GDPR compliance in a contract context means ensuring that arrangements involving personal data processing include the terms required by GDPR - typically through a Data Processing Agreement (DPA) - and that operational reality follows the contractual commitments. It turns a regulatory obligation into concrete clauses and observable behaviour.
How GDPR compliance works in contracts
A retailer selects a personalisation vendor that will process customer email, browsing behaviour and purchase history on its behalf. Before go-live the parties sign a Data Processing Agreement naming the retailer as controller and the vendor as processor, setting out the processing purpose, the personal-data categories, the sub-processor list, security measures, breach notification and data-return obligations.
Compliance runs on two tracks: the paper track (the DPA and its schedules) and the operational track (technical and organisational measures, sub-processor controls, transfer safeguards, breach protocols). A DPA on file with no operational evidence is still a compliance gap.
Where GDPR compliance appears in contracts
The centre of gravity is the Data Processing Agreement (DPA), either signed standalone or attached as a schedule to the master services agreement. Standard contents cover roles, processing purpose, data categories, sub-processing, international transfer mechanisms (SCCs, adequacy decisions), security measures, audit rights, breach notification and end-of-contract handling. Vendortell's own DPA is published as the reference instrument for customers processing personal data through the platform.
GDPR compliance FAQ
Is a DPA the same as GDPR compliance?
No. A DPA is the paper instrument. Compliance is the DPA plus the operational behaviour behind it. A DPA without matching controls is a paper-only position.
Who is the controller and who is the processor?
The controller decides why and how personal data is processed; the processor acts on the controller's instructions. In a typical vendor arrangement the buyer is controller and the vendor is processor.
What happens if the contract changes what data is processed?
The DPA is updated. New personal-data categories, new sub-processors or new international transfers each trigger a revision so paper and operational tracks stay in sync.