Skip to content
Talk to us

Do you need a data processing agreement with your website host?

Why GDPR Article 28 applies to your website host, the eight clauses the contract must contain, and which GDPR fine tier a missing agreement actually falls into.

Jack O'Connor· 6 min read· ·Updated

If someone else stores or handles personal data on your behalf, GDPR Article 28 requires a written contract between you and them. A website host almost always falls into that category, because the site holds enquiry forms, customer accounts, orders or analytics data, and the host stores all of it.

That contract is usually called a data processing agreement. Article 28(3) sets out what it has to contain, and it is a specific list rather than a general promise to take security seriously.

Breaching Article 28 sits in the lower of the two GDPR fine tiers. Article 83(4) covers Articles 25 to 39 and carries administrative fines of up to €10 million, or 2 per cent of total worldwide annual turnover, whichever is higher. The higher tier of €20 million or 4 per cent applies to other things, including the basic principles for processing and data subject rights.

The practical question for most organisations is simpler than the law. Ask your host for their agreement, read the eight clauses below, and keep it in the file.

What is a data processing agreement?

Under GDPR you are the controller of your website’s personal data, because you decide why it is collected and what happens to it. Your host is a processor, because it handles that data on your instructions.

Article 28(3) requires that the processing is governed by a contract or other legal act that is binding on the processor. That contract must set out the subject matter and duration of the processing, the nature and purpose of it, the type of personal data, the categories of data subjects, and the obligations and rights of the controller.

A data processing agreement is the document that does this. The name is a convention. The obligation is the contract.

Is my website host actually a processor?

If the host stores your site’s database, then yes. Contact form submissions, customer accounts, order records, comments and most analytics involve personal data, and the host holds all of it at rest.

Some suppliers are not processors and do not need an agreement. A domain registrar that only holds your registration details is your supplier, not your processor. A designer who builds a site and never touches live data is in a different position from one who has database access. The test is whether they process personal data on your behalf, not whether they send you an invoice.

What must the agreement contain?

Article 28(3) lists eight things the contract must stipulate. This is the checklist to read any DPA against.

  • Documented instructions. The processor acts only on your documented instructions, including on any transfer of data outside the EU, unless a law requires otherwise. If a law does require it, they tell you before processing unless that law forbids telling you.
  • Confidentiality. Anyone authorised to process the data is bound by confidentiality, either by commitment or by statute.
  • Security. The processor takes all measures required by Article 32, which covers the technical and organisational measures appropriate to the risk.
  • Sub-processors. The processor respects the conditions in Article 28(2) and 28(4) before engaging anyone else.
  • Help with data subject rights. The processor assists you in responding to access, erasure and the other Chapter III requests, so far as that is possible.
  • Help with security and breach duties. The processor assists you with Articles 32 to 36, which include breach notification and data protection impact assessments.
  • Deletion or return. At the end of the service, the processor deletes or returns all the personal data at your choice, and deletes existing copies unless law requires them to be kept.
  • Audit and information. The processor makes available all information needed to demonstrate compliance with Article 28, and allows for and contributes to audits and inspections by you or an auditor you appoint.

Article 28 adds one duty that is easy to miss. The processor must immediately tell you if, in their opinion, one of your instructions infringes GDPR.

What about sub-processors?

Almost every web host uses other companies. Infrastructure, backup storage, a content delivery network and email delivery are commonly separate suppliers.

Article 28(2) says the processor cannot engage another processor without your prior written authorisation, either specific or general. Where the authorisation is general, the processor has to tell you about intended additions or replacements and give you the chance to object.

Article 28(4) is the one that matters commercially. The same data protection obligations must be imposed on the sub-processor, and where that sub-processor fails, your host remains fully liable to you for their performance.

That is why a current sub-processor list is worth asking for. It tells you who is actually in the chain, and it gives you something to check when the list changes.

What happens if there is no agreement in place?

The absence of a compliant contract is itself an infringement of Article 28, separate from anything going wrong with the data.

Article 83(4) puts that in the lower fine tier, up to €10 million or 2 per cent of worldwide annual turnover, whichever is higher. Commentary often quotes the €20 million and 4 per cent figures for everything. Those belong to Article 83(5), which covers the basic principles for processing, the conditions for consent, data subject rights and international transfers.

For a regulated organisation the more immediate consequence is usually the audit rather than the fine. An outsourcing register with a supplier and no Article 28 contract against their name is a finding, and it is the kind that surfaces during due diligence at the worst possible time.

Who is liable when something goes wrong?

Article 82(1) gives anyone who suffers material or non-material damage the right to compensation from the controller or the processor.

Article 82(2) then narrows the processor’s exposure. A processor is liable for damage only where it has not complied with obligations specifically directed at processors, or where it acted outside or contrary to your lawful instructions. A controller is liable for damage caused by processing that infringes the Regulation.

The practical reading is that a breach caused by your own configuration stays with you, and a breach caused by the host ignoring the contract sits with the host. The contract is what decides which of those happened.

What to ask your host for

Three documents, and they should take a supplier minutes rather than weeks to produce.

The data processing agreement itself, so you can check it against the eight clauses above.

The current sub-processor list, so you know who else is in the chain.

Their position on audits, because Article 28(3)(h) entitles you to information and to audits, and a supplier who treats that as unreasonable is telling you something useful.

Our own Article 28 agreement and sub-processor list are available to clients on request, and the security page sets out what we commit to on breach notification.

This article sets out how we read the Regulation and it is not legal advice. Where the position matters, take your own.

Share this article

See exactly how your WordPress site is performing

Get a free HostLogic site audit covering Core Web Vitals, security posture, infrastructure and a maintenance gap analysis. Written report within 3 working days. No obligation, no sales pitch.