
IT, Privacy & Cybersecurity
ICT Projects part 9: the Data Processing Agreement
1 April 2025
There is hardly any IT project imaginable where personal data is not processed. When personal data is processed, both the controller and the processor are required under Article 28 of the GDPR to draw up a data processing agreement. Compliance with this legal obligation is important, if only because the mere fact that no data processing agreement has been concluded can lead to a fine from the Data Protection Authority. When are you a 'controller' or 'processor' and what requirements are imposed on a data processing agreement?