Data processing agreement for email: what you need to know
What is a data processing agreement for email?
A data processing agreement (often referred to by the English term DPA, Data Processing Agreement) is a contract that governs how a processor handles personal data it processes on your behalf. The GDPR describes in article 28 what such an agreement must contain.
The idea behind it is clear: if you process personal data yourself and engage an external party for it, you remain responsible for what happens with that data. The data processing agreement sets out in writing which arrangements apply, so it doesn't stay a matter of loose promises. Think of the purpose of the processing, the security measures, confidentiality, and what happens when the collaboration ends.
Why it matters
For anyone working with data of clients, patients or members, this is no formality. If you process personal data and outsource part of it, the GDPR expects you to record the arrangements properly. Without an agreement it's hard to demonstrate that you work carefully, and the responsibility still lies with you.
There's also a practical point. Supervisory authorities and clients ask about it more and more often. If you can show that you have written arrangements in place with your processors, you're in a stronger position. "We arranged that verbally" is an answer that raises questions.
Important to nuance: not every situation requires a data processing agreement, and the precise requirements depend on who plays which role. That makes it bespoke, and sometimes wise to have it checked.
For small organisations this is often a confusing point. You hear that you "must have a data processing agreement", but rarely for what exactly. In practice it's about the parties that process data on your behalf: think of an accounting package, a newsletter service or your email provider, depending on how you use them. For each of those, the question of whether an agreement should exist is separate. Keeping an overview of which parties those are is then the first and most important step.
How it works
To determine whether you need one, it helps to separate out the roles:
- Controller. That's you, if you determine why and how personal data is processed. You're in charge.
- Processor. That's a party that processes personal data on your behalf, according to your instructions, without determining the purpose of it itself.
- The agreement. If an external party processes data on your behalf, the GDPR can require a data processing agreement. It sets out, among other things, the subject and purpose, the types of data, the security measures, confidentiality, the engagement of sub-processors, and what happens at the end of the collaboration.
Whether an email provider counts as a processor in your situation depends on how you use the service and which data is processed in it. That's precisely the kind of assessment for which you consult a specialist if in doubt. What "GDPR-compliant" further means, you'll read in GDPR-compliant email: what that means.
What to watch out for
A few points of note and misconceptions:
- Thinking you always need a data processing agreement. That's not so. It depends on the roles and on what exactly is processed. Don't rush, but don't ignore it either.
- Mixing up the roles. A party isn't automatically a "processor". Sometimes a service provider is itself the controller for certain data. That classification determines which arrangements fit.
- Blindly signing a standard text. An agreement has to fit your situation and the data you process. Read what's in it, and check whether the security and sub-processors named are correct.
- Thinking the agreement takes over your work. Paper alone doesn't make you compliant. Your own working methods, security and care still count. See also the GDPR for small organisations.
Again: these are general points of note, not a conclusive legal judgment for your situation. Whether and which data processing agreement you need is bespoke; consult a specialist or the Belgian Data Protection Authority (GBA) if in doubt.
And at Mailflux
Mailflux hosts your email in Europe, GDPR-compliant, on your own domain, with encrypted connections, filtering against spam, phishing and malware, automatic backups and optional two-factor authentication. Your content isn't scanned for advertising. That's the technical and organisational foundation you build on further.
Do you need a data processing agreement for your situation, or want to know which arrangements are possible? Then feel free to get in touch with Mailflux and we'll look at what's possible together. What's required in your case still depends on your situation and the roles; consult a specialist if in doubt. You'll read more about the hosting side in European email hosting on your own domain.
FAQ
Frequently asked questions
Do I always need a data processing agreement for my email?
Not always. It depends on the roles and on what exactly is processed. If an external party processes personal data on your behalf, the GDPR can require an agreement. What applies in your case is bespoke; consult a specialist if in doubt.
What must a data processing agreement contain?
The GDPR (article 28) names, among other things, the subject and purpose of the processing, the types of data, the security measures, confidentiality, arrangements about sub-processors and what happens at the end of the collaboration. The precise content depends on your situation.
Does Mailflux offer a data processing agreement?
Get in touch with Mailflux about that and we'll look at what's possible for your situation together. The foundation, European GDPR-compliant hosting with encrypted connections, is there in any case. What's further required is bespoke; consult a specialist if in doubt.
What is the difference between a processor and a controller?
The controller determines why and how personal data is processed; that's you, for your own clients or members. A processor processes that data on your behalf, according to your instructions. Who has which role determines whether and which arrangements the GDPR expects.