# Data Processing Clause

Source: https://contracko.com/fr/bibliotheque-de-clauses/traitement-des-donnees

# Data Processing Clause

Governs how a processor handles personal data for a controller, as required by GDPR Article 28.

## Ce que c'est

A data processing clause or agreement (DPA) sets the controller-processor terms required by GDPR Article 28: subject matter, duration, instructions, security measures, sub-processing, breach notification and deletion. It is mandatory whenever one party processes personal data on another's behalf.

## Pourquoi c'est important

Without a compliant DPA, both parties breach the GDPR and risk fines and liability for data subjects' claims. The clause allocates security duties and breach-notification timing, which is critical when a data incident occurs.

## Comment l'appliquer

- Document the nature, purpose, duration and categories of data and data subjects.
- Require processing only on documented instructions and appropriate security measures.
- Set sub-processor approval, breach-notification timing and audit rights.
- Address international transfers with an appropriate safeguard (e.g. SCCs).

## Exemple de formulation

> The Processor shall process Personal Data only on the Controller's documented instructions, implement appropriate technical and organisational measures, and notify the Controller without undue delay of any personal data breach.

## Conseils de négociation

- • Controllers should require prompt breach notice (e.g. within 24 to 48 hours) and audit rights.
- • Processors should pre-list approved sub-processors and use a change-notification mechanism.

## Pièges courants

- • Treating the DPA as optional boilerplate rather than a mandatory GDPR requirement.
- • Ignoring international transfer safeguards when the processor sits outside the EEA.

### Comment Contracko aide

Contracko's AI review extracts data processing clauses from your vendor and SaaS contracts and flags any that are missing a sub-processor list, audit rights or breach-notification deadline. All DPAs are held in a central, searchable repository so your privacy team can quickly confirm coverage and locate specific agreements during a supervisory authority audit or a data incident.

## Références juridiques

- [GDPR Art. 28 GDPR: processor obligations Droit de l'UE](https://eur-lex.europa.eu/eli/reg/2016/679/oj)
- Dutch GDPR Implementation Act (Uitvoeringswet AVG)

Sauf mention contraire, les références renvoient au droit néerlandais (Burgerlijk Wetboek, le Code civil néerlandais) ; les instruments de l'UE tels que le RGPD s'appliquent dans toute l'UE. Il s'agit d'informations générales, pas de conseils juridiques. D'autres juridictions traitent ces concepts différemment. Vérifiez le texte en vigueur et votre situation avec un avocat qualifié.

## Pertinent pour

[Logiciels & SaaS](https://contracko.com/fr/secteurs/logiciel-saas)[Entreprises d'IA et de données](https://contracko.com/fr/secteurs/ia-donnees)[Santé](https://contracko.com/fr/secteurs/sante)[Services financiers](https://contracko.com/fr/secteurs/services-financiers)[Fournisseurs de services managés](https://contracko.com/fr/secteurs/prestataires-services-geres)

## Clauses associées

- [Confidentiality Clause](https://contracko.com/fr/bibliotheque-de-clauses/clause-de-confidentialite)
- [Limitation of Liability Clause](https://contracko.com/fr/bibliotheque-de-clauses/limitation-de-responsabilite)
- [Indemnification Clause](https://contracko.com/fr/bibliotheque-de-clauses/clause-indemnisation)

## Termes associés

- [Data processing agreement (DPA)](https://contracko.com/fr/glossaire/accord-de-traitement-des-donnees)
- [GDPR](https://contracko.com/fr/glossaire/rgpd)
- [Confidential information](https://contracko.com/fr/glossaire/informations-confidentielles)

### Ne manquez plus jamais une échéance de contrat

- L'IA repère les dates de renouvellement et de préavis
- Les risques et obligations sont mis en évidence automatiquement
- Les rappels vous aident à agir avant que les dates ne filent

Déposez un contrat pour commencer

PDF, DOCX, PNG ou JPG

[Démarrer l'essai de 7 jours](https://app.contracko.com/register?appLanguage=fr&utm_source=clause_library_sidebar&utm_medium=lead_magnet&utm_campaign=clause_library_sidebar_contract_upload&content_slug=data-processing&content_title=Data+Processing+Clause&cta_placement=clause_library_sidebar_cta&source_tool=clause_library_sidebar_data-processing)

Conforme au RGPD. Chiffré. Jamais utilisé pour l'entraînement de l'IA.

## Foire aux questions

Questions courantes sur cette clause.

- **Q:** When is a data processing agreement required?
  **A:** Whenever one party processes personal data on behalf of another; GDPR Article 28 makes a written agreement mandatory for that controller-processor relationship.

- **Q:** How fast must a data breach be reported between the parties?
  **A:** The processor must notify the controller without undue delay; many DPAs fix a hard deadline (often 24 to 72 hours) so the controller can meet its own reporting duty.

- **Q:** Does a DPA need to be updated when a new sub-processor is added?
  **A:** Yes. The processor must inform the controller in advance and allow a reasonable objection period; simply updating a website list without prior notice may not satisfy the obligation.

- **Q:** Can a processor transfer data outside the EEA?
  **A:** Only with an appropriate safeguard such as Standard Contractual Clauses (SCCs), an adequacy decision or Binding Corporate Rules. The DPA should specify the transfer mechanism used.

- **Q:** What happens if a processor acts outside the controller's instructions?
  **A:** The processor may become an independent controller for that processing and bear full GDPR liability for it, including potential fines and data subject claims.

## Ne manquez plus jamais une clause risquée

Contracko examine automatiquement chaque contrat à la recherche de cette clause et des obligations qu'elle crée.

[Démarrer l'essai gratuit de 7 jours](https://app.contracko.com/register?appLanguage=fr)

Réserver une démo
