Independent comparison · no paid rankings
Home / Blog / Compliance / Data processing agreement: commitments to require from a host

Data processing agreement: commitments to require from a host

A generic DPA appendix is not enough — documented instructions, sub-processor list, 72-hour breach notice and TIA support are what a hosting contract must guarantee.

Hébergeurs.eu Editorial Team 2 min read Updated Jul 19, 2026

You sign a "GDPR compliant" VPS. The DPA is a two-page PDF: "the provider commits to comply with regulation." No sub-processor list, no breach deadline, no deletion procedure at termination. One year later, client audit: blocked.

The data processing agreement (DPA) under Art. 28 is not boilerplate. It is the contract obliging the host to process personal data only on documented instruction.

Non-negotiable clauses (minimum)

Subject and duration — exact product (shared Pro, VPS Gravelines), duration aligned with hosting contract.

Nature and purpose — hosting, code execution, storage, infra logs.

Documented instructions — ticket, runbook or framework contract; no processing outside instruction.

Confidentiality — staff accessing data.

Security Art. 32 — encryption, access control, backups, tests.

Sub-processors — list + change notification + objection right.

Assistance rights, DPIA, breach — breach notification deadline (≤72 h), supervisory authority cooperation.

Contract end — deletion/return + certificate.

ClauseWeak signalStrong signal
Sub-processors"Trusted partners"Dated PDF list + 30-day notice
Breach"Per applicable law"≤72 h + details provided
Deletion"Best efforts"30-day deadline + certificate
Location"European Union"Region + backup exclusions

Refuse or negotiate

Clauses excluding all breach liability. Audit prohibition. Free transfer outside EU without mechanism. DPA covering "global offer" without your product.

The peak: the DPA protects the controller, not sales

Decide and move forward without blind spots

  1. Download DPA before signing — not after.
  2. Check Art. 28 checklist point by point.
  3. Map upstream sub-processors (CDN, support, hardware).
  4. Align register and transfers outside EU.

Guides, directory.

Frequently asked questions

Host always processor?

Yes if processing per your instructions; no if it sets its own purposes.

Standard DPA acceptable?

After reviewing scope, sub-processors, breach, deletion.

SCCs with EU host?

If upstream US chain or transfer outside EU.

Contract end?

Deletion/return + certificate + max deadline.


A solid DPA reads in measurable obligations — not "full compliance" on the sales slide.

HDS & compliance hosts

Filter European hosts by HDS, ISO and data residency.

Browse HDS hosts
Blog

Related reading

All articles →