Many Spanish SMEs work with an external IT provider or an IT maintenance firm that handles technical support, device configuration, backups, email, servers and, increasingly, the cloud environment. That figure is operationally essential. And yet, it is one of the points where most SMEs unknowingly breach the GDPR: the IT provider has access to systems containing personal data, and most do not sign with the SME the contract required by art. 28 GDPR.
This guide explains how to regulate that relationship under the GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Spain's Organic Law 3/2018): when the IT provider is a processor, what specific document needs to be signed, what minimum content it must include, how to manage remote access and backups, and how to properly close the relationship when switching to another IT provider.
When the IT provider is a processor
Article 28 GDPR defines the processor as the natural or legal person who processes personal data on behalf of the controller. The distinguishing feature is that the processor does not decide its own purposes or means: it executes what the controller instructs.
Applied to the reality of an SME, almost any external IT provider fits that definition. These are the typical situations in which they are clearly a processor:
- Recurring maintenance of the SME's devices, with remote or on-site access to workstations and servers.
- Administration of corporate email, including creating, amending and deleting accounts.
- Backup management: performing, holding, testing and restoring backups containing personal data.
- Configuration and support of the ERP, CRM, HR software or other systems processing data.
- Administration of cloud infrastructure (Microsoft 365, Google Workspace, AWS, Azure, GCP) contracted by the SME.
- Incident support with access to individual devices that may contain data.
- System migration from an old server to a new one, from one cloud provider to another, or from one software to another.
In all these cases, the art. 28 GDPR contract is required. The only situations clearly outside scope are very one-off interventions without access to personal data (for example, installing new equipment without prior data migration, or replacing a router without access to the internal network). In practice, those exceptions are rare.
What exact document needs to be signed
Article 28(3) GDPR allows the relationship to be governed by a contract or other legal act under Union or Member State law. The three most common forms are:
- IT services agreement with a data protection annex: the commercial contract regulates hours, rates and SLA; the annex regulates the processor role. The most common and cleanest approach.
- Specific processing agreement, signed alongside the services contract. Useful when you do not want to amend the commercial contract.
- Unified contract that integrates IT services and the art. 28 GDPR regime from the outset. Cleaner legally but less common.
What is not sufficient:
- The standard commercial services agreement with no mention of the GDPR or art. 28: it does not cover the required minimum content.
- A generic email from the IT provider stating that they comply with the GDPR: it is not a binding legal act with the content of art. 28(3).
- A brief clause in the initial quote saying "data protection rules will be complied with": empty of content.
Minimum content of the contract
Article 28(3) GDPR sets the mandatory minimum content. Adapted to the IT provider of an SME:
| Clause | What it must say applied to the IT provider |
|---|---|
| Subject matter and duration | Maintenance services, system administration, support and others described in the commercial contract, for the term of the relationship. |
| Nature and purpose | Keep the SME's systems operational so it can carry out its business. The IT provider may not use the data for its own purposes. |
| Types of data and categories of data subjects | Identifiers, contact, employment, commercial, financial; on employees, customers, suppliers; and, where applicable, any special categories that any system may contain. |
| General obligations | Process data on documented instructions from the controller, not use it for own purposes, maintain confidentiality even after termination of the contract. |
| Provider's personnel | Written confidentiality commitment from any technician with access, control of onboarding and offboarding of the provider's staff, log of who accesses what. |
| Security measures | Encrypted remote connection (VPN or equivalent), use of individual accounts with strong passwords and two-factor authentication, access log, encrypted backups, vulnerability management. |
| Sub-processors | List of the sub-processors used (collaborating technician, remote monitoring platform, cloud provider) and obligation to notify any change. |
| Assistance with rights | The IT provider assists the SME when an access, erasure, rectification, objection or portability request requires technical intervention. |
| Breach notification | Obligation to notify the SME without undue delay (ideally within 24-48 hours) of any breach or security incident detected. |
| Return at termination | Return of credentials, copies and configurations to the SME or to the incoming provider; secure deletion of the data the IT provider retained for its own operations. |
Remote access: what really matters day-to-day
The IT provider typically works through remote access to the SME's systems. That involvement raises three critical points the contract must regulate and practice must respect:
- Encrypted channel: remote access is performed via corporate VPN or an equivalent solution that encrypts the entire session. Not via remote desktop exposed to the internet without strong authentication.
- Individual accounts: each technician of the IT provider accessing the systems uses their own named account, not a shared provider account. The provider's staff onboarding and offboarding is notified to the SME so it can update permissions.
- Access log: systems retain a log of who accessed what, when and from where, for a reasonable period. This allows auditing activity in the event of an incident.
Backups: the point where control is most easily lost
Backups are one of the most sensitive areas under the art. 28 GDPR regime. The questions the contract must answer:
- Where they are stored: the IT provider's server, the SME's server, or an external cloud provider. If outside the EEA, Chapter V GDPR is triggered.
- Who has access: only authorised personnel of the provider, with an individual account and logging.
- How they are encrypted: in transit and at rest. The encryption key, ideally, held by the SME.
- How long they are kept: a clear rotation policy (daily, weekly, monthly), with secure destruction of older copies.
- How restoration is tested: at least one full test per year, documented. A backup that has never been restored is a backup that does not exist.
- What happens at the end of the relationship: backups managed by the provider are returned to the SME or to the new incoming provider, not simply destroyed.
"The external IT provider is one of the actors with the most access to data and, paradoxically, one with whom most SMEs operate without a signed Art. 28 contract. That is exactly the pattern the AEPD sanctions when a breach happens: a controller that did not choose a processor offering guarantees and did not document the relationship. Five signed pages solve the problem."
Mario P. Talamillo · Managing Partner, Certix®
Breaches and notification: the procedure many SMEs have not rehearsed
Article 33 GDPR requires the controller to notify the AEPD (the Spanish Data Protection Authority) of any security breach that may create risk to the rights and freedoms of those affected, within 72 hours of becoming aware of it. For the SME to meet that deadline, the IT provider must alert it very quickly. The contract must set this out expressly:
- A specific timeframe for the IT provider to report any incident to the SME (typically 24 to 48 hours maximum).
- Minimum information for the first communication: nature of the incident, systems affected, data potentially compromised, immediate measures taken.
- Technical cooperation to prepare the notification to the AEPD where required and, if applicable, the communication to those affected.
- Subsequent documentation: root cause analysis, measures to prevent recurrence.
Changing IT provider: the most critical phase
Changing external IT provider is the moment when most compliance is lost if not managed in an orderly way. A reasonable procedure:
- Complete inventory of what the outgoing IT provider managed: servers, devices, domains, certificates, administrative accounts, backups, cloud contracts, licensed software.
- Handover of credentials to the controller (the SME) or to the incoming provider: administrative passwords, encryption keys, specific configurations, custom scripts, technical documentation.
- Return or transfer of backups: the outgoing provider cannot simply destroy them; it must hand them over or guarantee access to the incoming provider.
- Confirmed deletion of the data the outgoing provider retained for its own operations, with written evidence.
- Credential rotation for all systems: administrative passwords, service accounts, third-party accesses known to the outgoing provider.
- Signature of the art. 28 GDPR contract with the incoming provider before operations begin.
- Updating the SME's RoPA: new processor, new measures, any new cloud sub-processor.
Minimum checklist for the external IT provider
- Art. 28 GDPR contract (or annex) signed and filed with the current IT provider.
- List of the IT provider's sub-processors, kept up to date and monitored.
- Analysis of international transfers where the IT provider or its sub-processors operate outside the EEA.
- Remote access policy: VPN or encrypted channel, individual accounts, activity log.
- Backup policy: location, encryption, retention periods, annual restoration test.
- Express timeframe for breach notification (24-48 hours) and cooperation procedure.
- Procedure for changing IT provider, with documented handover of credentials, copies and deletion.
- Routine credential rotation after the departure of any technician with administrative access.
Frequently asked questions
Is my SME's external IT provider a processor under the GDPR?
Yes, almost always. The IT contractor accessing the SME's devices, servers, email or backups processes personal data on behalf of the controller and is a processor (art. 28 GDPR). The relationship must be governed by a written contract with the content of art. 28(3). It does not matter whether the service is hourly, monthly or on call: any recurring technical access triggers the contractual obligation.
What does my SME need to sign with the IT provider: an annex, a separate contract or part of the services agreement?
All three forms are valid provided the final document contains the mandatory clauses of art. 28(3) GDPR. The most common is to sign a data protection annex linked to the IT services agreement. The standard commercial contract on its own does not cover the specific content the GDPR requires (sub-processors, assistance, breaches, return).
Can the external IT provider take copies of the data home to work on them?
Only if the contract authorises it, security measures allow it and the data copied is the minimum strictly necessary. The reasonable approach is to work on the SME's systems via an encrypted connection without extracting data. When extraction is unavoidable, it must be documented, limited to the necessary data, kept encrypted and securely destroyed after the task.
And if the IT provider ends the relationship with my SME, or I switch to another IT provider?
Article 28(3)(g) GDPR requires the processor to return the data to the controller before destroying it. Handover of credentials, return or transfer of backups, confirmed deletion of residual copies and rotation of all system credentials. The whole transition must be documented. Switching providers without this orderly handover is a common source of later disputes.
This content is purely informational and educational; it does not constitute specialised legal advice. Applying the regulations to each specific case requires individual analysis. Spanish regional sectoral regulations may extend or modify deadlines and requirements.
Have you signed Art. 28 GDPR with your external IT provider?
At Certix we assign you an SME compliance specialist. No commercial intermediaries, no generic templates.
Speak to a specialist