Service providers
Processing on behalf of a controller: vetting service providers beyond the contract
A data processing agreement is the frame. Robustness comes from selection checks, concrete instructions, evidence of measures and ongoing oversight.
9 minute read · Content as of 21.07.2026
First classify the roles cleanly
Not every external data processing arrangement is automatically processing on behalf of a controller. What matters is who determines the purposes and the essential means. The classification should be documented before the contract is signed.
Evidence must match the concrete risk
General certificates can help, but they do not replace an assessment of the commissioned service. Critical topics include access, tenant separation, deletion, incident notification, sub-processors and international transfers.
- Role and service description
- Data processing agreement and documented instructions
- Technical and organisational measures and relevant audit reports
- Sub-processor, transfer and exit arrangements
Sources used
- General Data Protection Regulation (EU) 2016/679 · EU · check the consolidated version
- Guidance documents of the Datenschutzkonferenz · DSK
- Guidelines for Controllers and Processors · EDPB
- Privacy management, RoPA, DPIA and incident templates · KaitoSec