Data Processing Agreement Romania: GDPR Guide
A data processing agreement is required when a company engages another party to process personal data on its documented instructions. The label used in the commercial contract is not decisive: the parties must first classify their actual GDPR roles, then align the agreement with the service, security model, subprocessor chain and any international transfers.
In brief
For a Romanian or foreign business subject to the General Data Protection Regulation (GDPR), an Article 28 data processing agreement (DPA) is not a generic confidentiality annex. It must describe the processing and impose specific duties on the processor. A processor DPA is not required where the supplier acts as an independent controller, although controller-to-controller data-sharing provisions may still be appropriate; joint controllers need an Article 26 arrangement. If personal data is transferred outside the European Economic Area, the DPA alone does not provide a Chapter V transfer mechanism, even where transfer clauses are integrated into the same contractual document.
When is a data processing agreement required?
The general rule is that a written DPA is required when one party processes personal data on behalf of another party. Article 28 GDPR requires the controller to appoint only processors that provide sufficient guarantees and to govern the processing through a binding contract or other legal act, in writing, including electronically.
The practical starting point is the service, not the supplier’s preferred contract label. Payroll providers, cloud hosting companies, customer-support platforms, outsourced IT administrators, email delivery services and some marketing vendors commonly act as processors because they handle data for purposes defined by their customer. The same vendor may nevertheless be a controller for separate activities, such as its own billing, fraud prevention or legally required records.
Before signing, map each processing activity and ask who decides why the data is processed and who makes the key decisions regarding the means of processing. Certain non-essential practical means may be left to the processor. The European Data Protection Board’s Guidelines 07/2020 on controller and processor concepts are the relevant official interpretative reference.
Choose the relationship that best describes the processing
Select a card to see the usual document and the main classification test.
The controller determines the purposes and makes the key decisions regarding the means of processing; the processor handles data on documented instructions and may decide certain non-essential practical means. Describe the service-specific processing and all mandatory Article 28 controls.
| Relationship | Main test | Usual document | Frequent mistake |
|---|---|---|---|
| Controller–processor | The supplier processes personal data for the customer’s purposes and on its documented instructions. | Article 28 DPA, usually attached to the services agreement. | Using a one-page confidentiality clause with no processing details or security annex. |
| Independent controllers | Each party determines its own purposes and makes the key decisions regarding the means of its processing. | Controller-to-controller data-sharing terms, transparency allocation and lawful-disclosure provisions. | Forcing a processor DPA onto a professional adviser or platform acting for its own lawful purposes. |
| Joint controllers | The parties jointly determine the purposes and key decisions regarding the means of processing. | Transparent Article 26 arrangement allocating responsibilities. | Calling one party a processor even though both designed the relevant processing. |
| Mixed roles | The role changes by processing activity. | Activity-specific clauses covering each role. | Applying one label to the entire commercial relationship. |
What must an Article 28 DPA contain?
A compliant DPA must identify the processing and include every mandatory control listed in Article 28(3) GDPR. It should specify the subject matter and duration, nature and purpose, types of personal data, categories of data subjects, and the controller’s rights and obligations. It must then translate the statutory requirements into workable contractual duties.
Test the operational core of the DPA
Each control needs both contractual wording and evidence that it can work in practice.
Define permitted purposes, operations, users and transfer instructions. The processor must alert the controller if it considers an instruction unlawful.
| Mandatory control | What the DPA should settle | Useful evidence or annex |
|---|---|---|
| Documented instructions | Purposes, permitted operations, access, disclosure, locations and transfers; process for changing instructions. | Processing schedule, service description, authorised-user model and change log. |
| Confidentiality | Authorised personnel must be bound by contractual or statutory confidentiality. | Role-based access, confidentiality undertakings and training records. |
| Article 32 security | Measures proportionate to the processing risk, not merely “industry standard security”. | Technical and organisational measures annex, certifications, test summaries and remediation process. |
| Subprocessors | Prior specific or general written authorisation, change notice, objection process and equivalent downstream duties. | Current subprocessor list, service and country details, due-diligence records and flow-down terms. |
| Assistance | Support for data-subject requests and controller obligations under Articles 32–36. | Request workflow, responsibility matrix, response contacts and DPIA support process. |
| End of service | Controller’s choice between return and deletion, copy deletion and lawful-retention exceptions. | Export format, deletion timetable, backup treatment and deletion certificate. |
| Information and audits | Evidence needed to demonstrate compliance and a workable audit or inspection mechanism. | Audit reports, questionnaires, certification scope, remediation plan and escalation rights. |
The European Commission has adopted optional standard contractual clauses for controllers and processors under Article 28. The parties may adopt the 2021/915 standard clauses or negotiate their own Article 28 terms. Where the standard clauses are used, additional clauses should not directly or indirectly contradict them or prejudice the fundamental rights and freedoms of data subjects.
Why a generic security clause is not enough
The security schedule should describe controls that match the actual data, systems and risks. Article 32 GDPR requires appropriate technical and organisational measures, taking account of the state of the art, implementation cost, processing context and risks to individuals. Depending on the service, relevant controls may include encryption, access management, logging, vulnerability management, backups, resilience, testing, staff controls and incident response.
A clause stating only that the supplier will apply “appropriate” or “industry standard” security gives the controller little evidence and may leave important assumptions unresolved. The annex should also distinguish controls included in the standard service from optional configurations that the customer must activate.
How should subprocessors be managed?
A processor cannot appoint a subprocessor without the controller’s prior specific or general written authorisation. Under a general authorisation, the processor must notify intended additions or replacements in time for the controller to object. The processor must impose equivalent data-protection obligations downstream and remains fully liable to the controller for the subprocessor’s performance of those obligations.
The contract should state what information accompanies a change notice, how long the objection window lasts, what constitutes a reasonable objection and what happens if the parties cannot resolve it. A nominal right to object is of limited value if the controller receives only a company name, with no service description, processing location or transfer information.
The European Data Protection Board’s Opinion 22/2024 on processors and subprocessors is an important due-diligence reference. Controllers should be able to identify the entire processing chain, including relevant subprocessors and, where appropriate, further sub-processing layers, and obtain enough information to assess whether sufficient guarantees exist.
Does a DPA cover international data transfers?
No. A DPA regulates processing on behalf of a controller, but the DPA alone does not provide a Chapter V transfer mechanism. If data moves to, or is remotely accessed from, a country outside the European Economic Area, the parties must separately establish whether an adequacy decision or another valid safeguard applies. The relevant Article 28 clauses and transfer safeguards may nevertheless be integrated into a single contractual document.
This distinction is easy to miss because two different EU instruments are commonly called “SCCs”. Commission Decision (EU) 2021/915 concerns standard clauses for the Article 28 controller–processor relationship. Commission Decision (EU) 2021/914 contains standard contractual clauses for transfers to third countries. Where the transfer clauses apply, the parties must select the correct module, complete the annexes and assess the destination-country context and any necessary supplementary measures.
How quickly must a processor report a data breach?
The GDPR requires the processor to notify the controller without undue delay after becoming aware of a personal data breach. The familiar 72-hour period applies to the controller’s notification to the competent supervisory authority where the legal conditions are met; it is not the processor’s default reporting deadline.
The DPA should therefore set a fast contractual notification route that gives the controller time to investigate and decide whether regulatory or data-subject communications are required. It should define the incident contact, initial information, phased updates, evidence preservation, cooperation, remediation and post-incident report. A fixed period can be useful, but it should not dilute the statutory “without undue delay” standard.
For the controller’s incident process, see our practical GDPR data breach guide for Romania.
What should the controller check before signing?
The controller should test both the contract and the processor’s ability to perform it. Article 28 requires sufficient guarantees, so signature alone is not the end of the due-diligence exercise.
- Confirm the role for each activity. Separate processor functions from any independent or joint-controller processing.
- Map the data and people involved. Record data categories, data subjects, purposes, systems, locations, retention and sensitive-data elements.
- Review the mandatory clauses. Check every Article 28 requirement and remove conflicts with the main services agreement.
- Test the security annex. Align the written controls with the service configuration and the risk level.
- Identify all relevant subprocessors. Verify functions, locations, change procedure, downstream obligations and transfer safeguards.
- Plan incidents and rights requests. Agree contacts, response steps, information fields and internal escalation.
- Set the exit route. Define return, export, deletion, backups, certification and any lawful retention.
- Retain accountability evidence. Keep the assessment, negotiated terms, approvals, notices and review dates.
Illustrative vendor scenarios
These examples are simplified and do not replace a factual role analysis.
SaaS provider hosting a customer database
The Romanian customer decides why client records are stored and how staff use them. The SaaS provider hosts and supports the database on the customer’s instructions. An Article 28 DPA is normally required, together with a security schedule and a review of hosting and support subprocessors.
Professional adviser receiving matter information
A lawyer, auditor or other regulated adviser may independently determine certain purposes and make key decisions regarding the means of processing because of professional duties and legal obligations. It may be incorrect to classify every such activity as processor work. The engagement terms should describe the actual roles and disclosures.
Cloud subprocessor with access outside the EEA
The immediate processor uses a support provider in a third country. The controller–processor DPA remains necessary, but it is not sufficient. The parties must also examine the relevant transfer mechanism, complete the required documentation and assess whether supplementary safeguards are needed.
How should the DPA interact with the main services agreement?
The documents should work as one contract set. The services agreement, DPA, security schedule, service levels and subprocessor information should use consistent definitions, liability rules, notice mechanisms, termination rights and order-of-precedence clauses.
Commercial limits on liability require particular attention. A DPA cannot remove statutory obligations or the rights of data subjects, while the allocation of contractual risk between the parties depends on the negotiated agreement and applicable law. Audit rights also need balance: the controller requires meaningful evidence, but the process should protect the processor’s security, confidentiality and other customers.
For a wider commercial review, use our contract review checklist for Romania. Technology businesses may also find our IT and SaaS contract services relevant.
Frequently asked questions
Is a DPA required with every service provider?
No. It is required where the provider processes personal data on behalf of the controller. An independent controller relationship may require data-sharing terms instead, while joint controllers need an Article 26 arrangement. The correct classification depends on the actual purposes, decision-making and degree of instruction for each processing activity.
Can the DPA be an annex to the services agreement?
Yes. The GDPR requires a binding written contract or other legal act but does not require a separate standalone document. An annex is common and can be efficient, provided the main agreement and DPA are consistent and the processing description, security measures and subprocessor terms are complete.
Does an Article 28 DPA replace international transfer SCCs?
No. The Article 28 relationship and the Chapter V transfer basis are separate legal questions. Commission Decision 2021/915 contains controller–processor clauses, while Decision 2021/914 contains transfer clauses for third-country transfers. Depending on the data flow, both sets of requirements may be relevant.
Must the controller approve every subprocessor?
The processor needs prior specific or general written authorisation. Under general authorisation, the controller must be informed of intended additions or replacements and given an opportunity to object. The DPA should make that process meaningful by defining the notice content, timing, objection grounds and consequences.
Must a processor report a breach within 72 hours?
The processor’s statutory duty is to notify the controller without undue delay after becoming aware of a personal data breach. The 72-hour rule concerns the controller’s notification to the supervisory authority where notification is legally required. The DPA should set an incident process that allows the controller to meet its own deadline.
Can a processor use personal data for its own product improvement?
Only if the relevant role, purpose and legal basis support that use. A processor cannot simply expand its instructions into an independent purpose. If the provider determines its own purpose and makes the key decisions regarding the means of a separate activity, it may act as a controller for that activity and must satisfy the corresponding GDPR duties.
Review the DPA against the real data flow
A targeted legal review can classify the parties’ roles, check the mandatory Article 28 terms, identify transfer issues and align the DPA with the services agreement, security evidence and subprocessor chain.
Discuss a data processing agreementDisclaimer: This article provides general information and does not constitute legal advice. It reflects the law and official guidance available as of the date of publication. The correct analysis depends on the actual processing activities, contractual roles, data flows, security measures and jurisdictions involved.
AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.
