Customer Impact

Website & Development

Data Processing Agreement with Your Web Agency: Why You Need One

Copy for AI

Yes, you need a data processing agreement with your web agency as soon as that agency can access the personal data of your visitors, leads or customers. That is almost always the case: contact forms, a CRM connection, hosting, analytics or simply access to your CMS. The GDPR then requires you to put the arrangements in writing. In this article you will read who exactly is what, why that agreement has to exist, what belongs in it and how to arrange it in practice without it turning into a mountain of paperwork.

What is a data processing agreement and who is who?

A data processing agreement is a contract in which you set out how an external party processes personal data on your behalf. It is commonly abbreviated to DPA. The requirement comes straight from the GDPR (the General Data Protection Regulation).

The division of roles is at the heart of it. You are the data controller: it is your company that determines why and how the data of your leads and customers is processed. Your web agency and your hosting provider are the processor: they process that data on your instructions, without pursuing a purpose of their own. Think of a web agency that manages your form submissions or a host that keeps your database on its servers.

That distinction matters, because the law places ultimate responsibility on you as the client. You choose the processor, you give the instructions, and you must be able to demonstrate that you have arranged it properly. The data processing agreement is the evidence of that.

Why do you need a data processing agreement with your web agency?

You need the agreement because the GDPR literally requires it as soon as an external party processes personal data on your behalf. Article 28 of the GDPR prescribes that this processing must be governed by a contract or another binding legal instrument. There is no threshold: it makes no difference how big your company is or how much data is involved.

In practice, a web agency almost always comes into contact with personal data. A few examples:

  • It builds and maintains your contact forms, where names, emails and phone numbers come in.
  • It has administrator access to your CMS, which holds submissions and user accounts.
  • It connects your site to your CRM, email tool or analytics system.
  • It hosts your site, or arranges hosting with a third party.

In all those cases, someone can access data about real people. That is what triggers the obligation. And it is not just a formality: the agreement protects above all you. It establishes that the agency uses the data only for your purpose, does not resell it, and secures it adequately. Without that document you have no enforceable arrangement and you carry the full risk alone.

This also touches on trust on your B2B website. Customers and prospects leave their data on the assumption that you handle it carefully. Sealing the chain properly with your suppliers is an invisible but essential part of that.

Is your hosting provider also a processor?

Yes, your host is as a rule also a processor, because its servers hold your databases, form submissions and backups. It can therefore technically access the personal data, and so you also need a data processing agreement with your host.

Large hosting providers usually have this arranged by default. They offer a ready-made data processing agreement that you accept digitally or that is woven into their terms and conditions. Even so, it is wise to check this actively rather than assume it. Simply ask your host or web agency: is there a data processing agreement, and where can I view it?

One point of attention is where your data is physically located. If the servers are within the European Economic Area, that is the simplest case. If data is processed outside the EEA, for example with an American cloud provider, extra rules apply to that transfer and appropriate safeguards must be in place. A web agency that has its affairs in order can explain in a few sentences where your data is and how that works.

What belongs in a data processing agreement?

A data processing agreement describes concretely what the processor may do with your data and under what conditions. In Article 28, the GDPR lists a fixed set of topics that must be included. The most important ones:

  • Subject, duration, nature and purpose. What is the data processed for, and for how long? Is it an ongoing processing operation or a one-off?
  • Type of data and data subjects. Which categories of personal data are involved (names, email addresses, IP addresses) and who does it concern (leads, customers, website visitors)?
  • Processing only on your instructions. The processor may use the data only for what you instruct, not for its own purposes.
  • Confidentiality. The staff who can access the data are bound to confidentiality.
  • Security. Which appropriate technical and organisational measures does the processor take, such as encryption, access management and backups?
  • Sub-processors. May the agency bring in other parties, and under what conditions? Think of an external host or an email tool.
  • Help with obligations. The processor helps you handle requests from data subjects (access, deletion) and reports data breaches in good time.
  • End of the collaboration. What happens to the data when the contract ends? Is it returned or deleted?
  • Oversight. The processor cooperates with audits and provides the information to demonstrate compliance.

You do not have to write this from scratch. Most data processing agreements follow a standard template, and your web agency or host usually provides its own version. Your task is mainly to check that the points above are in it and that the arrangements match reality, for example which sub-processors your data actually ends up with.

What happens if you do not have a data processing agreement?

Then you carry the risk, because as the data controller you remain liable for what happens to the data, even when the fault lies with your supplier. The absence of a data processing agreement is in itself already a breach of the GDPR, regardless of whether anything ever goes wrong.

The data protection authority can impose fines for violations. For the absence of a correct data processing agreement, this falls under the lower fine category of the GDPR, with a maximum in the order of 10 million euros or 2 percent of worldwide annual turnover, whichever is higher. In practice, an SME will rarely see the maximum, but the point is clear: it is a real risk and not a theory. On top of that, it is reputational damage you do not want just when you are trying to build trust with prospects.

More practically still: without an agreement you have no grip. You do not have it in black and white that your supplier secures the data, does not resell it or returns it when you leave. The moment something goes wrong, you are left empty-handed.

How do you arrange this in practice?

Arranging it is manageable if you approach it systematically. A workable approach:

  1. Make a list of your processors. Who comes into contact with the personal data around your website? Typically your web agency, your host, your analytics tool, your email or CRM system.
  2. Ask each party for the data processing agreement. Many suppliers have one ready. If you do not get one, or nobody knows what it is about, that is a warning sign.
  3. Check that the essentials are in it using the points above, paying attention to sub-processors and where your data is located.
  4. Keep everything in one place, so you can show it if the regulator or a customer asks for it.
IN PRACTICE Four steps to a watertight agreement 01 List processors who sees the data? 02 Request the DPA from each party 03 Check the essentials art. 28 points 04 Store centrally showable proof From inventory to demonstrable proof

A good web agency takes the lead here and offers the data processing agreement on its own initiative, often right at the start of the website project. The fact that the agency arranges this proactively and can explain where your data is stored is an immediate sign that it has its affairs in order. If you are in doubt about your current situation or are just starting a new project, it pays to factor this in from the outset when choosing a supplier. In our complete guide to having a B2B website built, this is a self-evident part of a professional process.

The short summary

As soon as your web agency or host can access the personal data of your visitors and leads, the GDPR requires a written data processing agreement. You are the data controller and remain ultimately responsible, so that agreement protects above all yourself. It sets out what the data is used for, how it is secured, which sub-processors are involved and what happens at the end of the collaboration. The good news: a solid supplier arranges this without you having to ask.

Do you want to be sure this is properly arranged for your website? Book your free intake and we will go through it together.

Free website scan

Enter your website and get an automatic scan within minutes, with concrete technical and SEO improvements. No sales pitch.

Where should we send your report?

We only use your details for your scan. No spam, unsubscribe anytime.