Template ready for practices: appointment of the data processor
Operating model and checklist for appointing the data processor in the firm. Guidelines on sub-processors, non-EU transfers, and...

Ready-to-use template for practices: appointment of the data processor
The appointment of the data processor is mandatory when an external supplier processes data on behalf of the controller, and it must be done in writing: this is required by Art. 28 of the GDPR. The contract must specify the nature, duration, and purpose of the processing, the types of data involved, and the categories of data subjects. Further down, you will find an operational template ready to be adapted to your practice or company.
In brief:
The appointment of the data processor is mandatory only for external entities processing data on behalf of the controller, not for authorized internal personnel.
The controller must identify, evaluate, and formalize the appointment, verifying that the candidate offers adequate technical and organizational security guarantees.
The written contract must include the subject matter, duration, purpose, categories of data and data subjects, instructions from the controller, security measures, and methods for returning or deleting the data.
For sub-processors, prior written authorization from the controller is required, along with compliance with information, notification, and contractual liability rules, with the option to object to changes.
The lack of a formalized agreement can lead to penalties and difficulties in demonstrating compliance during audits or incidents.
Treatbase Simplifies practice management Treatbase reduces manual transcriptions and paper management, helping dental practices work with greater efficiency. Discover Treatbase
Index
What is the data processor appointment and when should it be done
Who appoints and who can be appointed: parties and responsibilities
Essential elements of the appointment contract: what to include and how to draft it
Obligations of the processor and guarantees to verify during the appointment phase
Sub-processors: how to manage the chain and the controller's right to object
Practical template: step-by-step appointment contract outline
Special cases: transfers outside the EU and large-scale processing
Operational checklist before formalizing the appointment
Risks and liabilities in case of missing or incorrect appointment
Official resources to verify regulations
Why the appointment is not just paperwork: a practical perspective
How practice management software can simplify the document management of clinical data
Sources
What is the data processor appointment and when should it be done
The data processor, according to Art. 4 of the GDPR, is the entity that processes personal data on behalf of the controller, following their instructions. The controller remains the decision-maker: they establish the purposes and means of the processing, while the processor executes.
In the daily practice of a clinic or business, the appointment is triggered every time an external party accesses personal data to perform a service. Some recurring examples:
The vendor managing the cloud infrastructure or the management software in use
The consulting firm processing payroll
The company offering website hosting or email services
The partner managing IT backup or cybersecurity
No appointment is needed, however, for internal personnel authorized to process data (employees, direct collaborators): in that case, we refer to authorization to process, not an external processor, because there is no third party distinct from the controller.
Who appoints and who can be appointed: parties and responsibilities
The data controller has the duty to identify, evaluate, and formalize the appointment. This is not a choice to be delegated lightly: before signing, they must verify that the candidate offers adequate guarantees regarding technical and organizational measures, as required by Art. 28 par. 1 of the GDPR.
Who can receive the assignment? In practice, almost any type of structure:
Legal entities, such as IT service companies or accounting firms
Small and medium-sized enterprises offering outsourced services
Public bodies processing data on behalf of other administrations
Consultants and freelancers who access data to carry out a specific task
It is useful to immediately distinguish between two figures that are often confused: the external data processor is a third party, legally distinct from the controller, while the authorized internal personnel work under the direct authority of the controller itself and do not require a separate appointment deed.
Essential elements of the appointment contract: what to include and how to draft it
Art. 28 par. 3 of the GDPR precisely lists what the written contract must contain. This is not an optional list: missing one of these points exposes the agreement to disputes in the event of an audit or data breach.
Subject matter, duration, and purpose of the processing. Specify how long and for what exact purpose the processor will process the data, avoiding generic phrases like "for business purposes".
Categories of data and data subjects. List whether it involves common, sensitive, or judicial data, and who the individuals involved are (employees, clients, patients).
Documented instructions of the controller. The processor can only process the data according to written instructions, never at their own discretion.
Technical and organizational measures. These must be described with precision, not referenced vaguely.
Data return or deletion clauses. At the end of the contract, the agreement must establish what happens to the remaining data.
An advice: avoid copying generic clauses from templates found online without adapting them. An instruction like "process the data according to current regulations" is not enough: the EDPB requires concrete operational instructions, verifiable in the event of an inspection.
Obligations of the processor and guarantees to verify during the appointment phase
Before signing, the controller must check that the processor offers sufficient guarantees, as required by Art. 28 par. 1 of the GDPR. self-certification is not enough: verifiable elements are needed.
The technical measures to be explicitly requested include:
Encryption of data at rest and in transit
Regular backup systems with restoration tests
Role-based access control and activity logs
Periodic training of the personnel processing the data
Confidentiality commitments signed by each involved collaborator
An up-to-date record of processing activities
The EDPB guidelines indicate that the appointment deed is the contractual pillar that defines the scope of responsibilities, and they recommend periodically verifying the suppliers upstream of the processor as well.
An advice: insert an audit clause in the agreement with access to logs and proof of encryption. Without this possibility, verifying the promised guarantees remains an act of faith, not a control.
Sub-processors: how to manage the chain and the controller's right to object
The processor cannot outsource the processing at will. Art. 28, par. 2 and 4, requires written authorization from the controller, which can be specific (for each individual sub-supplier) or general (valid for a category of suppliers).
With general authorization, the processor must still:
Inform the controller of any intended changes concerning the sub-processors
Grant a reasonable timeframe for the controller to object to the change, often contractually set at 30 days
Impose equivalent obligations on the sub-processor as those assumed in the main contract
Remain fully liable to the controller for the performance of the sub-processor
Contractual clauses must clarify who is responsible in the event of a breach by the sub-supplier: a gap here is one of the most frequent causes of litigation between controller and processor in the event of an incident.
Practical template: step-by-step appointment contract outline
A well-written appointment contract follows a recurring structure, which you can adapt to your sector. Here is the recommended index:
Preamble. Identification of the parties, reference to the main service contract.
Subject matter and duration. Brief description of the assignment and period of validity.
Instructions of the controller. Detailed list of authorized operations.
Security measures. Reference to a detailed technical annex.
Sub-processors. Rules for authorization and notification.
Return and deletion of data. Timelines and methods at the end of the relationship.
Mandatory attachments. List of processing activities, technical measures, any security certifications.
A real example of this structure can be viewed in the appointment agreement published by CREA, which contains standard clauses on data return, audits, and sub-processor liability.
On an operational level, acceptance can take place with a qualified digital signature or an advanced electronic signature, provided the system retains certain proof of the date and identity of the signatory. Keep the original together with the technical annexes for the entire duration of the contractual relationship, and beyond.
Special cases: transfers outside the EU and large-scale processing
If the processor transfers data outside the European Economic Area, the appointment deed alone is not enough: it must be integrated with standard contractual clauses (SCC) or other equivalent guarantees recognized by European regulations.
For large-scale or particularly sensitive processing, it is advisable to strengthen the agreement with additional elements:
A data protection impact assessment (DPIA) shared with the provider before starting the service
More thorough periodic audits, with documentary verification of the declared measures
A cyber liability insurance policy with a limit adequate to the risk
As observed by ESG360, this type of integration is particularly relevant for cloud providers and healthcare services, where the volume and sensitivity of the processed data significantly raise the risk level in case of an incident.
Operational checklist before formalizing the appointment
Before writing the contract, gather all the necessary information: avoid discovering gaps halfway through drafting.
Full identification details of the controller and processor (company name, registered office, privacy contact)
Detailed list of entrusted processing operations, with categories of data and specific purposes
Categories of involved data subjects (employees, clients, patients, suppliers)
Provider's security documentation: certifications, audit reports, internal policies
List of any sub-processors already involved in the service
Planned procedures for returning or deleting data at the end of the relationship
With this list ready, drafting the contract becomes a task of compilation, not improvisation.
Risks and liabilities in case of missing or incorrect appointment
The absence of a written contract does not exempt anyone from the liabilities already existing in the processing relationship: this is confirmed by legal commentaries on Art. 28. In practice, both the controller and the processor can find themselves exposed to administrative fines and, in some cases, joint liability towards the injured data subjects.
The real problem emerges in the event of a data breach or audit: without a formalized contract, reconstructing who was supposed to do what becomes complicated, and the lack of documentary evidence aggravates the position of both parties. Cyber liability insurance and periodic audits remain the most concrete measures to mitigate the risk.
Official resources to verify regulations
To learn more or download templates, these sources remain the most solid point of reference:
The text of Art. 28 of the GDPR with practical commentary
The EDPB guidelines on controller and processor
The agreement template published by CREA as a concrete example
Why the appointment is not just paperwork: a practical perspective
A well-crafted appointment deed does not just serve to avoid penalties: it becomes the proof that a practice can show during an audit or investigation by the Data Protection Authority. Those who manage clinical data can find value in tools that automatically document access and processing, making it easier to demonstrate the guarantees promised in the contract.
— Matteo
How practice management software can simplify the document management of clinical data
Practice management software can be a practical ally for a dental clinic that needs to demonstrate, not just declare, the guarantees provided in the appointment contract: every access to patient data can be automatically recorded, without scattered papers or paper files to organize manually.

The software manages patient medical records with continuous activity tracking, which is especially useful when the controller needs to demonstrate to the Authority or a client that the technical measures described in the appointment deed are actually in place. The management of payments follows the same principle: sensitive data processed with verifiable logs, rather than notes scattered across different software.
This article does not constitute legal advice: for the final drafting of the appointment contract, consult a lawyer specializing in data protection. To see how Treatbase organizes the document management of your daily activities, discover the platform and request a direct trial with your clinic's data.
Sources
Article 28 GDPR: the data processor and sub-processors - GDPRLab
Data controller or data processor | EDPB - Data protection guide for small business