Data protection clauses: what happens to personal data?
When a vendor handles personal data for you, the contract must say how. Learn what a DPA is, controller vs. processor, breach notification windows, and the clauses regulators expect to see.
The short answer
A data protection clause (often a full Data Processing Agreement, or DPA) sets the rules when one side handles personal data for the other: what data, what they may do with it, how it is secured, how fast they must tell you about a breach, and what happens to the data when the contract ends. If a vendor will touch your customers' or employees' personal data, privacy law in most countries requires this clause to exist.
Controller vs. processor
Privacy law splits the world into controllers (who decide why data is processed) and processors (who handle it on the controller's instructions). If you hire an email platform, a payroll provider, or an analytics tool, you are usually the controller and they are the processor.
The controller carries most of the legal responsibility — which is why you, as the customer, need the contract to control the vendor, not the other way round.
What a DPA must cover
Under GDPR-style laws, the clause must specify the subject and duration of processing, the types of data, the vendor's obligation to act only on your instructions, confidentiality, security measures, rules for sub-processors, help with data-subject requests, breach notification, and deletion or return of data at the end.
If a vendor processes personal data for you with no DPA at all, that is not a grey area — in the EU and similar regimes it is simply unlawful, and the fine risk lands on you.
- Instructions only — the vendor uses data only as you direct.
- Security — named, specific measures, not "industry standard".
- Sub-processors — who else touches the data, and your right to object.
- Breach notice — a deadline in hours, not "without undue delay".
- Exit — deletion or return of data, with proof, when the contract ends.
Breach notification windows
When a vendor suffers a breach affecting your data, the clock starts ticking — under GDPR you may have 72 hours to notify your regulator, and you cannot notify about a breach you do not know about.
Look for a hard commitment: "within 24 (or 48) hours of becoming aware". Vague language like "promptly" or "as required by law" gives the vendor room you do not have.
International transfers and AI training
If the vendor stores or processes data in another country, check the transfer mechanism (standard contractual clauses, adequacy decisions). Transfers without a legal mechanism are a common audit failure.
A newer question: does the vendor use your data to train AI models? Many DPAs are now negotiated on exactly this point. If the contract is silent, assume silence is not protection — get a written no, or a written opt-out.
Sample clause language
Illustrative wording, written for this guide — not copied from any real contract.
Processor shall notify Controller of any personal data breach without undue delay and in any event within 24 hours of becoming aware, shall not engage sub-processors without prior written authorisation, and shall not use personal data to develop or train any machine-learning model.
Hard breach deadline, sub-processor control, and an explicit AI-training ban.
Vendor will take reasonable steps to protect data and will inform Customer of security incidents as appropriate. Vendor may use aggregated data for service improvement.
No deadline, no detail, and 'aggregated data for service improvement' can cover almost anything.
Red flags to look for
- No DPA at all for a vendor who will obviously touch personal data.
- Breach notification with no time limit.
- Unlimited rights to engage sub-processors without telling you.
- Broad rights to use your data for "service improvement" or "product development" — often code for AI training.
- No obligation to delete or return data when the contract ends.
What to ask for
- Set a concrete breach notification window: 24–48 hours from awareness.
- Require prior notice and an objection right for new sub-processors.
- Add an explicit ban on using your data to train models, or a clear opt-out.
- Name the security measures in an annex rather than accepting "industry standard".
- Require certified deletion within a fixed period after termination.
Find this clause in your own contract
Upload a PDF, Word file, or image and Lawly AI will pull out the clauses that matter, quote the exact wording, and explain the risk in plain English.
Frequently asked questions
Do I need a DPA for every software tool I use?
If the tool processes personal data for you — customer emails, employee records, user analytics — then under GDPR-style laws, yes. Reputable vendors have a standard DPA ready; if a vendor refuses to sign one, treat that as a serious warning.
Who gets fined if my vendor mishandles data?
Often both of you, but the controller — usually you, the customer — carries the primary responsibility. That is why the contract terms matter: they are your main lever over someone else's security.
What are standard contractual clauses?
Pre-approved contract terms that make it legal to send personal data from the EU (and similar regimes) to countries without an adequacy decision. Most international vendors incorporate them into their DPA.
Related guides
This guide is general educational information about how these clauses usually work. It is not legal advice, and contract law differs by jurisdiction. For a decision that matters, speak to a qualified lawyer.