Legal · July 3, 2026 · 7 min read

Invoicing, DPA, data breaches: the paperwork behind website tracking, sorted

Every tool that touches website data drags a little paperwork with it. Here is a plain-language map of the four documents you actually need — what they are, where they live, and how not to be scared of them.

Abstract navy grid with three stacked folder outlines representing sorted paperwork.

Nobody starts a business to file DPAs. But if you touch website data in the EU, four small documents keep the whole thing standing up. Here they are, without the legal fog.

The four documents

DocumentWhat it isWhen you need it
Data Processing Agreement (DPA)Contract with the vendor that touches personal data on your behalfWhen you use any tracking/analytics vendor at all
Records of Processing (Art. 30)Internal list of what data you process and whyIf you have staff or systematic processing — practically, most companies
Breach notification planShort internal doc: who does what if data leaksBefore you need it, not after
Invoice + retention rulesStandard invoicing, plus how long you keep visitor dataOngoing
The paperwork that matters — and what it isn't.

1. The DPA in one paragraph

A DPA is a contract that says: "you process this data only for the purposes we agreed, you don't sell it, you delete it when I ask, you tell me if something goes wrong." Reputable vendors publish one you can download in two clicks. If a vendor makes it hard, that's information.

Store the signed copy somewhere your team can find it in a hurry. If a customer's procurement person asks, you want a link ready, not a scavenger hunt.

2. Records of Processing (Art. 30)

A one-page list of the things your business does with personal data: newsletter, sales CRM, website analytics, payroll. For each, the purpose, the categories of data, who receives it, and how long you keep it. Boring, but the single most useful document if a regulator ever asks a question.

3. Breach notification — write it before you need it

If personal data leaks, the EU rule of thumb is 72 hours to notify the regulator. You do not want to invent the process in hour 71. A one-page "who calls who" sheet is enough for a small team.

  • Who discovers → who confirms → who notifies (name + phone)
  • Where the DPA copy is kept
  • A short breach description template — filled in advance

Not legal advice

Rules and thresholds differ per country and situation. This is a starting point, not a substitute for a chat with your DPO or lawyer.

4. Invoicing and retention — the boring but important bit

Invoicing is standard: VAT ID, itemised subscription, currency. Retention is where teams slip: they set up tracking and never decide how long visitor data lives. Pick a number (12 months is a common default), write it down, tell your team.

In one line

Sign the DPA, keep an Art. 30 list, write a one-page breach plan, decide your retention. That's 90% of the compliance nervousness gone.

  • Related: [Is visitor identification GDPR-compliant?](/blog/is-website-visitor-identification-gdpr-compliant)
  • Related: [The CFO's compliance questions — answered](/blog/compliance-questions-your-cfo-will-ask-and-the-answers)
  • Related: [What your privacy policy must say](/blog/privacy-policy-paragraph-when-you-identify-companies)
lead.box Team

Published by

lead.box Team

More articles

See lead.box on your own traffic

Start free — no card, no sales call required. Or book a 20-minute walk-through if you want the guided tour.

Start free trial

Notes on GDPR B2B lead intelligence

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links