Blog

Protection of the privacy of parties in contracts: DPA guide for DPOs and lawyers

The priority contractual clause is simple: require in the DPA (article 28 GDPR) that the subcontractor systematically pseudonymizes sensitive data before any transmission, and provides a secure mapping export allowing restitution under the control of the data controller. The absence of this obligation exposes the organization to an administrative sanction, regardless of the behavior of the subcontractor.

In three essential points:

  • Essential clauses: Complete DPA according to article 28 GDPR, with explicit obligation of pseudonymization, completed annexes and formalized right of audit.
  • Technical control: stateless solution (zero storage), automatic detection of personal data (PII), encryption in transit and export mapping for controlled restoration.
  • Audit proof: access logs, PDF reports, secure export mapping and DPIA if applicable, preserved and accessible to the CNIL on request.

Table of contents

Why the contract is at the heart of the protection of personal data

Article 28 GDPR requires a written contract between any data controller and its subcontractor, covering nine mandatory clauses. An incomplete or absent DPA makes the data controller directly liable for sanctions, even if the subcontractor has not committed any fault.

The distinction between data controller and subcontractor is not just a legal formality. It determines who sets the purposes of the processing, who receives documented instructions, and who bears the burden of proof in the event of an audit. A service provider who decides for himself how he processes data becomes co-responsible, with major contractual consequences on compensation and notification obligations.

CNIL doctrine: “The qualification of the actors must be analyzed when the contract is drawn up. Poor qualification leads to unsuitable clauses and an ineffective distribution of responsibilities. »

Source: CNIL Guide - responsibility of actors in public procurement

The privacy policy is a separate document from the DPA: it informs data subjects of the management of their data, while the DPA governs the obligations between professionals. Confusing the two can leave contractual blind spots.


A lawyer analyzing a contract relating to the protection of personal data

Practical checklist: which clauses are mandatory in your DPA?

Article 28 §3 GDPR imposes nine clauses. Here is their status and operational priority:

1. Purpose, duration and nature of the processing - Essential (mandatory). Define precisely what is processed, for how long and for what purpose.

2. Purposes of processing - Essential (mandatory). The processor may only process the data for the purposes documented by the controller.

3. Types of data and categories of data subjects - Essential (mandatory). Annex 1 must be completed; a DPA without complete annexes is legally unusable.

4. Obligations and rights of the data controller - Essential (mandatory). Documented instructions, right of control, right of audit.

5. Personnel confidentiality - Essential (mandatory). Written commitment from each person authorized to access the data.

6. Security measures (article 32 GDPR) - Essential (mandatory). Pseudonymization, encryption, access control, logging.

7. Conditions for subsequent subcontracting - Essential (mandatory). List of authorized subcontractors, back-to-back clause, prior authorization from the manager.

8. Assistance to people's rights - Essential (mandatory). Response times, procedure for processing requests for access, rectification, erasure.

9. Restitution and deletion of data at the end of the contract - Essential (mandatory). Export mapping terms, deletion deadline, proof of destruction.

Recommended in addition: incident notification clause (maximum time for notification to the person responsible without undue delay, and within 24 hours according to good contractual practices), penalty clause and separate confidentiality agreement (NDA) for strategic information not covered by the GDPR alone.


Discover at a glance the essential clauses to include in a data subcontracting agreement thanks to this infographic.

Pseudonymization or anonymization: what obligation should be included in the contract?

Pseudonymization is defined in article 4(5) of the GDPR as the processing of personal data in such a way that it can no longer be attributed to an individual without recourse to additional information kept separately. Pseudonymized data remains personal data: the GDPR continues to apply. This is precisely why it is preferable to anonymization in a contractual context.

Anonymization irreversibly removes any link with the person. Result: the data leaves the scope of the GDPR, but the person responsible also loses all ability to restore it. For a service contract or a data room, this loss of reversibility is often unacceptable.

Key point: Pseudonymization practiced upstream, before sending to a third-party service, limits the quantity of personal data transmitted and reduces the scope of the contractual liability of the data controller. It also simplifies the negotiation of DPAs and can reduce the frameworks required for international transfers, provided that reversibility is strictly controlled and documented.

Concretely, the contract must specify: the pseudonymization method used, the conditions for storing the mapping (restricted access, encryption), the terms of restitution or restoration of the original data, and who holds the re-identification key.


How to write operational clauses on pseudonymization?

Here are formulations that can be used directly in a DPA or a service contract.

Pseudonymization obligation clause:

“The subcontractor undertakes to pseudonymize all personal data appearing in the documents transmitted, prior to any processing or communication to a third party, according to a method compliant with Article 4(5) of the GDPR. The pseudonymization mapping is kept separately, under the exclusive control of the data controller, and can only be reconstituted with its prior written authorization. »

Auditability clause:

“The subcontractor makes access logs, audit reports in PDF format and secure mapping exports available to the data controller, upon request and within five working days. The manager has the right to an annual audit, with ten working days' notice, relating to the technical and organizational measures implemented. »

Pro tip: Systematically associate an NDA with the DPA for strategic information not covered by the GDPR alone. According to Me Valentin Simonnet, the penal clause forfeits the damage in advance and simplifies the sanction in the event of unauthorized disclosure, without the injured party having to demonstrate the extent of the damage. Have these clauses validated by an advisor before signing.


What technical measures should be contracted to pseudonymize your documents?

The measures to be contractually imposed on the subcontractor, in accordance with Article 32 GDPR, cover two levels.

Technical measures:

  • Automatic PII detection on 90+ data types (names, IBAN, social security numbers, health data, etc.)
  • Pseudonymization in real time, without intermediate storage of original documents (stateless mode)
  • Encryption in transit (TLS 1.2 minimum) and at rest (AES-256)
  • Strict access control with principle of least privilege and strong authentication
  • Complete logging of access and pseudonymization operations
  • Secure export mapping, kept separately and accessible only to the data controller

Organizational measures:

  • Mandatory training of authorized personnel, with traceability of authorizations
  • Back-to-back clauses imposed on each subsequent subcontractor
  • Incident management plan with contractual notification deadlines
  • Violation notification SLA (maximum time to the person responsible, then to the CNIL within 72 hours)

For common document formats (PDF, DOCX, data rooms), check that the chosen solution supports these formats natively and offers integration via REST or MCP API to fit into existing flows without interrupting processing.


Public markets: what additional precautions does the CNIL recommend?

In public procurement, the qualification of actors is often more complex than in a private context. A service provider can be a subcontractor for certain operations and a data controller for others, depending on the purposes pursued.

CNIL Recommendation: The agreement must determine in a clear and pragmatic manner the respective obligations of the parties, in particular for the exercise of individual rights. The list of authorized subcontractors must be contractually imposed upon award of the contract.

Source: CNIL Guide - public order

Operationally, form DC4 (list of subcontractors) must be kept up to date and annexed to the contract. Any modification to the subcontracting chain requires prior authorization from the contracting authority. Also provide a clause for validating security measures before starting services, and a right of termination if the technical guarantees become insufficient during execution.


Implementation plan: steps, timeline and resources

PhaseEstimated durationResponsibleDeliverable
Audit of existing treatments-DPO / CISOFlow mapping, identification of missing DPAs
Drafting and validation of the DPA1-3 monthsLawyer / DPODPA signed, complete annexes
Choice and validation of the technical solution1 monthCISO / DSITechnical evaluation report
Pilot (data room or documentary sample)1 monthCISO / business teamPilot report, export mapping test
API deployment and integration1-2 monthsDSI / integratorPut into production, logs activated
Periodic reviewAnnualDPOAudit report, DPA update

The contractual and technical validation stages can take place in parallel for reduce overall delay. The pilot on a restricted scope (an M&A data room or a batch of HR contracts) allows the solution to be validated before deployment on scale.

On costs: a pseudonymization SaaS license is billed per user seat and per volume of pages processed, with additional pack options. Add the API integration cost (variable depending on the complexity of the flows) and, where applicable, an annual external audit. A limited pilot makes it possible to control initial expenses before committing to a larger volume.


How to prove your compliance during a CNIL inspection?

The evidence expected by the CNIL and the auditors is grouped into three categories.

Contractual documents:

  • DPA signed with all annexes completed (description of processing, list of subcontractors, security measures)
  • Additional NDA for strategic information
  • DPIA (impact analysis) for high-risk treatments

Technical evidence:

  • Time-stamped and complete access logs
  • Audit reports in PDF format generated by the solution
  • Secure export mapping, proof of data deletion or restoration

Indicators to follow:

  • Number of accesses to pseudonymized data per period
  • Average time for notifying incidents to the data controller
  • Successful pseudonymization rate on processed documents
  • Average time to return mappings on request

Keep a record of incidents, even minor ones, and contractually provide for the right to audit with notice, defined scope and confidentiality clause on the results. undocumented data breaches are systematically aggravated during checks.


What recommendation should we take to act now?

Contractually constrain pseudonymization in the DPA, require export mapping and formalize the right to audit. Then launch a technical pilot on a restricted area to validate the solution before deployment.

Immediate actions:

1. Verify that each active DPA contains the nine mandatory clauses and complete annexes.

2. Add a pseudonymization clause and an auditability clause to each new contract or renewal.

3. Evaluate a stateless document pseudonymization solution and plan a one-month pilot.


Key points

The contractually imposed pseudonymization in the DPA, coupled with a stateless solution and a formalized right of audit, constitutes the most effective protection of the privacy of the parties in contracts subject to the GDPR.

PointDetails
Contractual obligation (art. 28 GDPR)The DPA must cover the nine mandatory clauses with all complete annexes, under penalty of punishable non-compliance.
Priority pseudonymizationRequiring pseudonymization before any transmission reduces the scope of contractual liability and simplifies DPAs.
Formalized auditabilityRequiring logs, PDF reports and export mapping in the contract guarantees proof of conformity during a CNIL inspection.
Public orderAdapt the clauses according to the CNIL qualification of the actors and keep the DC4 form up to date upon award of the contract.
Safe-docStateless document pseudonymization solution with detection of 90+ types of PII, secure export mapping and PDF audit reports.

What the stateless approach really changes in practice

Most guides on protecting privacy in contracts stop at clauses. It is necessary, but insufficient: a clause requiring pseudonymization without a verifiable technical solution is only a declaration of intent.

What changes with a stateless architecture is the very nature of residual liability. When no original document is stored on the subcontractor side, the scope of the DPA is mechanically reduced. The negotiations are shorter, the annexes less complex, and the risk of leak via Shadow AI disappears from the contractual scope. Teams continue to use their usual AI tools, but sensitive data never reaches them in identifiable form.

Export mapping is the other element that is often underestimated. Without it, pseudonymization becomes a one-way operation: the data is protected, but the data controller loses the ability to restore it. With secure mapping under its exclusive control, reversibility remains possible, GDPR compliance is maintained, and the contract can provide for precise and verifiable restitution obligations.


Safe-doc: stateless pseudonymization ready to integrate into your DPA

Your contracts now require verifiable documentary pseudonymization. Safe-doc meets this requirement with a zero storage architecture: documents are processed in real time, the original data never passes through our servers, and each operation generates a PDF audit report that can be used during a CNIL inspection.

Safe-doc

Detection covers 90+ data types (PII, financial data, health information), with native support for PDF and DOCX formats and REST API integrations to fit into your existing document workflows. The secure export mapping remains under your exclusive control, which directly simplifies the drafting of restitution clauses in your DPA.

To evaluate the integration with your existing DPA and launch a pilot on your document perimeter, request a demonstration or consult the Safe-doc GDPR compliance page.

This article is general information. For your specific situation, consult qualified legal advice and check current requirements with the CNIL.


Sources and references to learn more

  • GDPR text - article 28: legal basis for the contractual obligations of the subcontractor and the nine mandatory clauses of the DPA.
  • CNIL Guide - responsibility of actors in public procurement: doctrine on the qualification of actors, adapted clauses and precautions specific to public procurement.
  • DPA article 28 GDPR model - Legiscope: template and analysis of mandatory clauses, importance of annexes.
  • GDPR and contracts - Yousign: summary of the six essential clauses and good operational practices.
  • Confidentiality agreement (NDA) - Me Valentin Simonnet: legal analysis of the penal clause and the obligation of result in NDAs.
  • Confidentiality Agreement - LegalPlace: practical guide on drafting an NDA, duration, scope and sanctions.
  • GDPR pseudonymization art. 4(5) - Safe-doc: guide to GDPR compliance with pseudonymization and its integration into DPAs.
  • Confidentiality and AI contracts - Safe-doc: articulation between DPA, AI clauses and documentary pseudonymization.

Recommendation