When it applies at all, and who is who
A data processing agreement becomes necessary when someone processes personal data on your behalf and according to your instructions. The roles are determined by the actual circumstances: whoever decides on the purposes and essential means is the controller, regardless of the heading in the contract.
The roles follow from the actual activities in the specific situation, not from the formal designation, for example in a contract.
For AI tools, this results in a chain, not a single contract: you are the controller, the tool provider is the processor, the model provider a sub-processor. And beware of the reverse direction: a processor that adds its own purposes, such as product improvement, model evaluation or abuse detection across customers, becomes a controller itself for that processing (Art. 28(10) GDPR). That is exactly where the point of contention lies in many AI contracts.
The mandatory contents
Art. 28 GDPR requires a contract or other binding legal act that governs the following points:
- Subject matter and duration of the processing
- Nature and purpose
- Types of personal data and categories of data subjects
- Documented instructions, including on transfers to third countries
- Confidentiality of the persons involved and security under Art. 32
- Prior specific or general written authorisation of sub-processors, and equivalent obligations passed on to them
- Assistance with data subject rights, security incidents, impact assessments and prior consultation
- Deletion or return after the end of the service, including existing copies
- Evidence and audits
- Immediate notification if an instruction appears to be unlawful
The annex that is almost always missing
“Usage data and content” is not a list. With an agent tool, far more flows than a standard form provides for, and anything not listed in the annex is not covered by an instruction either:
- Inputs, instructions and conversation history;
- Excerpts from documents, file names, folder structures, project context;
- Tool outputs: command outputs, search results, retrieved pages, logs;
- Identity, sign-in, role, device and access data;
- Credentials and secrets that may turn up along the way, including security findings;
- Support bundles, error reports and attachments;
- Operational, usage and security data, and assessments derived from them;
- Special categories under Art. 9 and data under Art. 10 GDPR that may occur incidentally, which is practically unavoidable in personnel files, expert reports or legal briefs.
On top of that come the clauses worth fighting for in negotiations: no training and no product improvement on your content without separate, technically enforced approval; retention and human review disclosed per provider, model and version; deletion also in queues, caches and backups, with evidence; advance notice and a genuine right to object for new sub-processors.
Sub-processors: the list that should be available at all times
Controllers should have information on the identity, i.e. name, address and contact person, of all processors and sub-processors available at all times, regardless of the risk of the processing. The obligation to verify sufficient guarantees likewise applies regardless of the risk; only the depth of the verification depends on the measures.
“Cloud and AI partners” is therefore not enough. What you need is a register in which each entry states: legal entity, address, service, model (where relevant), country of processing, country of support access, transfer mechanism and the date of the last review. This list is the real work; the contract is the easier part.
The mistake with the standard clauses
The Commission has adopted two different sets of clauses: Implementing Decision (EU) 2021/915 for contracts between controllers and processors under Art. 28(7) GDPR, and Implementing Decision (EU) 2021/914 for transfers to third countries. The clauses for processing do not replace an assessment under Chapter V GDPR. Which mechanism supports a transfer, such as an adequacy decision or standard contractual clauses with an assessment of the third country, has to be determined separately; this is explained in the article on US providers and third-country transfers.
Example ChatGPT: which plan has a DPA?
This question comes up most often for ChatGPT, and the answer depends on the plan. A data processing agreement, which OpenAI calls the “Data Processing Addendum” (DPA), exists only for the business offerings: according to its first sentence, the OpenAI Services Agreement, which the DPA supplements, applies only to the API, ChatGPT Enterprise, ChatGPT Business and other services for businesses and developers, not to consumers. In the personal plans, OpenAI itself is the controller; the privacy policy for Europe names OpenAI Ireland Limited for this.
| Plan | Role of OpenAI | Data processing agreement (DPA) | Contracting party for customers in the EEA |
|---|---|---|---|
| Free, Go, Plus, Pro | Controller | No; the privacy policy applies | OpenAI Ireland Limited as controller |
| ChatGPT Business | Processor | Yes, as part of the Services Agreement | OpenAI Ireland Ltd. |
| ChatGPT Enterprise | Processor | Yes, as part of the Services Agreement | OpenAI Ireland Ltd. |
| API | Processor | Yes, as part of the Services Agreement | OpenAI Ireland Ltd. |
Measured against this article, the DPA covers the list of sub-processors with notice of every change and a 30-day objection period, audits at most once a year, transfers outside the EEA via standard contractual clauses or an adequacy decision, and return or deletion after the contract ends. The annex on types of data, by contrast, remains general: according to Annex 1, they depend on your use and “may” include names and contact details. You therefore have to record yourself which data actually goes in at your company, ideally in your AI policy. The rest of the data protection picture around ChatGPT is explained in the article ChatGPT at work.
What this means for Biwak
| DPA | Ready to downloadThe European Commission's standard contractual clauses (Implementing Decision 2021/915) with completed annexes, part of the terms and conditions for businesses, without a signature. The TOMs are in Annex III, the subprocessors in Annex IV. biwak.ai/avv (in German). |
|---|---|
| What is transferred | Question, context, file contentsFor every model request, inputs, the required conversation context and the file contents used go to the language model. The files themselves stay in the working folder on your computer. |
| Sub-processors | Named, with one gapThe privacy policy names the recipients with their addresses; for model requests, Supabase Pte. Ltd (Singapore, database in Frankfurt am Main), Microsoft Ireland Operations Limited (Dublin, processing in Azure's EU Data Zone; Microsoft's DPA in the version of 22 May 2026 is in place with Microsoft) and, for the fallback route, PREM SA (Lugano, Switzerland). Prem names the compute partners behind it, Nebius and TensorX, in its privacy policy; the DPA with Prem has not yet been signed. Section 14. |
| Storage and training at the model provider | Promised, with exceptionsAccording to the provider, inputs are not stored and not used for training. This is stated in its documentation; Microsoft's DPA additionally ties processing to the provision of the service and rules out profiling, advertising and market research. On Microsoft Azure, according to Microsoft, inputs are not accessible to other customers or to the model makers; however, conspicuous requests may be stored for abuse detection and reviewed by humans, with storage in Germany. Prem, the fallback route, binds its partners contractually, without technical safeguards. |
| Account and billing | Sign-in and usage dataBiwak processes sign-in and usage data for access, quotas and billing in a database in Frankfurt am Main. An account is required even for the one-off 100 trial credits. |
| This website | Host as processorVercel Inc., USA, with standard contractual clauses under Art. 46 GDPR; listed in section 9 of the privacy policy. |
Measured by its own standard, the same applies to Biwak: read Annex IV of the agreement. For each subprocessor, it states what is secured by contract and what is only stated in that subprocessor's documentation, and none of the model providers has expressly committed itself under Section 203 StGB. So continue to check carefully which personal data you put into tasks.
Frequently asked questions
We received a form from the provider. Is that enough?
Check two places. First, the annex: does it list the types of data that really flow in your case, or just “usage data”? Second, the sub-processors: does each entry state the legal entity, country and transfer mechanism, or just a generic label? Both gaps are common, and both stand out in an audit.
What should you check for Biwak model access?
Three points. Between you and Biwak, our DPA based on the EU standard contractual clauses applies to businesses; it can be read at biwak.ai/avv, and its annexes name the measures and subprocessors. Between Biwak and Microsoft, Microsoft's DPA applies, version of 22 May 2026. The chain is set out in sections 9 and 14 of the privacy policy: first Microsoft Azure in the EU Data Zone, alternatively PREM SA with its compute partners Nebius and TensorX. And for the third-country question: Microsoft Ireland Operations Limited in Dublin, although according to Microsoft the EU Data Zone may also include EFTA states such as Norway and Switzerland; PREM SA in Switzerland with an adequacy decision; Vercel and Supabase with standard contractual clauses.
What if the provider wants to use our data for improvements?
Then, for that processing, it is no longer a processor but a controller, with its own legal basis, its own transparency obligation and its own compatibility assessment. By default, this should be excluded in the contract. Any approval must be separate, specific, clear about roles and technically enforceable; for employee data, consent for this is particularly open to challenge.
Is it enough if the provider presents “ISO 27001”?
No. A certificate proves a management system, not a legal basis and not a transfer mechanism. It is a good building block when assessing sufficient guarantees under Art. 28(1) GDPR, and replaces neither the contract nor the annex nor the third-country assessment.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 28
- EDPB: Guidelines 07/2020 on the concepts of controller and processor, version 2.1
- EDPB: Opinion 22/2024 on obligations when relying on processors and sub-processors
- Implementing Decision (EU) 2021/915 (standard contractual clauses under Art. 28(7) GDPR)
- Implementing Decision (EU) 2021/914 (standard contractual clauses for third-country transfers)
- OpenAI: Data Processing Addendum, valid since 1 January 2026 (checked on 24 September 2026)
- OpenAI: Services Agreement, scope (checked on 24 September 2026)
- OpenAI: EU Privacy Policy, as of 24 August 2026, section 12
- Biwak: Privacy policy, sections 9 and 14
This text is not legal advice. It is the groundwork we had to do for ourselves, with the legal references, so that your lawyer does not have to start from scratch. Where a question depends on your circumstances, the text says so.
