GDPR & Data Protection

Data Processing Agreement - Who a Physiotherapist Must Sign One With

Author:

Who a physiotherapist must sign a data processing agreement with - booking software, accounting firm, hosting, IT - and what it must contain under GDPR Article 28.

Joanna has run a physiotherapy practice for five years. She keeps her patient calendar in a popular booking app, outsources bookkeeping to an accounting firm, and hosts her website with a local hosting company. When a colleague asked her during a conversation, "do you have signed data processing agreements with all of those companies?", she realized she had no idea what that meant. After all, she is the one who's the data controller for her patients' data -- why would she need to sign anything with an online calendar provider?

The answer is: because each of those entities processes her patients' personal data on her behalf, and the GDPR explicitly requires that kind of cooperation to be based on a written agreement. Without one, the practice is exposed to a serious violation -- even if no data has ever leaked. In this article we explain who a physiotherapist must sign a data processing agreement with, what such an agreement must contain, and how to check a supplier who "already has their own template."

What is a data processing agreement

A data processing agreement (DPA, in Polish also called "umowa powierzenia przetwarzania danych") is a document that governs a situation where the data controller (the physiotherapy practice) entrusts the processing of personal data to another entity (the processor), e.g. a software provider or an accounting firm. The processor does not decide independently why and how the data is processed -- it acts solely on the controller's instructions, within the scope set out in the agreement.

The legal basis is Article 28 of the GDPR, which states explicitly: where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures. Importantly -- processing by a processor must be governed by a contract or other legal act that is binding on the processor and the controller. A verbal "trust me" is not enough. We cover the broader picture of implementing GDPR at a practice in the article GDPR at a physiotherapy practice.

Who is a processor at a typical physiotherapy practice

Most practices rely on several external suppliers that rarely get thought of in terms of "data processing." Yet every one of them, if they have access to patients' personal data, is a potential processor.

Calendar and EDM software provider

Booking apps and electronic medical record (EDM) systems are the most obvious example. The provider stores patients' names, phone numbers, and sometimes health data on its servers -- exactly as described in the article about electronic medical records in physiotherapy. There's an important trap here, though: some popular booking platforms (such as Booksy or similar services) define the relationship in their terms not as a simple processing arrangement, but as joint controllership. That is an entirely different legal construction than processing under Article 28 -- it requires a separate arrangement setting out each party's responsibilities under Article 26 GDPR. Before you accept anything "automatically" in a supplier's dashboard, check its terms of service to see whether it talks about processing or joint controllership -- this isn't a formality, it's a real difference in your liability.

Accounting firm

Invoices and accounting documents contain personal data of clients (and sometimes employees). The accounting firm processes them on your behalf -- a classic processing scenario, usually the simplest to formalize, since most accounting firms already have ready-made templates.

Website hosting company

If your practice's website has a contact form, a booking form, or a newsletter, the data from those forms ends up on the hosting company's server. That's also processing -- a topic we cover in the article Practice website and GDPR.

Medical waste collection company

If the documentation accompanying waste collection (e.g. handover protocols) includes patients' personal data, the waste collection company also becomes a processor for that narrow scope. It's worth checking this before signing a collection agreement -- in many cases the waste documentation can be drafted so that personal data never appears in it at all, which simplifies the situation.

IT company servicing equipment and software

A technician who remotely logs into a computer running the patient record system, or physically repairs hardware with access to the database, is processing personal data -- even if this happens occasionally. This is one of the most frequently overlooked processors, because the arrangement is often informal ("just call if something breaks").

Supplier Type of relationship What to check
Calendar / EDM appUsually processing, sometimes joint controllershipProvider's terms -- processing or joint controllership
Accounting firmProcessingWhether it has its own DPA compliant with Art. 28
Hosting companyProcessingServer location, subprocessing
Medical waste collectorProcessing (if data is in the documentation)Whether waste documentation contains personal data
IT / equipment service companyProcessingScope of access, duration of access

What a data processing agreement must contain under GDPR Art. 28

Article 28 GDPR leaves little room for discretion regarding the content of the agreement -- it lists specific elements that must be included. Missing even one of them means the document does not meet the requirements, even if both parties signed it.

Mandatory elements

  • Subject matter and duration of the processing -- what the service consists of and how long the cooperation lasts.
  • Nature and purpose of the processing -- e.g. running an appointment calendar, bookkeeping services.
  • Type of personal data and categories of data subjects -- e.g. standard patient data, possibly health data.
  • Obligations and rights of the controller -- including the right to issue instructions and to carry out audits.
  • The processor's commitment to process data only on documented instructions from the controller -- the processor cannot use the data for its own purposes "on the side."
  • Confidentiality guarantee -- persons authorized by the processor to process data must be bound by confidentiality.
  • Appropriate security measures under Article 32 GDPR -- technical and organisational protection of the data.
  • Rules on subprocessing -- conditions under which the processor may use further subcontractors.
  • Assistance to the controller in fulfilling data subjects' rights (e.g. a patient's request for access to their data).
  • Assistance in meeting obligations regarding data security, breach notification, and impact assessment.
  • Return or deletion of data after the cooperation ends -- what happens to the data when you terminate the agreement with the supplier.
  • Right to audit -- the controller's ability to verify that the processor actually complies with the agreement.

Missing even one of these elements makes the agreement incomplete from a GDPR standpoint, which during a UODO inspection is treated the same as having no agreement at all.

Subprocessing -- when a supplier uses further subcontractors

Many software providers themselves rely on external infrastructure -- e.g. storing data on the servers of a large cloud provider. This is known as subprocessing. The GDPR requires that a processor not engage another subcontractor without the controller's prior consent (general or specific), and that it inform the controller of planned changes in this regard, giving the controller a chance to object. In practice, this means it's worth checking whether the agreement with your calendar app provider includes information about subcontractors -- and whether the practice has a real opportunity to review changes.

When a supplier "already has their own template"

Large software, hosting, or cloud tool providers usually don't negotiate the content of a data processing agreement with each client individually -- they have a ready-made, standard document (often available as a link in the terms of service or the customer dashboard). That's not a problem in itself, but it doesn't release the practice from the obligation to verify it.

Before accepting such a standard document:

  • Ask for a copy of the data processing agreement (DPA) if it isn't easily available publicly -- you have the right to know it before you start using the service.
  • Check that it contains all the elements from Article 28 GDPR listed above -- especially the rules on subprocessing and the return of data after the cooperation ends.
  • Verify the location where data is processed -- if data is transferred outside the European Economic Area, additional compliance mechanisms must exist (e.g. standard contractual clauses).
  • Don't automatically assume that because a supplier is large and well-known, its template is necessarily compliant -- standard documents sometimes turn out to be outdated or missing important elements.

[SP] Example -- Solo practice: Joanna checks her calendar app's terms of service and discovers that the provider treats the relationship as joint controllership, not processing. Instead of panicking, she contacts the provider, asks for a document setting out the division of responsibility under Article 26 GDPR, and fills in the missing processing agreements with her accounting firm and her website hosting company.

[GR] Example -- Group practice: At a practice employing five physiotherapists, everyone uses one shared EDM system, but each therapist used to separately arrange ad-hoc equipment repairs with a local IT company. The owner reviews all of these relationships, draws up a list of the actual processors, and signs one unified processing agreement with the IT company servicing the whole practice, instead of five loose arrangements.

The risk of not having a processing agreement during a UODO inspection

Missing a processing agreement with any of the actual data processors is one of the fundamental violations found by the Personal Data Protection Office (UODO) during inspections. Importantly -- a fine or post-inspection recommendation doesn't require an actual data leak to have occurred. The mere fact that a practice transfers personal data to an external entity without a proper legal basis and without an agreement meeting the requirements of Article 28 GDPR is a violation in itself.

In practice, this means a practice can operate for years without a single security incident and still be sanctioned during a routine inspection or in response to a patient complaint, purely for lacking formal documentation. This is one of those areas of GDPR where the risk can be eliminated entirely -- all it takes is organizing your supplier list once and signing the appropriate agreements with each of them.

How to organize your processing agreements step by step

  1. Make a list of every external entity that has access to patients' personal data -- software, bookkeeping, hosting, IT, waste collection.
  2. For each one, check whether a processing agreement exists -- a separate document or a clause in the terms of service / main agreement.
  3. Verify whether the document contains the elements from Article 28 GDPR -- if not, ask the supplier to complete it or sign a separate DPA.
  4. Determine whether the relationship is processing or joint controllership -- especially with booking platforms.
  5. Note the review date and revisit the list whenever you change suppliers or add a new service.

Frequently asked questions

Do I need to sign a data processing agreement with my accounting firm?

Yes. The accounting firm processes the personal data contained in accounting documents on behalf of the practice, so it is a processor within the meaning of Article 28 GDPR. Without a signed processing agreement, the cooperation takes place without the required legal basis, which during an inspection is treated as a violation regardless of whether any data leak occurred.

What's the difference between processing and joint controllership?

Under processing, the processor acts solely on the controller's instructions and does not decide on the purposes or means of processing -- this is governed by the agreement required under Article 28 GDPR. Under joint controllership, both parties jointly determine the purposes and means of processing, which requires a separate arrangement under Article 26 GDPR covering the division of responsibility. Some booking platforms use exactly this second model, which is why it's worth checking their terms of service.

Can a practice negotiate a processing agreement with a large supplier?

In practice, large suppliers rarely negotiate the content of their standard document individually, but the practice has the right to ask for a copy and check its compliance with Article 28 GDPR before signing or starting to use the service. If the document omits important elements, it's worth flagging this to the supplier -- some update their templates on request, especially in the medical sector.

What happens if there's no processing agreement, even if no data leak has ever occurred?

Missing a processing agreement is a violation in itself, regardless of whether a security incident occurred. During an inspection, UODO can issue a post-inspection recommendation or, in more serious cases, an administrative fine solely for the lack of a proper legal basis for the entrusted processing, without needing to demonstrate any actual harm.

CTA: Not sure where to start organizing your processing agreements with suppliers? The PREMIUM package includes a ready-made data processing agreement template (instructions + fillable template) together with complete GDPR documentation for your practice -- just fill in the supplier's details and send it for signature. See FizjoReady packages →

Related articles:
- GDPR at a physiotherapy practice -- a complete guide
- Practice website and GDPR
- Electronic medical records in physiotherapy

Newsletter

Regulatory changes and practical tips for physiotherapy practices. No spam.