement and documented instructions
  • Technical and organisational measures and relevant audit reports
  • Sub-processor, transfer and exit arrangements

Sources used

Back to Data protection