Blog/DPAs and processors

Do You Need a Data Processing Agreement With Your Hosting Provider?

Legas.ai legal team·5 min·31 Jul 2026

Yes, you need one. The better news is that if you host with one of the large cloud platforms, you almost certainly already have it, sitting inside terms you clicked through at signup and never opened. The question worth your time is not whether the obligation exists. It is which of your vendors it covers, and what you do about the ones that never gave you anything.

What makes a host a processor

Start with what "processing" means, because the word is broader than it sounds. GDPR Article 4(2) defines it to include storage. Not reading the data, not analysing it. Holding it counts.

So a hosting provider that keeps your production database on its disks is processing personal data. It does that on your instructions and for your purposes, which under Article 4(8) makes it a processor and you the controller. Nobody at your host needs to open your users table for this to be true. We get pushback on this every few weeks, usually phrased as "they can't see anything, it's all encrypted." Encryption is a security measure, and a good one. It doesn't change who is holding the data on whose behalf.

The role follows the actual activity rather than the label either side prefers. The EDPB made the point directly in its Guidelines 07/2020 on the concepts of controller and processor: you work out the roles from what each party really does and decides, and a contract cannot assign a role that the facts contradict. A host that only ever executes your instructions is a processor. If it started using your users' data for its own purposes, it would become a controller for that, and terms saying otherwise would not save it.

"We're on AWS, so we're fine" is the mistake

This is the one we see most, and it deserves a blunt answer. Your host being large, reputable and certified against every standard with an acronym does not by itself put a contract in place between the two of you. Article 28(3) says the processing shall be governed by a contract. The party that has to make sure that contract exists is the controller, and the controller is you. A DPA published on a provider's website is also not automatically a DPA that governs your account, which depends on how the provider wires it in.

How the big providers actually do it

Most of the major platforms worked out years ago that negotiating Article 28 terms with every customer was unworkable, so they wrote one set and made it automatic.

AWS incorporates its GDPR Data Processing Addendum into the AWS Service Terms, and it applies to customers automatically whenever they use AWS services to process personal data. Nothing to sign, no form to submit. Vercel does much the same: its DPA becomes binding when you enter the main agreement, and the standard contractual clauses inside it are treated as signed by that act.

Smaller and regional hosts vary a lot. Some have perfectly good terms and simply don't advertise them. Others will send you a PDF if you email support and ask for the Article 28 addendum. A few have nothing at all, and a company that stores your customers' data but cannot produce processor terms on request has told you something useful about itself.

Whoever you're with, save a copy of the terms as they stood on the day you accepted them, and check that the DPA covers the plan you're actually on. Published pages get rewritten, and some providers scope their terms to particular products or tiers.

What Article 28 actually requires

If you want to know whether what you have is a real contract or a decorative one, here is the checklist. It has to be in writing, which under Article 28(9) includes electronic form, so clicked-through terms do qualify.

It must set out the subject matter and duration of the processing, its nature and purpose, the types of personal data and the categories of people involved, and your rights and obligations as controller. Article 28(3)(a) to (h) then spell out what the processor commits to: acting only on your documented instructions, keeping its staff under confidentiality, applying Article 32 security measures, not bringing in sub-processors except on the terms below, helping you answer data subject requests, helping you with breach notification and impact assessments, deleting or returning the data when the work ends, and giving you the information and audit access you need to verify all of it.

Read your host's DPA against that once. It takes twenty minutes and tells you whether you're holding a compliant contract or a marketing document.

The sub-processor chain

Your host has vendors of its own, and they touch your data too. Article 28(2) says a processor cannot engage a sub-processor without your authorisation. In practice that is nearly always general authorisation given in the DPA, plus notice when the list changes and a window to object. Article 28(4) is the part that protects you: the sub-processor has to be bound by equivalent data protection obligations, and your host stays fully liable to you if that sub-processor fails.

The mechanism is usually visible in the terms. Vercel, for instance, publishes its sub-processor list, lets you subscribe to notifications when it adds one, gives you five days to object on data protection grounds, and if the objection can't be resolved in good faith your remedy is to walk.

Objecting is rare in practice. Knowing the list is still not optional housekeeping, because your privacy policy has to describe who receives personal data and your Article 30 record has to name the recipients. If you've never opened your host's sub-processor page, parts of your own documentation are guesswork.

What it costs you to skip it

A missing Article 28 contract sits in GDPR's lower penalty tier, up to €10 million or 2% of worldwide annual turnover under Article 83(4).

The number is less interesting than how easily the failure gets found. Most GDPR questions turn on judgement about risk, necessity or proportionality. This one doesn't. A supervisory authority asks for the contract with your processor and you either produce it or you don't, which is why it so often shows up as an add-on finding once an authority is already looking at you. The EDPB's first coordinated enforcement action, run by 22 supervisory authorities in 2022 and reported in January 2023, examined exactly this: how public bodies contract with their cloud providers, and how hard it can be to get GDPR-compliant terms out of them.

For most companies, though, the first person to ask won't be a regulator. It'll be a prospect's security reviewer working down a vendor questionnaire, wanting to know who hosts your data and under what contract. Having no answer costs deals long before it costs fines.

Not sure which of your vendors count as processors?

Run a free scanGenerate your Data Processing Agreement — €19