Skip to main content
Beta! Dokumentasjonen er automatisk generert. Informasjonen kan være ufullstendig og inneholde feil, spesielt skjermbilder og videoer. Se Om hjelpesidene. Vi vil veldig gjerne ha innspill: Kontakt oss via «Fant du det du lette etter?» nederst, i chatten nede til høyre eller på support@placepoint.no – vi svarer så fort vi kan!

Data processing agreement

A data processing agreement is the written contract that must be in place when a business lets someone else process personal data on its behalf, for example a management company that keeps the tenant register for an owner, or a system supplier that stores the data in the cloud. The agreement sets out what the supplier is allowed to do with the data, and it is a requirement under GDPR Article 28. The parties cannot opt out of it, and a service cannot be taken into use before it is signed.

The roles decide who needs the agreement. The controller decides the purpose of the processing, the processor carries it out on assignment. Article 28(3) of the General Data Protection Regulation requires the agreement to set out the subject matter of the processing, the duration, the nature and the purpose, the type of personal data and the categories of data subjects. It must also require the processor to process the data only on documented instructions, keep it confidential, meet the security requirements in Article 32, assist the controller when data subjects ask for access or erasure, delete or return everything when the assignment ends, and submit to audits. The agreement must be in writing, and electronic form is sufficient.

Sub-processors are the point where most agreements are thin. A processor cannot engage another processor without written permission, and if the permission is given generally, the controller must be notified of new or replaced sub-processors and be able to object to the change. The processor is fully liable to the controller for the sub-processor meeting its obligations. A usable agreement therefore has an annex listing the sub-processors with name, service and country of operation. If one of them sits outside the EEA, the transfer needs its own basis under Chapter V of the Regulation. The European Commission's standard contractual clauses for controllers and processors can be used as a template, and Datatilsynet (the Norwegian Data Protection Authority) has its own guide to the content.

In property, the split of roles is usually clear once you look for it. The Landlord is the controller for information about the tenants in a tenancy under husleieloven (the Norwegian Tenancy Act), while the manager, the accountant and the system supplier are processors. In due diligence, the data room supplier is a processor for the seller. Exchanging tenant lists between seller and buyer in a property transaction, on the other hand, is a disclosure between two controllers, and no data processing agreement helps there: each party must have its own legal basis for processing. A breach of Article 28 can lead to fines of up to 10 million euros or 2% of global annual turnover under Article 83(4), and the liability for damages under Article 82 applies to both parties.

Placepoint is the controller for the property and company data we collect and pass on, including data from Grunnboken (the Norwegian land register) and matrikkelen (the Norwegian cadastre). If you send personal data into the service yourself, for example a national identity number in a lookup or a bulk extract you order, we process it on your assignment, and we then enter into a data processing agreement under Article 28. What the template covers is described in Integration and security.

From Placepoint's dictionary: Data processing agreement

More information: Datatilsynet: Databehandleravtale, Lovdata: General Data Protection Regulation Article 28, European Data Protection Board: Guidelines 07/2020 on the concepts of controller and processor

English: Data processing agreement (DPA), the controller-to-processor contract required by GDPR Article 28.

Frequently asked questions

When do I need a data processing agreement?

When an external party processes personal data on your assignment: a manager, an accountant, a data room supplier, IT operations or a cloud service. The agreement must be in place before the processing starts. If both parties are controllers, as with seller and buyer in a property transaction, it is a disclosure and not a processing assignment, and each party then needs its own legal basis under GDPR.

What must the agreement contain?

Purpose, duration, type of data and categories of data subjects, and the processor's obligations: being bound by instructions, confidentiality, security measures, assistance with access and erasure, deletion or return on termination, and access to audits. An annex should list the sub-processors with service and country of operation, since transfers out of the EEA require their own legal basis.

Who is responsible if the processor makes a mistake?

The controller answers for the choice of supplier and for the instructions, but the processor can be fined directly for its own obligations and is fully liable for the sub-processors it uses. Towards the data subject, both can be held liable for damages.

Do I need a data processing agreement with Placepoint?

For the property and company data we pass on, such as information from Grunnboken about the registered owner, Placepoint is the controller, and it is then not a processing assignment. If you send personal data into a lookup or an extract, we process it on your assignment, and we enter into a data processing agreement for that.

Beta! Dokumentasjonen er automatisk generert. Informasjonen kan være ufullstendig og inneholde feil, spesielt skjermbilder og videoer. Se Om hjelpesidene. Vi vil veldig gjerne ha innspill: Kontakt oss via «Fant du det du lette etter?» nederst, i chatten nede til høyre eller på support@placepoint.no – vi svarer så fort vi kan!