This page provides a practical guide: who is who in your relationship with a software vendor, what a processing agreement must contain, what questions to ask before signing, and what mistakes small businesses commonly make. At the end — a ready action plan for two hours.


Who is who in the relationship with a software vendor
GDPR distinguishes three roles that may apply to your business:
Controller — this is you as the business owner or manager. You decide why and how customer data is processed. You are responsible for the entire process, even if you do not physically do anything — the controller bears liability when something goes wrong.
Processor — this is the CRM vendor, booking system, SMS gateway, VoIP provider, or any other software that processes personal data on your behalf. It does so on your instruction, not on its own initiative.
Sub-processing — situation when your vendor uses services of another entity. Example: the CRM vendor hosts data on an external server or sends SMS through an external gateway. Then you need an agreement with that sub-processor as well.
- 01Customer
- →02company (controller)
- →03CRM vendor (processor)
- →04their hosting (sub-processor)
According to Article 29 GDPR, the processor and any person acting under the controller's authorization who has access to personal data shall process it only on the controller's instructions. The controller must have control over who and to what extent has access to data.
Why this matters for your business
As the controller, you are responsible for everything that happens with customer data. Even if you do not process data yourself — you are responsible for the vendor. If the vendor leaks data, UODO will come to you, not to them. That's why it's worth knowing who you are entrusting data to and what their obligations are.
Vendor map: what to check
Before you start looking for agreements, list all services you use. Many small businesses are unaware of how many tools actually process customer data. This table will help you organize this process:
| Service | What customer data it processes | Is there a processing agreement? | Where is the agreement? | Who connected it? |
|---|---|---|---|---|
| CRM | name, phone, email, contact history | yes / no / don't know | … | … |
| Online booking system | contact details, date, service | yes / no / don't know | … | … |
| SMS gateway | phone number, message content | yes / no / don't know | … | … |
| VoIP telephony | phone number, call recordings | yes / no / don't know | … | … |
| Email marketing tool | email, name | yes / no / don't know | … | … |
| Contact form on website | data from form | yes / no / don't know | … | … |
| Cloud storage (e.g. Google Drive, Dropbox) | documents with customer data | yes / no / don't know | … | … |
| Messenger (e.g. WhatsApp Business) | phone, message content | yes / no / don't know | … | … |
Most often forgotten items are free website plugins, trial versions of tools, and services connected by an employee on their own account. Each of these is a potential gateway to your customer data — and a potential gap in your processing chain.
Typical tools you forget about
Many firms forget about tools that seem "free" or "unimportant." But each of them processes customer data: website form plugins, survey tools, free CRMs with ads, apps for handling Instagram or Facebook messages. Even if you use them "on trial" — the responsibility for data is the same.
What a processing agreement must contain according to UODO
UODO specifies exactly what a data processing agreement should contain. These are not recommendations — these are elements without which the agreement does not meet legal requirements:
| Agreement element | What it means | Question to ask the vendor |
|---|---|---|
| Subject matter and duration of processing | What exactly the vendor does and for how long | How long will you process data? Will data be deleted after the agreement ends? |
| Nature and purpose of processing | For what purpose and how data is processed | What exactly do you use this data for? |
| Type of data | What categories of data (e.g., name, phone, email, address) | What specific data do you process? |
| Categories of data subjects | Whose data (e.g., customers, employees) | Whose data do you process — customers, employees, contractors? |
| Controller's obligations and rights | What the controller can demand from the processor | How can I verify that the agreement is actually being implemented? |
| Confidentiality commitment | Whether vendor's employees are bound by non-disclosure | Who in your company has access to my data? |
| Technical and organizational requirements | How the vendor secures data | What security measures do you use? |
| Conditions for sub-processing | Whether the vendor uses subcontractors | Do you use other companies to process my data? |
| Duty to assist the controller | In fulfilling data subject rights and breach notifications | What does your assistance look like when fulfilling customer rights? |
UODO emphasizes that the agreement must be in writing — this also applies when the vendor offers "terms acceptance" as a form of agreement. The terms may be an element of the agreement, but terms alone do not replace a written processing agreement. Read more about where data physically ends up in the article Automation and GDPR.
What this means in practice
A processing agreement is not a document you download from the internet and sign. It must be an agreement tailored to your situation. If you use five different tools, you need five separate agreements — or one "extended" agreement if the vendor offers it. But you cannot assume that one agreement for everything automatically covers all services.
Verifying the vendor before signing
The mere fact that a vendor offers a processing agreement does not mean you can simply sign it. UODO indicates that the controller must verify whether the processor provides sufficient guarantees of implementing appropriate technical and organizational measures.
Before signing the agreement, ask the vendor these questions:
- Where are the servers physically located? Does data leave the European Economic Area?
- Who has access to the data? How many employees and on what basis?
- What does the breach notification process look like? How quickly will I be informed if there's a leak?
- What happens to data after the cooperation ends? Will I get it back, or will it be deleted?
- Do you use subcontractors? If so — who are they and do I need to sign agreements with them too?
- What security certifications do you have? (ISO 27001, SOC 2, etc.)
- Do you conduct regular security audits?
Do not settle for generic answers like "the data is safe." Ask for specific responses in writing — you are the one answerable to UODO, so you need something to refer to in case of an inspection.
Learn more about the vendor verification process in the comparison n8n vs Make — the article shows how to analyze tools for security.
Sulkowicki Cultural Centre case — real UODO fine
In a real case, UODO imposed a fine of two thousand five hundred PLN on Sulkowicki Cultural Centre for entrusting data processing without a written processing agreement and without verifying whether the processor provides sufficient guarantees. Importantly — this was about bookkeeping services, records, reports, and document storage. This was not some "exotic" vendor, but a standard accounting service.
The processing agreement should have specified, among other things: subject matter and duration, nature and purpose of processing, type of data, categories of data subjects, controller's obligations and rights. Sulkowicki Cultural Centre had no such agreement — and paid the fine. Read more about this case in the official UODO announcement: Powierzenie przetwarzania danych trzeba udokumentować.
For a small business, this amount is not an amount that will ruin the business. But it shows that UODO takes even minor violations seriously. And more importantly — Sulkowicki Cultural Centre had to subsequently sign an agreement and comply with requirements. It is better to do this early than to pay a fine and then chase losses.
McDonald's Polska case — real UODO fine
In a real case, UODO imposed a total fine of over sixteen million PLN on McDonald's Polska and nearly two hundred thousand PLN on the processor 24/7 Communication for entrusting employee data to an external company for workforce scheduling without verifying whether the processor ensured appropriate safeguards.
What went wrong:
- No risk analysis before entrusting data.
- No verification whether the processor applies appropriate safeguards.
- Processing agreement was signed but not actually enforced — no audits or inspections.
- The processor used another entity without a sub-processing agreement.
UODO emphasized that the controller and processor are jointly liable — and both sides faced consequences. An agreement is not a document you file away and forget. It is a living agreement that must be enforced. Details of this case are available in the UODO announcement: Data protection is the responsibility of both the controller and the processor (in Polish).
Sub-processing — when your vendor uses subcontractors
When your CRM vendor uses external hosting, and the SMS gateway uses an external operator, we are talking about sub-processing. Article 28(4) and (9) GDPR requires that the processor may use sub-processors only based on a separate sub-processing agreement.
In the McDonald's case, one of the problems was precisely that 24/7 Communication used another entity without a sub-processing agreement. Even if your vendor is "solid" — check whether their subcontractors also have agreements.
Questions for the vendor:
- What external services do you use in processing my data?
- Are there sub-processing agreements with those entities?
- Can I know the names of those entities?
- What is the process for verifying subcontractors?
Processing agreement lifecycle — from selection to termination
A processing agreement is not a one-time document. It is a process that accompanies the entire lifecycle of cooperation with the vendor:
- 01Vendor selection
- →02verification of guarantees
- →03signing
- →04regular verification
- →05review when scope changes
- →06cooperation end (return or delete)
Verifying agreement implementation is not a formality. In the McDonald's case, the agreement was signed, but nobody checked whether it was actually being enforced. Regular questions like "did you conduct an audit?" or "how many people had access to data in the last quarter?" are standard, not aggression.
Learn more about common mistakes firms make when implementing automation in the article Errors when implementing automation — they often relate to security and data processing issues.
Common small business mistakes
Many small businesses make the same mistakes that then cost them time and money:
Service connected on an employee's "card" — one employee sets up an account with a service using their own email, without the owner's knowledge. The company has no agreement, does not know where data is processed, cannot retrieve it after the employee leaves.
Free tier without an agreement — many tools offer free versions without a data processing agreement. This does not mean data is not being processed. It means processing happens at the company's risk.
Exporting database to external tool "on trial" — upload customer list to a new marketing tool to "test how it works." Without agreement, without verification, without control. Classic violation scenario.
No verification when changing vendors — company switches CRM to another but does not check what happens with old data. Was it deleted? Is it still being processed somewhere?
Compare different approaches to automation in the article Custom Automation vs Ready-Made SaaS — sometimes a ready-made solution with one vendor is less risky than dozens of separate tools.
Do it yourself in two hours — action plan
This is not a task for weeks. You can do basic verification in about two hours:
Step 1: List all tools (20 minutes) Open the table above and write down all services you use. Do not skip free plugins, trial versions, and tools connected by employees.
Step 2: Find agreements (40 minutes) Go to each vendor's website and look for "Data Processing Agreement" (DPA) or "Terms" section. Download the document. If it's not there — this is the first warning signal.
Step 3: Fill the table (30 minutes) For each tool, write: whether agreement exists, what it contains, where it is stored, who is responsible for vendor contact.
Step 4: Identify gaps (20 minutes) Mark tools without agreements or with incomplete agreements. These are your priorities.
Step 5: Act (10 minutes) Start with the most critical tools — those processing the most customer data (CRM, bookings, SMS).
If you have doubts — a specific case is worth consulting with a lawyer or Data Protection Officer (DPO). Some situations require individual assessment, especially when data is of a special type or the processing scale is large.
How it looks in a modern system
Fewer separate tools means fewer processing agreements to manage, fewer places where customer data is stored, and less risk that something will slip through. Instead of five separate services (CRM, calendar, SMS, email marketing, phone) — one platform where everything is in one place.
In a CRM and automations system all channels — phone, form, messengers and Google Business card — record in one place. Confirmation comes right away, reminder arrives a day before and a few hours before the appointment.
This does not mean the processing agreement becomes unnecessary. On the contrary — you still need to verify the vendor and sign an agreement. But managing one agreement instead of five is simply less work and less risk.
Learn more about integrations in the article CRM or ERP — the difference between one integrated system and many separate tools directly affects the number of agreements and risk.
If you want to see how one system looks instead of many separate tools, check Aura integrations — connecting POS, calendar, CRM and other services into one data flow. Learn more about customer data — one customer card instead of five lists in five systems. See how API works — programmatic access to system data and actions. A dedicated admin panel gives you one place to manage all data operations with role-based access.
Frequently asked questions
Does the processing agreement need to be in writing?
Yes. UODO clearly states that the data processing agreement must be in writing. Accepting terms or clicking "I agree" in a user panel is not sufficient. The document should contain all the elements mentioned above: subject matter, duration, nature and purpose of processing, type of data, categories of data subjects, controller's obligations and rights.
What if the vendor does not offer a processing agreement?
This is a warning signal. If the vendor refuses to sign an agreement or says "terms are enough" — consider a different vendor. Without a processing agreement, you risk a fine from UODO and bear full responsibility as the controller. Some companies offer an agreement as an attachment to terms — this may be acceptable, but make sure the document is signed and contains all required elements.
Do I need to sign an agreement with every vendor?
Not every vendor is a processor. If a vendor processes data for their own purpose (e.g., payment provider processes data within their own payment service, not on your instruction), you do not need a processing agreement. But if the vendor processes data on your behalf, according to your instructions — you need an agreement. Have doubts? Consult with a DPO or lawyer.
Can I use free tools without an agreement?
Using a free tool does not relieve you of the obligation to have an agreement if the tool processes personal data on your behalf. Many free versions of CRM or email marketing tools process data on your instruction — therefore require an agreement. The fact that you do not pay for the service does not mean you are not responsible for customer data.
What must a sub-processing agreement contain?
A sub-processing agreement (when your vendor uses subcontractors) should contain the same elements as a processing agreement, plus information about who the sub-processor is. As a controller, you have the right to know exactly who processes your customers' data. If your vendor refuses to provide information about subcontractors — this is a serious warning signal.
How often should I verify agreement implementation?
We recommend at least once a year. Ask the vendor about security audit results, check whether the scope of services or subcontractors has changed. In case of major changes (e.g., server location change, new subcontractors) — immediately request agreement updates. In the McDonald's case, the agreement was signed, but nobody verified its implementation — this led to a huge fine.
Can I sign one agreement for all tools from one vendor?
It depends on what the vendor offers. Some offer an "extended" agreement covering all their services — this is convenient. Others require separate agreements for each product. In both cases, make sure the agreement actually covers all services you use and that all elements are in writing.
What if the vendor disappears from the market?
This is one of the most often overlooked scenarios. Before signing the agreement, ask: what happens to data if cooperation ends? Most will answer that data will be deleted or returned. But it is worth having this in writing. In case of vendor bankruptcy, data recovery can be very difficult — therefore it is worth regularly archiving data on your own side.