The Data Processing Agreement (DPA) is a mandatory contract under Art. 28 GDPR between a controller (event organizer) and a service provider that processes personal data on their behalf. It governs the subject matter, duration, nature, and purpose of the processing, as well as security and control obligations.
Legal basis: Art. 28 GDPR
Form: Written, including electronic
Sanctions: Up to €10 million / 2% of annual turnover
What is a Data Processing Agreement?
The Data Processing Agreement (DPA) – also known as Data Processing Agreement (DPA) – is a mandatory document under the GDPR. Whenever an event organizer provides personal data to an external service provider that processes it on their behalf, Art. 28 GDPR requires a written contract – before the first data transfer takes place.
In event practice, this is often overlooked: organizers need a DPA with print service providers for name badges, hotels for room blocks, catering services, email marketing providers, and lead retrieval vendors. Failing to do so carries the risk of fines and reputational damage.
When is a DPA necessary?
A DPA is required if:
- Personal data is involved (names, email addresses, identifiers, payment details, etc.)
- A service provider processed on behalf of the controller (not a joint controller, not an independent recipient)
- The processing is not merely an adjunct to another primary service (e.g., a tax advisor is a recipient, not a data processor)
Typical data processors for events:
- Congress management software and SaaS providers
- Email marketing service providers (e.g., newsletter tools)
- Print service providers for badges and program booklets
- Hotels and hotel room block agencies, provided they are acting on behalf of the controller
- Lead retrieval providers
- Web analytics and tracking service providers
- Telephone service providers for hotlines
- Cloud hosting providers and backup providers
Mandatory content
According to Art. 28 (3) GDPR, a data processing agreement must at least contain:
- Subject matter of processing: Which data is processed and for what purpose?
- Duration of processing: How long is the contract term?
- Nature and purpose: Specific operations (storage, transmission, analysis)
- Categories of data subjects (Participants, speakers, sponsors)
- Obligations and rights of the controller
- Technical and organizational measures (TOMs): Encryption, access controls, backup, pseudonymization
- Instruction-based processing: Service provider may only act upon instructions
- Confidentiality obligation of employees
- Handling of sub-processors – List or individual approval
- Data transfer to third countries: Standard contractual clauses, adequacy decisions
- Cooperation and assistance obligations regarding data subject rights
- Notification obligations in the event of data breaches (within hours, not days)
- Audit rights: Organizer may have the service provider audited
- Return or deletion of data after contract termination
Sub-processors
A typical SaaS provider works with other service providers themselves (cloud hosting, email delivery, monitoring). These are sub-processors. The DPA must specify:
- List of existing sub-processors including name, registered office, and purpose of processing
- Approval of additional sub-processors (general vs. individual)
- Notice period for changes
- Right to object for the controller
- Contractually equivalent obligations the sub-processor
Common practical errors
- No DPA with the print service provider for name tags – a common gap
- "Light" DPAs without clearly defined TOMs
- DPA only after contract conclusion instead of before
- Overview of sub-processors is not maintained
- Third-country data transfers not sufficiently regulated (caution with US cloud providers!)
- Outdated versions gathering dust, new contractual situations not reflected
Best practices
- Maintain a DPA list: Which service provider, which DPA, which version, which date?
- DPA before the first data transfer signed, not retroactively
- Standard templates use the industry standard or your own data protection officer
- Sub-processor overview view the platform provider's
- Prefer EU hosting, where possible – reduces third-country complexity
- DPA as a selection criterion treat as a requirement for new service providers
DPA in Converia
Converia provides an up-to-date, legally vetted data processing agreement that has been coordinated with the data protection officers of German universities – available as part of our general terms and conditions and customizable if needed. Includes a sub-processor overview and a summary of technical and organizational measures.
DPA out-of-the-box, not as a special case
At Converia, the data processing agreement is standard, not an add-on – clearly documented and accessible at any time.
- GDPR for events – Compliance & Law
- Payment management – Ticketing & Registration
- Attendee management – Ticketing & Registration
Legally vetted DPA during the onboarding process – including a sub-processor overview.