The Data Processing Agreement With Your Web Agency
By CodexierPublished 4 min read
Most companies think of GDPR in terms of their cookie banner and privacy policy, and forget the agency that builds and maintains their website. Yet that agency often has access to contact form submissions, customer accounts, newsletter lists or the CRM. Under GDPR, that makes it a processor acting on your behalf, and you as the controller must have a written data processing agreement in place, called a personuppgiftsbiträdesavtal in Swedish. This guide explains when you need one and what it must contain.
When the agency becomes a processor
| Agency role | Processor? |
|---|---|
| Designs a site with dummy content and hands it over | Usually not |
| Hosts the site and its form submissions | Yes |
| Maintains a webshop with customer and order data | Yes |
| Sets up and administers your CRM or newsletter tool | Yes, while it has access |
| Runs analytics on your behalf | Yes, for the data it handles |
What the agreement must contain
- Subject, duration, nature and purpose of the processing, the types of personal data and the categories of people concerned.
- That the agency processes data only on your documented instructions.
- Confidentiality obligations for everyone at the agency with access.
- Appropriate technical and organisational security measures.
- Rules for engaging sub-processors, with your prior authorisation.
- Assistance with data subject requests, security, breach handling and impact assessments.
- Deletion or return of data when the assignment ends.
- Your right to information and to audits to verify compliance.
IMY and the European Data Protection Board publish guidance and templates. Many agencies have a standard agreement; read it rather than signing on trust, and check that it matches what the agency actually does for you.
Sub-processors: hosting, email, analytics
Your agency rarely works alone. The hosting provider, email service, form tool, backup service and analytics platform all process the same data and are sub-processors. The agreement should list them or give you a way to see the list and object to changes.
| Sub-processor type | What to check |
|---|---|
| Hosting and backups | Where data is stored, ideally within the EU |
| Email and form delivery | Whether form contents pass through a third-party service |
| Analytics and tag tools | What personal data is sent, and on which legal basis |
| Support and ticket tools | Whether your customers' data ends up in the agency's own systems |
| Providers outside the EU | The transfer mechanism, such as the EU-US Data Privacy Framework or standard contractual clauses |
Security and breach duties
If a personal data breach happens at the agency or a sub-processor, you as controller may need to notify IMY within 72 hours of becoming aware of it. That clock only works if the agency tells you quickly. The agreement should require notification without undue delay, specify what information the agency provides and name contact people on both sides. Our guide to personal data breaches and the 72-hour rule explains the controller's side.
- Ask how access to your systems is controlled: individual accounts, two-factor authentication, removal when staff leave.
- Ask how updates and backups are handled for the site and its plugins.
- Agree how quickly the agency will inform you of a breach, and in what form.
At the end of the contract
When you change agency or end maintenance, the agreement should require the agency to return or delete personal data, including in backups within a stated period, and to confirm it in writing. Combine that with a technical handover: admin access, code, domain and hosting accounts should already be in your name. See our website GDPR checklist for the rest of the site's obligations.
Whichever agency you choose, including us for a website launch, ask for the data processing agreement and sub-processor list before you sign; prices for our work are on the pricing page. When you do not need one: if the agency only designs and hands over a site without ever touching personal data, a DPA is not required, but document that division of roles. To go through your setup, book a free call.
Frequently asked questions
Who is responsible for writing the data processing agreement?
Legally the controller, meaning your company, must ensure it exists. In practice the agency often provides a standard agreement, which you review and sign.
Is a clause in the main contract enough?
It can be, if it covers everything Article 28 requires. Many companies prefer a separate appendix, which is easier to update when sub-processors change.
Does a freelancer need a data processing agreement too?
Yes, the rules are the same. A freelancer with access to your site's data or your CRM is a processor, regardless of the size of the business.
What happens if we have no agreement?
You are not complying with GDPR, and IMY can issue sanctions. More practically, you have no contractual right to demand deletion, breach notification or information when you need it.
Unsure what your agency does with your customers' data?
Tell us who builds, hosts and maintains your site today. In fifteen minutes we can map which roles process personal data and what the agreement should cover.
Book a free 15-minute call