The legal basis for a data processing agreement is the EU General Data Protection Regulation (GDPR), which entered into force on May 25, 2018. This regulation updates and supplements the previous data protection law, which was enshrined in the German Federal Data Protection Act (BDSG). The new BDSG incorporates the rules established in the GDPR into national law. Data processing by a data processor must be based on a contract or other legal instrument that describes and agrees upon the further requirements for data processing; these include, among other things, the obligations and rights of the controller and the data processor, as well as the handling of personal data.

Article 28 of the GDPR – Data Processors – stipulates, in particular, that processing on behalf of a controller may only be carried out by data processors who provide sufficient guarantees that the rights of data subjects are protected. To this end, the data processor must implement appropriate technical and organizational measures to ensure that the processing of the transferred data complies with the requirements of this Regulation.