How it works in a data room
When a company uploads files containing personal information, the data room provider processes that information on the company’s instructions. The agreement fixes the terms: what data is processed and why, security measures, confidentiality of staff, use of subprocessors such as hosting companies, assistance with breaches and individuals’ requests, and deletion or return of data at the end. Most providers publish a standard version that customers accept with the main contract, and larger clients sometimes negotiate their own.
Why it matters in a deal
Under the GDPR, using a processor without a compliant written contract is itself a breach, regardless of whether anything goes wrong. The agreement is also where international transfers are handled, usually by incorporating standard contractual clauses, and where deletion after the deal is promised, which links to the seller’s data retention policy. Legal and privacy teams typically ask for the agreement and the subprocessor list early in selection. The United Kingdom guide notes how UK law mirrors these requirements.
Example
A Dublin medical device company preparing for a sale asks three providers for their processing agreements. One lists subprocessors in four countries without saying which handle files and which handle support tickets. The company’s privacy counsel asks for clarification, receives a revised annex showing that document storage stays in the EU, and signs before any HR files are uploaded.