DPA with AI Providers: What Article 28 GDPR Requires
If an AI provider processes personal data on your behalf, Article 28 GDPR requires a written DPA. What it must contain and where its limits lie.
In short: yes. If an AI provider processes personal data on your behalf, you need a data processing agreement (DPA). Article 28 GDPR requires it. The contract must be written and must contain fixed elements. Without one, the data sharing has no contractual basis.
When do you need a DPA?
A DPA becomes due as soon as an external provider processes data for you and personal data is involved. You remain the controller, the provider is the processor. The question is not how clever the AI is, but whether personal data flows.
- You enter names, emails or customer data into an AI tool.
- The provider stores or processes this data on its servers.
- You decide purpose and means, the provider carries it out.
- Test or pilot phases count too, once real data flows.
- Anonymising upfront changes the exposure but does not remove the duty.
Mandatory content under Article 28
A DPA cannot be vague. Article 28(3) GDPR sets out exactly what it must contain. First the core details of the processing, then the concrete duties of the provider. These core details frame everything:
- Subject matter and duration of the processing.
- Nature and purpose of the processing.
- Type of personal data.
- Categories of data subjects.
- Rights and obligations of the controller.
A DPA is not a legal basis
This is a common mix-up. A DPA governs how a provider works on your behalf. It does not say whether you are allowed to process the data at all. These are separate bricks. Do not confuse them.
- The legal basis comes from Article 6 GDPR, not from the DPA.
- A data protection impact assessment (DPIA) may also be needed.
- Technical measures alone do not replace the contract.
- The DPA governs the relationship, not the permission.
- All the bricks must be in place together.
Transfers outside the EU
Many AI providers sit in the US or process data there. That means data leaves the EU. The rules in Articles 44 and following GDPR then apply. You need extra safeguards, usually standard contractual clauses.
- Check where the provider actually processes data.
- Standard contractual clauses (SCCs) are the common instrument.
- An adequacy decision can ease the transfer.
- A transfer impact assessment often supplements the clauses.
- Review the DPA and the transfer safeguards together.
AI offerings in practice
Not every AI offering provides a usable DPA. Free or private consumer versions often do not. Business, Enterprise or API plans, by contrast, frequently do. Do not rely on assumptions, read the provider documentation.
- 1According to OpenAI, its Enterprise and API offerings provide a data processing addendum.
- 2According to Google, a Cloud Data Processing Addendum applies as part of the contract.
- 3Consumer chatbots without a business plan often provide no contract.
- 4The exact scope depends on the plan you choose.
- 5Check the date of the documentation, because policies change.
| Duty under Art. 28(3) | What it means | Your practical question |
|---|---|---|
| Documented instructions | The provider processes data only on your documented instructions | Is this stated in the contract? |
| Confidentiality | Staff are bound to confidentiality | Is this guaranteed? |
| Security (Art. 32) | Technical and organisational measures protect the data | Which measures does the provider name? |
| Sub-processors | Further providers only with approval and equal duties | Who are the sub-processors? |
| Data subject rights | Support with access, deletion and other rights | Is there a process for this? |
| Deletion and audits | Return or deletion at the end, plus evidence and audits | Can you verify this? |
This is where ONYRI works on the principle of data minimisation (Art. 5 GDPR). The tool detects sensitive data in your text and replaces it with reversible tokens before the text reaches the AI. The mapping of token to value stays in the browser and is never sent to the server. After the response, the real values are restored. Important and honest: this is pseudonymisation, not anonymisation. Pseudonymised data remains personal data (Recital 26 GDPR). ONYRI reduces exposure, but replaces neither a DPA nor a legal basis.
Takeaway: the DPA is mandatory, but only one brick. Sharing less data lowers your risk on top. Both together is the solid path.
Frequently asked questions
- Do I need a DPA for ChatGPT or Gemini?
- As soon as you enter personal data and the provider processes it on your behalf, yes. According to OpenAI and according to Google, such contracts are available in the Enterprise, Business or API offerings. Check the current documentation of the provider in question.
- Is a DPA the same as a legal basis?
- No. The DPA governs how the provider works on your behalf. The permission to process comes from Article 6 GDPR. These are two separate bricks, and both must be in place.
- What happens without a signed DPA?
- Then the data sharing lacks the contractual basis required by Article 28 GDPR. That is a breach and can lead to complaints or fines. Settle the contract before productive use.
- Is pseudonymisation enough instead of a DPA?
- No. Pseudonymised data remains personal data (Recital 26 GDPR). Minimisation lowers your risk, but replaces neither the DPA nor the legal basis. Both stay necessary.
Sources & references
- GDPR Regulation (EU) 2016/679, Art. 28, 32, 44 ff. — EUR-Lex
- European Data Protection Board — EDPB
- Enterprise Privacy and Data Processing Addendum — OpenAI (vendor documentation)
- Cloud Data Processing Addendum — Google (vendor documentation)
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.