Ir al contenido
Launch offerOnly until … — after that, prices go back to normal.See pricing

Blog

Processor contract (art. 28 RGPD): when and with whom to sign it

Author: Tranquilia by GRAC SA10 min read

General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.

Direct answer: the processor contract is obligatory whenever an outside company processes personal data on behalf of yours: your hosting, your gestoría (a Spanish accountancy and payroll practice), your marketing agency or the software you use to manage customers, among others (art. 28 of Reglamento (UE) 2016/679, the RGPD). You have to sign it before giving them access to the data, not afterwards, and in writing (it may be electronic). This guide explains when it is needed, with whom, and what it must include as a minimum, with links to the official sources (updated 16 July 2026).

Contents

What is the processor contract?

Processor (Spanish: encargado del tratamiento) = an outside company that handles data for you, following your instructions, without deciding what it is used for. Your gestoría, when it runs your payroll, is a processor. Your hosting, when it stores your website with your customers' data, is one too.

When you give that company access to personal data (of your customers, your employees or anyone else), the law obliges you to formalise it in a contract. A verbal agreement is not enough, nor is a generic clause buried in the provider's terms: the contract has a minimum content set out by law, and we explain it further down.

This contract does not replace the information you already give your customers or employees about the processing of their data (those are the information clauses). It is a separate agreement, between your company and the provider, governing what the provider may and may not do with that data.

When do you have to sign it?

You have to have it signed before the provider starts processing the data, not as a formality afterwards. In practice, this happens at three moments:

  1. When you take on a new provider that is going to handle personal data: hosting, management software, marketing agency, a print shop that sends letters with addresses, a courier company with access to your customer database, and so on.
  2. When you review old contracts. If you signed with a provider before 2018, or with a generic confidentiality clause that does not cover the required content, that contract is not valid as it stands. The AEPD (Spain's data protection authority) itself points out that contracts predating the RGPD must be updated: a simple generic reference to the legislation is not sufficient.
  3. When the terms of the service change. If the provider starts processing data it did not process before, or changes the country where it hosts it, you need a new contract or an addendum; the old one is not enough.

You do not need to sign it with all your providers: only with those that process personal data on your behalf. An office paper supplier does not need this contract; your invoicing program with access to your customers' data does.

Who do you sign it with (and who not)?

You sign it with any company that processes personal data following your instructions, without itself deciding the purpose or the means of the processing. Common examples in a small business:

  • Your gestoría or asesoría (Spanish accountancy and advisory practices), when it handles your payroll, your bookkeeping or your staff registrations and deregistrations.
  • Your hosting or software provider (invoicing, CRM, bookings, ERP) if that software stores data on your customers or employees.
  • Your marketing or email marketing agency, if you pass it contact lists.
  • Your IT person or technical support provider, if they have remote access to your systems containing personal data.
  • Document destruction companies, couriers with access to data, call centres, external payroll managers.

You do not sign it with anyone who decides on their own account what they use the data for: that is no longer a processor, it is another controller (for example, a public body you send data to under a legal obligation, or a partner with whom you share customers on equal terms). Nor is it needed with providers that never touch personal data.

One case that gets overlooked: your own gestoría, when it handles your payroll or your bookkeeping, is a processor with respect to your employee data. The rule in art. 28 makes no exceptions by type of provider: it applies to a gestoría just as it does to a hosting company.

What must the contract include as a minimum?

The RGPD, in art. 28.3, sets a minimum obligatory content. It is not an indicative list: if any of these points is missing, the contract does not comply. It has to set out:

  1. The subject matter, duration, nature and purpose of the processing, the type of data and the categories of people affected.
  2. That the provider only processes the data following your written instructions — never on its own initiative (art. 28.3.a).
  3. That all the provider's staff who see the data commit to confidentiality (art. 28.3.b and art. 5 of the LOPDGDD (Spain's data protection act), which also makes that commitment continue even if the person stops working there).
  4. That the provider applies appropriate security measures (art. 28.3.c and art. 32 RGPD).
  5. The conditions under which the provider may subcontract to another company (sub-processors) — we look at this in the next section.
  6. That the provider helps you when someone asks you to see, correct or delete their data (art. 28.3.e).
  7. That the provider warns you if it detects a security failure, so that you can meet the 72-hour deadline with the AEPD (art. 28.3.f and art. 33 RGPD).
  8. What happens to the data when the contract ends: the provider deletes it or returns it to you, your choice (art. 28.3.g).
  9. That the provider gives you the information needed to demonstrate that it complies, and allows audits (art. 28.3.h).
  10. That the contract is in writing, including electronic form (art. 28.9).

It is one contract per provider, not a single generic one for all of them: each company processes different data, for different purposes. The AEPD publishes an indicative set of model clauses that you can use as a starting reference (see sources).

What if your provider subcontracts to another company?

It is common: your hosting in turn uses another company's data centre, or your gestoría subcontracts payroll delivery to a specialist payroll gestoría. The RGPD allows it, but on one clear condition: the provider needs your prior written authorisation, general or specific, before subcontracting (art. 28.2 RGPD).

  • General authorisation: you accept that the provider may use sub-processors under certain conditions, and it informs you of changes so that you can object.
  • Specific authorisation: you approve each sub-processor one by one, before it starts processing data.

In either case, the provider remains answerable to you for that sub-processor meeting the same obligations as it does. If your provider subcontracts without telling you or without your authorisation, it is in breach of the contract.

What happens if you do not sign it?

The AEPD (Agencia Española de Protección de Datos) is the body that oversees this in Spain. It can ask for explanations, order changes or, in the most serious cases, impose a fine. The RGPD sets the possible maximums at two levels: up to 10 million euros or 2 % of annual worldwide turnover, and up to 20 million or 4 %, depending on the infringement (art. 83 RGPD); the higher of the two figures applies.

In practice those figures are the legal ceiling, not the norm: the fine is graduated according to the seriousness, the size of the business and whether you have cooperated. The most common outcome, if this contract is missing, is not the fine itself, but that it comes to light in the middle of some other review (for example, after a customer complaint or a security breach) and you have to put things right in a hurry, with no room to manoeuvre. That is why it is worth getting it done calmly, rather than when there is already a problem on your hands.

How do you sign it in practice?

  1. Make a list of your providers that process personal data: hosting, software, gestoría, marketing, technical support, couriers with access to data.
  2. For each one, draft or use a template covering the 10 points in the previous section, adapted to what that provider does exactly with your data.
  3. Send it to them to sign. Many large providers (hosting, software) already have their own template: check that it covers the minimum points before signing it as it stands.
  4. Keep the copy signed by both parties in that provider's folder, for as long as the relationship lasts and a few years more, in case you have to prove that you were complying with the law.
  5. If you change provider or the terms of the service change, draw up a new contract: the old one is archived as evidence of what was in force at the time.

Tranquilia generates this contract automatically for every provider you add to your dossier, with the 8 obligatory clauses of art. 28.3 already included and ready to send out for signature by email. You can try it with up to 2 companies, with all the features active, with no card and no time limit — it is the free plan, not a cut-down demo.

Frequently asked questions

Do I need a different contract for each provider? Yes. Each provider processes different data, with a different purpose and a different duration. A generic contract for all of them does not comply with art. 28.3, which requires the subject matter and nature of the processing to be set out in each case.

Is a contract signed before 2018 valid? No, not if it only makes a generic reference to data protection legislation. The AEPD points out that such contracts must be brought into line with the content required by art. 28 RGPD; an old confidentiality clause is not enough.

Does my own gestoría have to sign it with me? Yes, if it processes your employees' or customers' data on your behalf (payroll, bookkeeping, registrations and deregistrations). Nothing in art. 28 exempts gestorías: they are a processor like any other provider.

Can the provider sign and then subcontract without telling me? No. It needs your prior written authorisation, general or specific, before subcontracting to another company (art. 28.2 RGPD). If it does so without telling you, it is in breach of the contract.

Where do I have to keep the signed contract? In that provider's folder, for as long as the business relationship lasts and a few years more, so that you can prove you were complying with the law if you are asked.

Official sources


Content report produced from verified official sources — it does not constitute an official certification or a legal opinion. If you have doubts about a specific case, consult your gestoría or a legal professional.

Want to see how this contract is generated automatically for each of your providers? See the guide for asesorías and gestorías or take a look at the free plan.

Review: Translation of the Spanish original, which prevails in case of divergence.

Get your clients GDPR-compliant in 15 minutes.

Set up my free instance

No card, no sales calls. Two companies free, for as long as you like.

Blog