What a Data Processing Agreement Means When You Use AI

If an AI provider processes personal data on your behalf, you need a data processing agreement — in German, an Auftragsverarbeitungsvertrag or AVV. Article 28 GDPR requires it. It is not a formality, and the details differ meaningfully between providers.

What it establishes

The agreement fixes the roles. You are the controller: you decide why and how personal data is processed, and you remain responsible to the people whose data it is. The provider is the processor: they act only on your documented instructions.

That relationship carries specific consequences, and the contract is where they are written down.

What must be in it

Art. 28(3) lists the required content. In practice you are checking for:

  • Subject matter, duration, nature and purpose of the processing, plus the categories of data and of data subjects. Usually an annex — read it, because a vague annex means nobody thought about your case.
  • Processing only on documented instruction, including for transfers to third countries.
  • Confidentiality obligations on the provider's staff.
  • Security measures under Art. 32. These should describe what is actually implemented, not a generic list.
  • Sub-processor terms — who they are, how changes are notified, whether you can object.
  • Assistance with data subject rights — access, deletion, portability requests.
  • Assistance with breach notification and with impact assessments.
  • Deletion or return at the end of the relationship.
  • Audit rights — information and inspection.

What to look at closely for AI services

The sub-processor list. Every AI provider has them. If the list is absent or says "as published on our website", ask for a copy and a notice commitment with a defined period and a right to object.

The training question. This should be explicit: your data is not used to train models, covering third-party models as well as the provider's own. A website claim is not a contractual term.

Prompts as data. Your users will type unpredictable things. The agreement should cover input data and generated output, not just the documents you formally upload.

Processing location. A named region, contractually fixed, with any exceptions identified. Watch for ancillary processing — monitoring functions in particular — that may sit elsewhere.

Deletion in practice. Ask specifically about backups. Data usually persists there longest, and a deletion clause silent on backups is incomplete.

What people get wrong

Assuming terms of service suffice. They do not. The Art. 28 agreement is a separate instrument.

Signing without reading the annexes. The substance lives there — the security measures, the sub-processors, the processing description. The main body is largely standard; the annexes are where providers differ.

Forgetting that responsibility stays with you. The agreement allocates duties; it does not transfer your accountability as controller. If something goes wrong, the person whose data it was comes to you.

Never revisiting it. Sub-processors change and services evolve. If your provider notifies a change and nobody reads the notification, the objection right you negotiated is worthless.

A reasonable expectation

A serious provider will have a standard agreement ready, will send it before you ask twice, and will answer questions about processing location and sub-processors precisely. Difficulty at this stage is informative about what operating with them will be like.

This article is general information, not legal advice. For your specific situation, consult a qualified lawyer.

All Articles
Let’s Talk

about the process
AI should run.