How 100 Irish charity websites handle cookie consent
We checked what 100 of Ireland’s largest charity websites do with cookies before a visitor chooses anything. 47 set analytics or advertising cookies first.
Why GDPR Article 28 applies to your website host, the eight clauses the contract must contain, and which GDPR fine tier a missing agreement actually falls into.
If someone else stores or handles personal data on your behalf, GDPR Article 28 requires a written contract between you and them. A website host almost always falls into that category, because the site holds enquiry forms, customer accounts, orders or analytics data, and the host stores all of it.
That contract is usually called a data processing agreement. Article 28(3) sets out what it has to contain, and it is a specific list rather than a general promise to take security seriously.
Breaching Article 28 sits in the lower of the two GDPR fine tiers. Article 83(4) covers Articles 25 to 39 and carries administrative fines of up to €10 million, or 2 per cent of total worldwide annual turnover, whichever is higher. The higher tier of €20 million or 4 per cent applies to other things, including the basic principles for processing and data subject rights.
The practical question for most organisations is simpler than the law. Ask your host for their agreement, read the eight clauses below, and keep it in the file.
Under GDPR you are the controller of your website’s personal data, because you decide why it is collected and what happens to it. Your host is a processor, because it handles that data on your instructions.
Article 28(3) requires that the processing is governed by a contract or other legal act that is binding on the processor. That contract must set out the subject matter and duration of the processing, the nature and purpose of it, the type of personal data, the categories of data subjects, and the obligations and rights of the controller.
A data processing agreement is the document that does this. The name is a convention. The obligation is the contract.
If the host stores your site’s database, then yes. Contact form submissions, customer accounts, order records, comments and most analytics involve personal data, and the host holds all of it at rest.
Some suppliers are not processors and do not need an agreement. A domain registrar that only holds your registration details is your supplier, not your processor. A designer who builds a site and never touches live data is in a different position from one who has database access. The test is whether they process personal data on your behalf, not whether they send you an invoice.
Article 28(3) lists eight things the contract must stipulate. This is the checklist to read any DPA against.
Article 28 adds one duty that is easy to miss. The processor must immediately tell you if, in their opinion, one of your instructions infringes GDPR.
Almost every web host uses other companies. Infrastructure, backup storage, a content delivery network and email delivery are commonly separate suppliers.
Article 28(2) says the processor cannot engage another processor without your prior written authorisation, either specific or general. Where the authorisation is general, the processor has to tell you about intended additions or replacements and give you the chance to object.
Article 28(4) is the one that matters commercially. The same data protection obligations must be imposed on the sub-processor, and where that sub-processor fails, your host remains fully liable to you for their performance.
That is why a current sub-processor list is worth asking for. It tells you who is actually in the chain, and it gives you something to check when the list changes.
The absence of a compliant contract is itself an infringement of Article 28, separate from anything going wrong with the data.
Article 83(4) puts that in the lower fine tier, up to €10 million or 2 per cent of worldwide annual turnover, whichever is higher. Commentary often quotes the €20 million and 4 per cent figures for everything. Those belong to Article 83(5), which covers the basic principles for processing, the conditions for consent, data subject rights and international transfers.
For a regulated organisation the more immediate consequence is usually the audit rather than the fine. An outsourcing register with a supplier and no Article 28 contract against their name is a finding, and it is the kind that surfaces during due diligence at the worst possible time.
Article 82(1) gives anyone who suffers material or non-material damage the right to compensation from the controller or the processor.
Article 82(2) then narrows the processor’s exposure. A processor is liable for damage only where it has not complied with obligations specifically directed at processors, or where it acted outside or contrary to your lawful instructions. A controller is liable for damage caused by processing that infringes the Regulation.
The practical reading is that a breach caused by your own configuration stays with you, and a breach caused by the host ignoring the contract sits with the host. The contract is what decides which of those happened.
Three documents, and they should take a supplier minutes rather than weeks to produce.
The data processing agreement itself, so you can check it against the eight clauses above.
The current sub-processor list, so you know who else is in the chain.
Their position on audits, because Article 28(3)(h) entitles you to information and to audits, and a supplier who treats that as unreasonable is telling you something useful.
Our own Article 28 agreement and sub-processor list are available to clients on request, and the security page sets out what we commit to on breach notification.
This article sets out how we read the Regulation and it is not legal advice. Where the position matters, take your own.
Get a free HostLogic site audit covering Core Web Vitals, security posture, infrastructure and a maintenance gap analysis. Written report within 3 working days. No obligation, no sales pitch.