EU

Data Processing Agreement

The short answer. If you buy a dataset containing personal data and you decide what it is used for, you are a controller and the vendor is a processor, and the arrangement has to be governed by a contract meeting GDPR Article 28(3) rather than by a license. Article 28(3) sets out what the contract must stipulate. Sub-processors need authorization under Article 28(2) and the same obligations have to flow down under Article 28(4). If the data moves outside the EU, Chapter V applies, usually through the standard contractual clauses under Article 46.

The law

GDPR Article 28(3)

Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller. That contract or other legal act shall stipulate, in particular, that the processor: processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation.

This is the sentence that makes a plain license insufficient. A license grants rights in a file; an Article 28(3) contract allocates responsibility for personal data, and it has to name the subject matter, the duration, the nature and purpose, the data types and the categories of data subjects. The full list of processor obligations runs from 28(3)(a) to 28(3)(h) and includes processing only on documented instructions, assisting with data subject requests, and deleting or returning the data at the end of the arrangement.

GDPR Article 28(2)

The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.

A data vendor's supply chain — studios, annotation teams, hosting platforms, quality vendors — consists of sub-processors. General written authorization is permitted, but it comes with a change-notice duty and a right to object. Ask for the current list before signing, and ask what happens when it changes, because the answer determines whether you find out about a new sub-processor before or after your data is there.

GDPR Article 28(4)

Where a processor engages another processor for carrying out specific processing activities on behalf of the controller, the same data protection obligations as set out in the contract or other legal act between the controller and the processor as referred to in paragraph 3 shall be imposed on that other processor by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organisational measures.

The obligations have to be imposed down the chain by contract. A vendor that cannot show the flow-down clause has sub-processors outside the frame, which means your Article 28 compliance depends on agreements you have never seen and cannot audit. Ask to see one executed flow-down agreement rather than a description of the process.

GDPR Article 46(1)

In the absence of a decision pursuant to Article 45(3), a controller or processor may transfer personal data to a third country or an international organisation only if the controller or processor has provided appropriate safeguards, and on condition that enforceable data subject rights and effective legal remedies for data subjects are available.

Transfers outside the EU need an adequacy decision or appropriate safeguards, which in practice means the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, together with an assessment of the destination country. A US buyer sourcing recordings of EU speakers is a transfer in at least one direction, and usually in both.

Who it applies to

Article 28 applies whenever a controller uses a processor, regardless of where either party is established, if the processing is within the scope of the GDPR. Two complications are specific to buying data rather than buying a service.

First, the vendor may not be a processor at all. A company that collects audio on its own initiative, decides what to collect, and sells the same corpus to every buyer is acting as a controller in its own right. In that case a DPA is the wrong instrument, and the questions become what lawful basis the vendor had for the collection and what basis you have for your own processing. The instrument has to match the role, and buyers often assume it does because a vendor offered to sign something titled DPA.

Second, the territorial reach of Chapter V is wider than buyers expect. If the vendor is in the EU and you are not, the transfer rules apply to the delivery. If you are in the EU and the vendor is not, they apply to the receipt. If neither party is in the EU but the speakers are, the GDPR still governs the underlying processing through Article 3(2), and the transfer analysis attaches to wherever the data actually goes — including annotation and storage locations that are not the vendor's headquarters.

What it costs to get wrong

Two tiers are in play. Failing to have an Article 28(3) contract infringes the Articles 25 to 39 group, which is Article 83(4): up to 10 million euros, or up to 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher. A transfer without an adequacy decision or Article 46 safeguards is a Chapter V infringement, which is Article 83(5): up to 20 million euros or 4%, whichever is higher.

The commercial consequence usually arrives first. Enterprise procurement asks for the DPA and the transfer mechanism as standard documents. A dataset that cannot be documented cannot be resold, cannot be embedded in a product sold to regulated buyers, and cannot be used by a customer whose own diligence is audited.

There is also a subtler cost that shows up in disputes. Without an Article 28(3) contract there is no deletion-or-return clause, no audit right, and no defined response when a speaker withdraws consent. Those gaps turn a compliance question into a commercial negotiation with no baseline, and the buyer is usually the party with more to lose.

How to comply when you are buying data

The work starts with the role question, because everything else depends on the answer.

  • Establish the roles in writing: is the vendor a processor acting on your instructions, or a controller selling the same data to others? The answer decides whether you need a DPA, a joint controller arrangement, or your own lawful basis for the receipt.
  • If the vendor is a processor, check the contract against Article 28(3)(a) to (h) item by item. The clauses most often missing are the deletion-or-return term and the audit right.
  • Get the sub-processor list in writing, the change-notice mechanism, and one executed flow-down agreement so you can see the obligations are actually imposed.
  • Name the transfer mechanism and attach the standard contractual clauses. Map every country the data touches, including annotation and storage locations, not just the vendor's registered address.
  • Set retention and deletion in the contract to match your own retention rule. A vendor holding copies for longer than you do is a second processing operation you are not managing.
  • If a document titled DPA arrives, read it against Article 28(3). A license with the word DPA in the title does not contain the stipulations, and the title is not what a supervisory authority reads.

How we handle consent and licensing →

Related compliance topics

Not legal advice

We are a sourcing company, not a law firm. Nothing on this page is legal advice, and it does not create a lawyer–client relationship. Whether a particular dataset is permissible in your jurisdiction depends on your use case, where you operate, and where the people in the recordings are located. Our role is to document the chain of consent accurately so that your counsel can assess it.

Sourcing data under Data Processing Agreement?

Tell us the language, the hours, and what the data needs to look like. You will get a real number and a real timeline — not a range. If we cannot source it well, we will tell you that instead.

  • Pilot batch before the full run, so problems surface early.
  • Consent documentation delivered with the data.
  • No medical or clinical data. No recorded telephone calls.

We reply within two business days. Your details are used only to answer this request. See our privacy policy.

Contact

Talk to a human

Send a specification and we will come back with a real number and timeline.

Submit a sourcing request

Or email hello@linguacorpus.com