ILP Abogados
Madrid · Internacional
Contrato de encargo de tratamiento de datos entre responsable y encargado

Delegating Without Risk: A Case-Law Guide to the 5 Critical Points on the Data Processing Agreement (Data Protection Series II)

Last updated: 22 July 2026.

Quick answer. In Spain, outsourcing the processing of personal data to a provider without a written data processing agreement (art. 28.3 GDPR) is a serious infringement under art. 73.k) of the LOPDGDD. The controller cannot delegate its duty to supervise, nor shift the fine to the processor through indemnity clauses. This guide brings together 5 keys with Supreme Court case law and AEPD penalty decisions. (Updated July 2026.)

The 5 Essential Points on Penalties for Lacking a Data Processing Agreement

Outsourcing services to third parties is an everyday activity in any company, but when it involves access to the personal data of clients or employees, the legal risk multiplies. To shield your organisation against inspections and fines, every business must master the following 5 fundamental points about the “data processing agreement”, thoroughly backed by legislation, Supreme Court case law and the penalty decisions of the Spanish Data Protection Agency (AEPD).

  1. The absence of a written agreement is a direct “serious infringement”

Delegating the processing of data to a provider without documenting it in writing is not a mere administrative defect, but a direct breach of Regulation (EU) 2016/679 (GDPR). The law requires that processing by the processor be governed by a written contract or other legal act documenting the instructions, responsibilities and required security measures.

  • Applicable legislation: Organic Law 3/2018 (LOPDGDD), article 73.k). This provision specifically classifies as a serious infringement outsourcing data processing to a third party without the prior execution of a written contract or legal act with the content required by article 28.3 of the GDPR.
  1. Calling yourselves “independent controllers” does not avoid the fine if the reality requires a processing arrangement

Many companies try to avoid the processing agreement by signing commercial arrangements in which they mutually define themselves as “independent controllers”. The AEPD rejects these formal arrangements if, in practice, one of the parties provides a service to fulfil the other’s purpose. Operating under an incorrect model carries very severe penalties.

  • AEPD penalty: Decision EXP202407910 (File PS/00248/2024), dated 30 September 2025. In this case, the AEPD penalised a courier company (proposing an initial fine of €200,000, paid with reduction at €164,000) for delivering parcels through the smart lockers of a company providing that service, without having executed a data processing agreement, since both entities had incorrectly configured themselves in their commercial contract as independent controllers.
  1. Without a processing agreement, the business legally loses control of its database

The processing agreement is not just a formality, but the only tool that ensures data does not leave the sphere of control of the responsible business. If there are no instructions clearly documented under article 28 of the GDPR, the business loses control over what the subcontractor does with the information, which may lead to unlawful disclosures, breaches of confidentiality or use for the subcontracted company’s own purposes.

  • AEPD penalties: Decisions EXP202407910 (File PS/00248/2024) of 30 September 2025 and EXP202304148 (File PS/00247/2024) of 10 October 2025. The AEPD expressly rules that “control is lost when the processor does not have instructions documented through a processing agreement”. This allowed, for example, a provider to use recipients’ telephone numbers to create its own “blocking lists”, which is punishable.
  1. “Indemnity clauses” do not shield the business against its own systemic failures

It is common practice to include clauses in commercial contracts by which the provider (processor) undertakes to pay or reimburse any AEPD fine. However, these indemnity clauses do not operate as an infallible civil liability insurance. If the AEPD detects a systemic breach attributable to the controller itself (such as, precisely, the lack of verification, lack of due diligence or the absence of an adequate processing agreement), payment of the AEPD fine cannot be transferred civilly to the subcontractor.

  • Case law: Supreme Court, Civil Chamber (First Chamber), Judgment No. 551/2023, of 19 April 2023. The Court dismissed the recourse action by which the controller sought to recover €740,000 in fines (for 26 AEPD penalties) by claiming payment from its processor, establishing that the controller’s culpability for breaching its own obligations is neither removed nor increased by the collaborator.
  1. Due diligence obligations over agencies and providers are non-transferable

The business responsible for the file can never excuse itself on the malpractice of the company it entrusts with a service in order to avoid a penalty. Fundamental obligations such as verifying that the processor offers sufficient guarantees, controlling the instructions issued or unequivocally confirming consents fall directly, personally and non-transferably on the company that orders the processing.

  • Case law: Supreme Court, Civil Chamber (First Chamber), Judgment No. 551/2023, of 19 April 2023. The High Court consolidates the doctrine that control, active supervision and verification obligations cannot be contractually delegated to the processor. A processing agreement must exist in writing on a mandatory basis, but its mere existence does not exempt the business from its non-delegable duty to supervise that the processor complies with the law.

Would your supplier contracts survive an AEPD inspection? We review your data processing agreements and flag the gaps that expose your company to a fine. Get in touch and we’ll go through it with you.

Frequently asked questions

Is a data processing agreement mandatory?

Yes. When a provider accesses personal data to deliver a service to you, article 28.3 of the GDPR requires a written contract or other legal act. Not having one is a serious infringement under article 73.k) of the LOPDGDD.

What penalty applies for not having a processing agreement?

It is a serious infringement fined by the AEPD. In a 2025 decision (EXP202407910) it proposed €200,000 —paid at €164,000 with reduction— against a company operating without this agreement after wrongly labelling itself an “independent controller”.

Does calling ourselves “independent controllers” avoid the processing agreement?

No. The AEPD looks at the reality of the processing, not the label on the contract: if one party provides a service to fulfil the other’s purpose, there is a processing arrangement that must be formalised, even if the commercial contract says otherwise.

Can I shift an AEPD fine to my provider with an indemnity clause?

Not if the breach is yours. The Supreme Court (STS 551/2023) rejected recovering €740,000 in fines from the processor: the controller’s culpability for breaching its own obligations is not transferred to the collaborator.

Can I delegate my duty to supervise to the processor?

No. Verifying that the processor offers sufficient guarantees, controlling the instructions and confirming consents are the controller’s own, direct and non-transferable duties (STS 551/2023). The agreement is mandatory, but it does not exempt you from supervising.

What happens to my database if there is no processing agreement?

You legally lose control: without documented instructions (art. 28 GDPR), the provider may use the data for its own purposes —e.g. building its own “blocking lists”— which the AEPD considers punishable (EXP202304148).



Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.

GUÍA GRATUITA

Regulación Financiera España 2026

DORA + MiCA + MiFID II + EMIR en un solo documento

Descargar gratis →

Videos relacionados

Cargando videos…

Discover more from ILP Abogados

Subscribe now to keep reading and get access to the full archive.

Continue reading