Data processing on behalf in practice: When is a contract required?


Definition, practical cases and typical errors
In many companies, collaboration with external service providers is carried out quite naturally in the background. The website is managed by an agency, a cloud tool stores customer data, and the IT service provider has regular access to systems and mailboxes. However, one point is often overlooked in this context: the contract for order processing.
Not infrequently, such a contract is completely lacking, even though personal data is long since being processed by external providers. Often, it is not even consciously acknowledged that there is actually a data protection law requirement.
Because the GDPR does not require a review of even routine business processes to be carried out for large projects or sensitive special cases. Even everyday business processes can constitute processing of orders, making an AV contract mandatory.
From a consulting perspective, it is evident that these „everyday“ situations are particularly often overlooked in practice, with sometimes significant legal and organizational consequences.
What does order processing actually mean??
The term “order processing” refers to the processing of personal data by an external service provider on behalf of and under the instructions of the company.
What is important here is that the service provider does not decide on the purpose and means of the processing itself, but acts solely on behalf of the contracting company.
The legal basis for this is found in Article 28 of the GDPR. It clearly states that such cooperation is only permitted with a corresponding contract.
For companies, this means in practice: As soon as a service provider is involved in the processing of personal data, it must be checked early on whether there is a requirement to obtain prior consent and therefore the obligation to conclude an AV contract.
When a contract is required
An AV contract is always necessary when a service provider not only accidentally sees personal data, but actually processes it for the company.
Typical examples are:
In these cases, a normal service contract is not sufficient. Without an AV contract, a central data protection legal basis is lacking.
In practice, this means that even long-established service provider relationships should be regularly reviewed to ensure that the data protection legal classification remains valid. Especially in the case of large IT infrastructures, there are often unnoticed gaps.
When an AV contract is not necessary
Not every external contact involving personal data automatically constitutes processing of orders. A classic example is the tax advisor. This person usually works independently and is subject to their own legal obligations. Therefore, they is usually not a processor of orders.
Banks, postal service providers, and many small businesses often do not fall under Article 28 of the GDPR, even if they come into contact with personal data.
The crucial question is always: Does the service provider work under direction for the company or does it pursue its own goals and have its own legal responsibilities?.
It is this demarcation that is often incorrectly assessed in everyday life. From a consulting perspective, this demarcation is one of the most common factors of uncertainty. Misjudgments lead either to unnecessary effort or, in the more critical case, to missing contracts and thus to real compliance risks.
Typical errors in practice
The most common mistake is not signing an unnecessary contract, but the complete absence of an AV contract. Many companies have been using external software providers, website service providers, or cloud solutions for years without ever checking whether order processing is in place.
This particularly affects historically established structures. Systems were introduced, providers were changed, and processes were expanded without the data protection agreements being followed. At the latest when a review is conducted by the supervisory authority or after a data breach, this gap becomes visible.
Then it quickly becomes clear that not only the contract is missing, but often also the documentation, the testing of the service provider, and the contractual protection of technical protective measures.
In practice, it is often evident that order processing cannot be viewed in isolation. The absence of contracts often goes hand in hand with other deficiencies, such as the service provider audit, documentation in the record of processing activities, and the implementation of technical and organizational measures.
What companies should do now
The first step is an honest assessment of the current situation. Only then can a clear assessment be made of where actual action is needed.
Equally important is the quality of existing contracts. Many AV contracts are outdated, formulated too broadly, or do not sufficiently take into account current requirements such as third-party transfers, sub-contractors, or technical safeguards.
A signed contract alone is not enough. The actual collaboration must also be organized in a data protection-compliant manner.
Especially in large-scale structures, a complete overview is often lacking. Only a systematic examination reveals which service providers actually fall under the scope of contract processing and where there is a need for action.
From a consulting perspective, a structured approach is advisable: First, a complete overview of all service providers used should be compiled. Subsequently, the data protection-related classification and the review of existing contracts should be carried out. Only on this basis can measures be prioritized and implemented efficiently.
An early legal assessment of data protection helps avoid unnecessary risks and establish existing processes in a legally sound manner. Often, many uncertainties can be quickly and pragmatically resolved through a structured examination.
Conclusion
Data processing on behalf is one of the topics that are often overlooked in everyday business life. Not because companies deliberately choose to avoid it, but because many people simply do not realize that an AV contract is even necessary. That is precisely why it is worthwhile taking a close look at existing service providers and processes.
For companies, this means in concrete terms: The review of service providers should not be a one-time process, but rather a permanent part of a functioning data protection management system.
Those who conduct or have their premises inspected early on establish clear responsibilities, reduce liability risks, and prevent unpleasant surprises from inspections or incidents.
Often, it is only during a structured inventory that one realizes how many data protection gaps have already arisen in everyday life. This is exactly where effective and practical data protection management begins.
From our experience, it is evident that a structured initial review creates significant transparency and quickly makes existing risks visible. This is where effective and practical data protection management comes into play.
FAQ
What is order processing?
An order processing agreement exists when an external service provider processes personal data on behalf of a company and under its instructions. The service provider does not, in principle, determine the purposes of the processing itself.
When is a contract for order processing required?
A contract for the processing of orders (AV contract) is required when an external service provider processes personal data for your company on a binding basis. The legal requirements for this result from Article 28 GDPR.
Which service providers often require an AV contract?
Typical examples are cloud and software providers, hosting service providers, external payroll services, IT service providers with system access, newsletter tools, applicant management systems, or document destruction services.
Do I need an AV contract with every service provider?
No. Not every service provider that comes into contact with personal data is automatically a processor. What is crucial is whether the service provider acts under the direction of instructions or processes personal data on their own initiative.
Do I need an AV contract with my tax advisor?
As a rule, no. Tax advisors usually process personal data on their own responsibility and are subject to their own legal and professional obligations. Therefore, they are generally not processors of orders.
How do I recognize if there is an order processing system in place?
An important question is: Does the service provider process the personal data solely for your company and according to your specifications? If so, there is much to suggest that it is being processed on behalf of the company. However, if the service provider pursues its own objectives or decides independently on the processing, there may be a separate responsibility.



