QUICK ANSWER

If the agency that built your website also hosts it, or logs in to the database where your members' details sit, it processes personal data for you. Under the GDPR that makes it a processor, and Article 28 requires a written contract. The European Commission publishes that contract for free. The real work is its four annexes.


Picture the secretary general of an association with 800 members. The website went live two years ago with a membership form, a members' area and a newsletter sign up. A small agency built it and still hosts it. What was signed at the time was a quote and an invoice.

In GDPR terms that association is the controller, and its agency is almost certainly a processor. The law has a specific contract for that relationship, and a great many association websites run without one. It is also one of the cheapest gaps to close, because the Commission has already written the contract.

The only part you have to write is four annexes

Figure 1Decision 2021/915

Four annexes. Two of them are the work.

The clauses are fixed. What you add goes in the annexes, named here as the Commission's text names them.

Figure 1The contract is already written. Annexes II and IV are where the time goesCommission Implementing Decision (EU) 2021/915 of 4 June 2021, Annexes I to IV.

The contract itself is the European Commission's standard clauses for controllers and processors, and its obligations are fixed. What changes from one association to the next is four annexes.

Annex I names the two of you, and takes five minutes. Annex II describes the processing: whose data, which data, anything sensitive, what is done with it, why, and for how long. Annex III lists the security measures. Annex IV lists everyone else who touches the data.

For a typical association the honest Annex II is short: members and newsletter subscribers; names, addresses, email, membership status, and payment references; kept for the length of the membership and a stated period after.

If your agency stores your members' data, it is processing it

The GDPR's definition of processing in Article 4(2) includes storage. A processor, in Article 4(8), is anyone who processes personal data "on behalf of the controller".

The European Data Protection Board takes that literally. Its guidelines on controllers and processors give the example of a hosting company that only stores encrypted files and never looks at them. It still "is processing personal data on employer A's behalf and is therefore a processor". The same guidelines treat an IT support firm that inevitably sees personal data while doing its job as a processor too.

So the test for your agency is practical. If it hosts the site, runs the database behind the membership form, or keeps an admin login it uses to maintain things, it is processing your members' data. An agency that handed over the files and never touched the site again may not be.

Article 28 asks for a written contract, and says what goes in it

Article 28(3) says processing by a processor "shall be governed by a contract", and 28(9) says it must be in writing, which can be electronic. The contract has to set out what is processed, for how long, why, and about whom, and it has to commit the agency to eight things:

  1. Act only on your documented instructions.
  2. Keep its staff bound to confidentiality.
  3. Keep the data secure.
  4. Bring in another processor only on the terms you agreed.
  5. Help you answer members who ask to see or delete their data.
  6. Help you with security, breach notification and impact assessments.
  7. Delete or return the data when the work ends, at your choice.
  8. Give you what you need to show all of this, and allow audits.

The duty to check sits with the association. Article 28(1) says a controller shall use only processors "providing sufficient guarantees". The EDPB adds that accepting a provider's standard terms does not move that responsibility, and that a provider changing its terms by posting them on its website does not satisfy Article 28.

The Commission has already written the contract, and it costs nothing

Commission Implementing Decision (EU) 2021/915 of 4 June 2021 sets out standard contractual clauses between controllers and processors. Article 1 of the Decision says they fulfil Article 28(3) and (4).

The clauses are fixed. Clause 2 says the parties may not change them except by adding or updating information in the annexes. They can sit inside a broader contract, such as your agreement with the agency, as long as nothing else in it contradicts them.

So nobody needs to draft the obligations. When Elevates took on its first association membership project in 2026, this is the contract it chose, on 16 August, rather than writing its own. What is left is describing your own situation in the four annexes, and that is where the time goes.

The annex most agencies have never filled in is the list of subprocessors

Article 28(2) says a processor shall not engage another processor without your prior written authorisation, specific or general. Clause 7.7 of the Commission's text turns that into two options: approve each subprocessor in advance, or approve a list and be told in writing before it changes.

On an association website the list usually includes the hosting company, the service that sends the newsletter, the tool behind the forms, backup storage and any analytics. Each one that handles member data for the agency, rather than under your own direct contract, belongs on that list.

If your agency cannot write that list in an afternoon, that is the finding. It means nobody knows where your members' data goes.

An agency that decides what to do with your data stops being a processor

Article 28(10) says a processor that determines the purposes and means of processing is treated as a controller for it. An agency that reused your member list to promote its own services, or added its own tracking to your site, would be making those decisions itself.

That is why the purposes line in Annex II matters to both sides. It is the written record of what the agency was allowed to do, and therefore of what it was not.

What this takes, and what Elevates does

Start without paying anyone. Download the clauses from EUR-Lex, fill in Annex I yourself, and send Annexes II to IV to your agency to complete. If they come back within a week with a complete list of subprocessors and a clear description of the processing, sign it. That is the whole job, and many associations will be done at that point.

The ceiling is Annexes II and IV. Both depend on knowing where the data actually goes: every form, plugin, email service, embed and backup. On a site built over several years, sometimes by more than one person, nobody holds that map, and that includes the agency.

The rule Elevates works to is that data the site does not need to keep, it passes through rather than stores, because every system that holds member data adds a line to Annex IV and a place for something to go wrong. For an association whose site has grown without a map, Elevates traces every place member data goes, completes the annexes from what it finds, and removes what does not need to be there before anyone signs.

If your agency sends back a complete Annex IV, you are in good hands. If it cannot, your members' data is in more places than anyone has written down, and the contract is the easiest part of fixing that.

This post describes published law and guidance. It is not legal advice about any particular association.

Contact Us