· Post
Ten records were agreed. Millions ended up in the test system.
Data processing agreement for freelancers: where to get one from Google and Microsoft, why free Gmail is ruled out and what to have ready before anyone asks.
An IT firm I know well was supposed to fill a test system together with a large German company. Ten customer records had been agreed, and the data protection team and the works council had both approved it. On each side, a programmer clicked OK. The transfer took a minute instead of three seconds, and afterwards the test system held not ten records but millions.
The corporation had to report the breach to the data protection authority, without undue delay and where feasible within 72 hours. The small service provider had to produce what it had, immediately: its data processing agreement (DPA) and the description of its technical and organisational measures. If an hour like that is when you start writing those documents, you are in serious trouble.
In the small businesses I know, it starts more innocently, with an annoyed customer and a website without a privacy policy. Shortly afterwards the authority starts asking questions, and by then it is too late to go looking for the paperwork.
I am not a lawyer. I have worked in IT since 1998 and deal with these questions almost every day. What follows is the basic kit I recommend to self-employed people from the technical side, not legal advice.
Who the GDPR applies to, and who it does not
If the only people you keep in Gmail, iCloud or Outlook are family and friends, you are out: the GDPR does not apply to purely personal or household activities (Art. 2(2)(c), the so-called household exemption). As soon as customers, clients, members or prospects are in your address book, it applies in full, even to a one-person business, and so do the DSG in Austria and the BDSG in Germany. If you use one account for family and clients at the same time, you cannot rely on the household exemption for the business part.
Clubs and associations overlook this most often. The treasurer keeps the membership list in their private Gmail because it happens to be there, and that leaves the club with exactly the same obligations as a company.
| What is in the account | Does the GDPR apply? | Do you need a DPA? |
|---|---|---|
| Family and friends | no, household exemption | no |
| Personal and business mixed | yes, for the business part | yes, but not available for a free account |
| Customers, clients, prospects | yes, even in a one-person business | yes |
| Members of a club or association | yes | yes |
What a data processing agreement covers
The data processing agreement (sometimes called a data processing addendum; in German Auftragsverarbeitungsvertrag, or AVV) is set out in Art. 28 GDPR. Your client gave her phone number to you, not to Microsoft. Without a contract, Microsoft is a third party as far as that data is concerned, and you have passed it on. With a DPA, Microsoft becomes your service provider, bound by your instructions, with fixed rules on confidentiality, security, sub-processors, deletion and audits. A missing contract is an infringement, and Art. 83 provides for fines.
The agreement works in both directions. If you process data for clients yourself, say as a virtual assistant working in other people’s inboxes or as a web service provider, you are the processor. Then many clients will want to see your DPA and your measures.
The list first, then the contracts
The obvious first step would be to go and get the DPA from Google or Microsoft. I would turn the order round. Email is only one of many services that touch client data, and if you start with the best-known one, you often stop with the best-known one.
Start with a mind sweep, just for tools: email, calendar, cloud storage, video conferencing, newsletter, appointment booking, accounting, the contact form on your website. Anything where a name or a phone number lands goes on the list.
That list becomes your record of processing activities under Art. 30 GDPR. The exemption for small businesses only applies to occasional processing, and you process client data all the time. A table is enough as a framework, plus your contact details and a short description of your measures:
| Purpose | Which data | Where, under which contract | Third country | When deleted |
|---|---|---|---|---|
| Client correspondence | Name, email, phone | Microsoft 365, DPA filed | USA, standard contractual clauses in the DPA | after the engagement ends, unless something has to be kept |
| Invoices | Name, address, service | Accounting software, DPA filed | none, servers in the EU | when the retention period ends |
| Appointment booking | Name, email, appointment | Booking tool, DPA filed | as per the list of sub-processors | after the appointment |
Many people leave the last column empty because they want to keep client data forever. That is not allowed. And when a client says “delete my data”, you know straight away everywhere it is stored.
The same list gives you your privacy policy, linked in the footer of your website and referenced in your contracts. It names who data goes to, Google or Microsoft for example, and states that it may also be processed in the US.
Data processing agreements for freelancers at Google and Microsoft
You only get a DPA with a business account. Free Gmail, Outlook.com, GMX and Yahoo do not offer one, because the provider there is not working on your behalf but as a controller in its own right, with purposes of its own. And paid does not mean business: Google One and Microsoft 365 Family are consumer plans and change nothing about that.
Google Workspace: As a super admin, open the Admin console and go to Menu → Account → Account settings → Legal and compliance. In the “Security and Privacy Additional Terms” section, click “Review and Accept” next to the “Cloud Data Processing Addendum”. If your contract already includes the addendum, Google says accepting it makes no difference, so it cannot do any harm.
Microsoft 365: There is nothing to click here. The Data Protection Addendum is automatically part of the business agreements through the licensing terms, and the current version is at aka.ms/DPA.
Both publish audit reports and certifications such as ISO 27001, Microsoft in the Service Trust Portal, Google in the Compliance Reports Manager. Download everything as PDFs, put it in a folder called Data Protection and make a note of when you accepted. A box that only gets ticked once the authority asks will not help you any more. The same goes for every service on the list.
What you have to prove yourself
The DPA covers what the provider does. What you do is set out in your technical and organisational measures under Art. 32, TOMs for short. They have to be both set up and written down. Here is what I consider reasonable today:
- Sign-in: two-factor authentication wherever it is available, and a password manager instead of one password for everything.
- Devices: a lock by password, PIN or Face ID, and an encrypted drive. Current devices can do this, but it is not always switched on. Check on a Mac under System Settings → Privacy & Security → FileVault, on Windows 11 under Settings → Privacy & security → Device encryption, or BitLocker.
- Permissions: only people who have to be administrators are administrators. Anyone who leaves the business loses their access the next day.
- Backups: ideally weekly, with a second provider that has a data centre in the EU and a DPA.
- Sharing: twice a year, check who has access to what, and record it with the date.
For the settings in the Admin console, feel free to ask an AI model: “I recently became the super admin of Google Workspace for two people. Which security settings matter most, and where do I find them?” Working through the list is still down to you.
You document this in a simple file: which service, what is set up, what happens when someone leaves. That does not mean you have won automatically. But when an authority decides on a fine, it expressly takes into account which measures you had taken (Art. 83(2) GDPR). An access list that has been signed off twice a year for years looks rather different from a shrug.
The Data Privacy Framework applies, until further notice
Google, Microsoft and Apple contract with European customers through companies in Ireland and are subject to the GDPR. The problem is US law, which their parent companies are also subject to. That is why the European Court of Justice has already struck down the basis for transfers to the US twice: Safe Harbor in 2015 and Privacy Shield in 2020. Since July 2023 the EU-U.S. Data Privacy Framework has applied, and an appeal against it is pending before the same court.
For you as a business customer of Google or Microsoft, this means less than it sounds, because the EU standard contractual clauses are in your DPA anyway. If the framework falls, that does not make the transfer unassailable, but you are not left without a contract.
Jörg works for an Australian company and knows the other side: the US is only the best-known case. Every transfer to a third country without an EU adequacy decision needs its own legal basis. There is no such decision for Australia, so transfers there need the European Commission’s standard contractual clauses, adopted unchanged. The same applies to a German IT service provider whose team is partly based in Kosovo. Where your data really goes is in the list of sub-processors that comes with every DPA.
Using only European providers is a legitimate choice, but not the only permissible one, and in my experience you pay for it in features with many tools. To me it makes more sense to do what is legally possible with every service, and to be able to prove it.
Data protection is an area of responsibility, not a project
Setting it up is a project with a clear outcome: list complete, contracts filed, measures set up and described, privacy policy online. The next actions almost write themselves. “Download the DPA from Zoom” is as concrete as a next action gets.
After that, data protection is an area of responsibility, and an area runs on reminders in your tickler file rather than on good intentions: the sharing review twice a year, the list against the services you actually use once a year. New services go on the list first and into use second. There is a checklist for when someone leaves, because it happens too rarely to keep in your head.
Where this typically falls apart
- The account from the early days. Your first clients land in your private Gmail because it was already there, and they stay there. There is no DPA for it, not even if you pay.
- The treasurer with the private address. Members’ mail runs through the inbox of whoever holds the post at the time. When the post changes hands, the list does not move with it. It doubles.
- Paperwork on demand. DPAs only get downloaded and TOMs only get written when someone asks. A document dated yesterday only proves that you started yesterday.
- Sharing with no end date. The folder for a project that finished long ago is still shared, and nobody has looked at it since.
- The third country through the back door. The provider is in the EU, its support team is not. If you have never read the list of sub-processors, you do not know where your data ends up.
Common questions
Is a data processing agreement mandatory for freelancers?
Yes, as soon as a service provider processes your clients’ personal data on your behalf, such as your email provider or your cloud storage. There is no minimum size: the GDPR applies to one-person businesses too. The only exception is purely private data, such as the addresses of family and friends.
Can I use a free Gmail account for business?
Not for client data, because Google does not offer a data processing agreement for free accounts. The same goes for free accounts at Outlook.com, GMX or Yahoo and for paid consumer plans. You only get the agreement with a business account such as Google Workspace or Microsoft 365 Business.
Does the GDPR apply to clubs and associations?
Yes, a club or association that holds member data falls fully under the GDPR, whatever its size. The association is the one responsible, and the board has to see that it is implemented. Membership lists therefore belong in an association account with a data processing agreement, not in an office holder’s private email account.
Do I need a data protection officer as a freelancer?
Usually not. The GDPR only requires one in specific cases, for example when large-scale processing of health data is part of your core activity. In Germany one is also mandatory if, as a rule, at least 20 people are constantly involved in the automated processing of personal data (Section 38 BDSG), while Austria has no such threshold. All other obligations apply regardless.
Is the Data Privacy Framework enough for Google and Microsoft?
For now it is a valid basis for transfers to the US, but a contested one: an appeal against the adequacy decision is pending before the European Court of Justice, which struck down both of its predecessors. Google and Microsoft have also included the EU standard contractual clauses in their data processing agreements. If the framework falls, their business customers are therefore not left without a contractual basis.
Open your email provider’s admin console today and look for the data processing agreement. If you find it within ten minutes, put it in the Data Protection folder and move on to the next service on the list. If you cannot find an admin console at all, you already have the more important answer.
Which services touch your client data is rarely written down anywhere in full, and often nobody has checked the settings behind them. In the Digital Workplace Audit I go through your tools with you from the technical side and record what is in place and what is missing; the legal review stays with your lawyer. Write to me if you are self-employed and would rather sort out the paperwork now than on the day someone asks for it.
Topics: Data Protection, GDPR, Google Workspace, Microsoft 365