Nobody starts a business to file DPAs. But if you touch website data in the EU, four small documents keep the whole thing standing up. Here they are, without the legal fog.
The four documents
| Document | What it is | When you need it |
|---|---|---|
| Data Processing Agreement (DPA) | Contract with the vendor that touches personal data on your behalf | When you use any tracking/analytics vendor at all |
| Records of Processing (Art. 30) | Internal list of what data you process and why | If you have staff or systematic processing — practically, most companies |
| Breach notification plan | Short internal doc: who does what if data leaks | Before you need it, not after |
| Invoice + retention rules | Standard invoicing, plus how long you keep visitor data | Ongoing |
1. The DPA in one paragraph
A DPA is a contract that says: "you process this data only for the purposes we agreed, you don't sell it, you delete it when I ask, you tell me if something goes wrong." Reputable vendors publish one you can download in two clicks. If a vendor makes it hard, that's information.
Store the signed copy somewhere your team can find it in a hurry. If a customer's procurement person asks, you want a link ready, not a scavenger hunt.
2. Records of Processing (Art. 30)
A one-page list of the things your business does with personal data: newsletter, sales CRM, website analytics, payroll. For each, the purpose, the categories of data, who receives it, and how long you keep it. Boring, but the single most useful document if a regulator ever asks a question.
3. Breach notification — write it before you need it
If personal data leaks, the EU rule of thumb is 72 hours to notify the regulator. You do not want to invent the process in hour 71. A one-page "who calls who" sheet is enough for a small team.
- Who discovers → who confirms → who notifies (name + phone)
- Where the DPA copy is kept
- A short breach description template — filled in advance
Not legal advice
Rules and thresholds differ per country and situation. This is a starting point, not a substitute for a chat with your DPO or lawyer.
4. Invoicing and retention — the boring but important bit
Invoicing is standard: VAT ID, itemised subscription, currency. Retention is where teams slip: they set up tracking and never decide how long visitor data lives. Pick a number (12 months is a common default), write it down, tell your team.
In one line
Sign the DPA, keep an Art. 30 list, write a one-page breach plan, decide your retention. That's 90% of the compliance nervousness gone.
- Related: [Is visitor identification GDPR-compliant?](/blog/is-website-visitor-identification-gdpr-compliant)
- Related: [The CFO's compliance questions — answered](/blog/compliance-questions-your-cfo-will-ask-and-the-answers)
- Related: [What your privacy policy must say](/blog/privacy-policy-paragraph-when-you-identify-companies)
Published by
lead.box Team
More articles
See lead.box on your own traffic
Start free — no card, no sales call required. Or book a 20-minute walk-through if you want the guided tour.
