Template ready for practices: appointment of the data processor

Operating model and checklist for appointing the data processor in the firm. Guidelines on sub-processors, non-EU transfers, and...

Ready-to-use template for practices: appointment of the data processor

The appointment of the data processor is mandatory when an external supplier processes data on behalf of the controller, and it must be done in writing: this is required by Art. 28 of the GDPR. The contract must specify the nature, duration, and purpose of the processing, the types of data involved, and the categories of data subjects. Further down, you will find an operational template ready to be adapted to your practice or company.

In brief:

  • The appointment of the data processor is mandatory only for external entities processing data on behalf of the controller, not for authorized internal personnel.

  • The controller must identify, evaluate, and formalize the appointment, verifying that the candidate offers adequate technical and organizational security guarantees.

  • The written contract must include the subject matter, duration, purpose, categories of data and data subjects, instructions from the controller, security measures, and methods for returning or deleting the data.

  • For sub-processors, prior written authorization from the controller is required, along with compliance with information, notification, and contractual liability rules, with the option to object to changes.

  • The lack of a formalized agreement can lead to penalties and difficulties in demonstrating compliance during audits or incidents.

Treatbase Simplifies practice management Treatbase reduces manual transcriptions and paper management, helping dental practices work with greater efficiency. Discover Treatbase

Index

  • What is the data processor appointment and when should it be done

  • Who appoints and who can be appointed: parties and responsibilities

  • Essential elements of the appointment contract: what to include and how to draft it

  • Obligations of the processor and guarantees to verify during the appointment phase

  • Sub-processors: how to manage the chain and the controller's right to object

  • Practical template: step-by-step appointment contract outline

  • Special cases: transfers outside the EU and large-scale processing

  • Operational checklist before formalizing the appointment

  • Risks and liabilities in case of missing or incorrect appointment

  • Official resources to verify regulations

  • Why the appointment is not just paperwork: a practical perspective

  • How practice management software can simplify the document management of clinical data

  • Sources

What is the data processor appointment and when should it be done

The data processor, according to Art. 4 of the GDPR, is the entity that processes personal data on behalf of the controller, following their instructions. The controller remains the decision-maker: they establish the purposes and means of the processing, while the processor executes.

In the daily practice of a clinic or business, the appointment is triggered every time an external party accesses personal data to perform a service. Some recurring examples:

  • The vendor managing the cloud infrastructure or the management software in use

  • The consulting firm processing payroll

  • The company offering website hosting or email services

  • The partner managing IT backup or cybersecurity

No appointment is needed, however, for internal personnel authorized to process data (employees, direct collaborators): in that case, we refer to authorization to process, not an external processor, because there is no third party distinct from the controller.

Who appoints and who can be appointed: parties and responsibilities

The data controller has the duty to identify, evaluate, and formalize the appointment. This is not a choice to be delegated lightly: before signing, they must verify that the candidate offers adequate guarantees regarding technical and organizational measures, as required by Art. 28 par. 1 of the GDPR.

Who can receive the assignment? In practice, almost any type of structure:

  • Legal entities, such as IT service companies or accounting firms

  • Small and medium-sized enterprises offering outsourced services

  • Public bodies processing data on behalf of other administrations

  • Consultants and freelancers who access data to carry out a specific task

It is useful to immediately distinguish between two figures that are often confused: the external data processor is a third party, legally distinct from the controller, while the authorized internal personnel work under the direct authority of the controller itself and do not require a separate appointment deed.

Essential elements of the appointment contract: what to include and how to draft it

Art. 28 par. 3 of the GDPR precisely lists what the written contract must contain. This is not an optional list: missing one of these points exposes the agreement to disputes in the event of an audit or data breach.

  1. Subject matter, duration, and purpose of the processing. Specify how long and for what exact purpose the processor will process the data, avoiding generic phrases like "for business purposes".

  2. Categories of data and data subjects. List whether it involves common, sensitive, or judicial data, and who the individuals involved are (employees, clients, patients).

  3. Documented instructions of the controller. The processor can only process the data according to written instructions, never at their own discretion.

  4. Technical and organizational measures. These must be described with precision, not referenced vaguely.

  5. Data return or deletion clauses. At the end of the contract, the agreement must establish what happens to the remaining data.

An advice: avoid copying generic clauses from templates found online without adapting them. An instruction like "process the data according to current regulations" is not enough: the EDPB requires concrete operational instructions, verifiable in the event of an inspection.

Obligations of the processor and guarantees to verify during the appointment phase

Before signing, the controller must check that the processor offers sufficient guarantees, as required by Art. 28 par. 1 of the GDPR. self-certification is not enough: verifiable elements are needed.

The technical measures to be explicitly requested include:

  • Encryption of data at rest and in transit

  • Regular backup systems with restoration tests

  • Role-based access control and activity logs

  • Periodic training of the personnel processing the data

  • Confidentiality commitments signed by each involved collaborator

  • An up-to-date record of processing activities

The EDPB guidelines indicate that the appointment deed is the contractual pillar that defines the scope of responsibilities, and they recommend periodically verifying the suppliers upstream of the processor as well.

An advice: insert an audit clause in the agreement with access to logs and proof of encryption. Without this possibility, verifying the promised guarantees remains an act of faith, not a control.

Sub-processors: how to manage the chain and the controller's right to object

The processor cannot outsource the processing at will. Art. 28, par. 2 and 4, requires written authorization from the controller, which can be specific (for each individual sub-supplier) or general (valid for a category of suppliers).

With general authorization, the processor must still:

  • Inform the controller of any intended changes concerning the sub-processors

  • Grant a reasonable timeframe for the controller to object to the change, often contractually set at 30 days

  • Impose equivalent obligations on the sub-processor as those assumed in the main contract

  • Remain fully liable to the controller for the performance of the sub-processor

Contractual clauses must clarify who is responsible in the event of a breach by the sub-supplier: a gap here is one of the most frequent causes of litigation between controller and processor in the event of an incident.

Practical template: step-by-step appointment contract outline

A well-written appointment contract follows a recurring structure, which you can adapt to your sector. Here is the recommended index:

  1. Preamble. Identification of the parties, reference to the main service contract.

  2. Subject matter and duration. Brief description of the assignment and period of validity.

  3. Instructions of the controller. Detailed list of authorized operations.

  4. Security measures. Reference to a detailed technical annex.

  5. Sub-processors. Rules for authorization and notification.

  6. Return and deletion of data. Timelines and methods at the end of the relationship.

  7. Mandatory attachments. List of processing activities, technical measures, any security certifications.

A real example of this structure can be viewed in the appointment agreement published by CREA, which contains standard clauses on data return, audits, and sub-processor liability.

On an operational level, acceptance can take place with a qualified digital signature or an advanced electronic signature, provided the system retains certain proof of the date and identity of the signatory. Keep the original together with the technical annexes for the entire duration of the contractual relationship, and beyond.

Special cases: transfers outside the EU and large-scale processing

If the processor transfers data outside the European Economic Area, the appointment deed alone is not enough: it must be integrated with standard contractual clauses (SCC) or other equivalent guarantees recognized by European regulations.

For large-scale or particularly sensitive processing, it is advisable to strengthen the agreement with additional elements:

  • A data protection impact assessment (DPIA) shared with the provider before starting the service

  • More thorough periodic audits, with documentary verification of the declared measures

  • A cyber liability insurance policy with a limit adequate to the risk

As observed by ESG360, this type of integration is particularly relevant for cloud providers and healthcare services, where the volume and sensitivity of the processed data significantly raise the risk level in case of an incident.

Operational checklist before formalizing the appointment

Before writing the contract, gather all the necessary information: avoid discovering gaps halfway through drafting.

  • Full identification details of the controller and processor (company name, registered office, privacy contact)

  • Detailed list of entrusted processing operations, with categories of data and specific purposes

  • Categories of involved data subjects (employees, clients, patients, suppliers)

  • Provider's security documentation: certifications, audit reports, internal policies

  • List of any sub-processors already involved in the service

  • Planned procedures for returning or deleting data at the end of the relationship

With this list ready, drafting the contract becomes a task of compilation, not improvisation.

Risks and liabilities in case of missing or incorrect appointment

The absence of a written contract does not exempt anyone from the liabilities already existing in the processing relationship: this is confirmed by legal commentaries on Art. 28. In practice, both the controller and the processor can find themselves exposed to administrative fines and, in some cases, joint liability towards the injured data subjects.

The real problem emerges in the event of a data breach or audit: without a formalized contract, reconstructing who was supposed to do what becomes complicated, and the lack of documentary evidence aggravates the position of both parties. Cyber liability insurance and periodic audits remain the most concrete measures to mitigate the risk.

Official resources to verify regulations

To learn more or download templates, these sources remain the most solid point of reference:

Why the appointment is not just paperwork: a practical perspective

A well-crafted appointment deed does not just serve to avoid penalties: it becomes the proof that a practice can show during an audit or investigation by the Data Protection Authority. Those who manage clinical data can find value in tools that automatically document access and processing, making it easier to demonstrate the guarantees promised in the contract.

— Matteo

How practice management software can simplify the document management of clinical data

Practice management software can be a practical ally for a dental clinic that needs to demonstrate, not just declare, the guarantees provided in the appointment contract: every access to patient data can be automatically recorded, without scattered papers or paper files to organize manually.


Treatbase

The software manages patient medical records with continuous activity tracking, which is especially useful when the controller needs to demonstrate to the Authority or a client that the technical measures described in the appointment deed are actually in place. The management of payments follows the same principle: sensitive data processed with verifiable logs, rather than notes scattered across different software.

This article does not constitute legal advice: for the final drafting of the appointment contract, consult a lawyer specializing in data protection. To see how Treatbase organizes the document management of your daily activities, discover the platform and request a direct trial with your clinic's data.

Sources

Recommended

Contacts

Request DEMO

info@treatbase.it

Treatbase S.r.l. - Via Gaetano Donizetti 4 – 00198 Rome (RM) - VAT / Fiscal Code: 18041701006 - PEC: treatbase@legalmail.it

Contacts

Request DEMO

info@treatbase.it

Treatbase S.r.l. - Via Gaetano Donizetti 4 – 00198 Rome (RM) - VAT / Fiscal Code: 18041701006 - PEC: treatbase@legalmail.it

Treatbase S.r.l
Via Gaetano Donizetti 4 - 00198 Rome (RM)
VAT number / Tax code: 18041701006
PEC: treatbase@legalmail.it

Contacts

Request DEMO

info@treatbase.it

Privacy Policy Cookie Policy