/
Data Processing Agreements Between a Brand and an Influencer Marketing Platform: What GDPR Actually Requires
Guide
Influencer Marketing Basics
Brands
When a brand uses an influencer marketing platform to handle tracking, fee payouts or campaign data, the brand is normally the GDPR controller and the platform is the processor. Article 28 requires a written Data Processing Agreement (DPA) between them before processing begins, covering eight specific elements: subject matter, duration, nature, purpose, data types, categories of data subjects, the processor's obligations, and the rules for sub-processors. A missing DPA is itself a GDPR violation — independent of whether a breach ever happens.
This is practical guidance from Make Influence, not legal advice. Use it as a checklist of what to get in place with a vendor — get the specific legal assessment of your own agreement from a lawyer.
Influencer Marketing and GDPR: What Brands Need to Know covers the whole field — what personal data is involved, the lawful basis under Article 6, and a short introduction to the data processing agreement. This article goes one level deeper on exactly one of those points: the vendor relationship between the brand and the platform running the campaign. That's a different question from "do we have a lawful basis to process the influencer's data" — it's about what the contract with the vendor itself has to contain, and what happens if it's missing.
GDPR Article 4(7) and 4(8) define the two roles: the controller decides the purpose and means of processing; the processor processes data on the controller's behalf, on documented instructions. When a brand uses an influencer marketing platform to run tracking links, fee payouts or creator communication, the platform is typically a processor for exactly that part of the processing — it acts on the brand's instructions and may not use the campaign data for its own purposes.
But that only covers the processing the platform carries out on the brand's behalf. Most platforms are simultaneously an independent controller for their own purposes — for example when they create and manage creators' own user accounts, run their own customer relationship with the brand, or use aggregated, anonymized figures for their own product development. A platform can be a processor for your campaign data and a controller for its own data within the same contractual relationship at the same time — it isn't either/or, and it's worth keeping the two roles apart when you read a platform's terms.
| Situation | Platform's role |
|---|---|
| The platform tracks clicks and sales through your tracking links and pays out fees on your instruction | Processor for the brand |
| The platform creates and manages creators' own logins and user profiles for its own purpose | Controller for that part, independent of the brand |
| The platform uses aggregated, anonymized campaign figures to improve its own product | Controller for the anonymized statistics — but only if the data is genuinely anonymized, not merely pseudonymized |
| The platform passes your campaign data to a payment provider to execute payouts | Still a processor, with the payment provider as a sub-processor — see the section below |
The data processing agreement isn't a formality that a single line in a platform's general terms of service can satisfy. Article 28(3)(a)-(h) lists eight specific elements the agreement has to contain:
| Element | What it means in practice for an influencer marketing platform |
|---|---|
| (a) Subject matter and duration | What the platform processes data about — campaign participants, tracking clicks, fee recipients — and how long the agreement runs, typically tied to your subscription or campaign period |
| (b) Nature and purpose | Tracking, attribution, fee payout, reporting — described concretely, not as "general data processing" |
| (c) Type of personal data and categories of data subjects | Cookie IDs, click IDs, IP addresses, creators' names and bank details, competition entrants' emails |
| (d) The controller's obligations and rights | The brand's right to instruct, audit and halt the processing |
| (e) Processing only on documented instructions | The platform may not use the campaign data for its own purposes — e.g. to target its own marketing at your customers |
| (f) Confidentiality | Staff at the platform with access to the data must be bound by confidentiality |
| (g) Security measures (Article 32) | Encryption, access control and other technical and organizational measures, matched to the risk |
| (h) Assistance to the controller | The platform must help the brand respond to data subject requests (e.g. a creator asking to see their own data), assist with security incidents and data protection impact assessments, delete or return data once the engagement ends, and make available information that demonstrates compliance |
An agreement that skips one or more of these points doesn't satisfy Article 28 — no matter how thorough it otherwise looks. This is one of the places where a generic vendor contract differs from an actual data processing agreement: see the comparison below.
Most influencer marketing platforms use their own sub-vendors — cloud hosting, payment providers, email tools. GDPR calls them sub-processors, and Article 28 sets two specific requirements for them:
In practice, that means you as a brand have a right to know which sub-processors the platform actually uses — most reputable platforms publish a list, often on their own site under "subprocessors" or a similarly named page. If that list is missing entirely, it's a specific point to ask about before signing.
A missing or deficient data processing agreement is itself a GDPR violation — independent of whether a breach ever happens. That follows directly from Article 28 being a standalone obligation, not a formality that only gets triggered if something goes wrong. Article 83(4)(a) places violations of Article 28 in the lower fine tier — up to EUR 10 million or 2% of annual global turnover, whichever is higher — separate from the higher tier for violations of the basic processing principles.
Beyond the fine risk itself, a missing agreement weakens your ability to demonstrate compliance with the accountability principle in Article 5(2) — the principle that the controller must be able to show compliance, not just claim it. If a breach happens at the platform and there's no agreement setting out the platform's obligations to assist and notify you, you're typically worse placed to respond to Datatilsynet and the affected individuals within your own deadline.
| Ordinary vendor contract | Data processing agreement (Article 28) | |
|---|---|---|
| Governs | Price, service level, notice period, liability caps | How personal data may specifically be processed |
| Content requirement | Freely agreed between the parties | Eight statutory minimum elements, per Article 28(3) |
| Can one replace the other? | No — the two documents govern different things and typically exist side by side | No — it doesn't replace the collaboration contract with the individual creator either |
| Typical form at a platform | Standard terms or an individually negotiated contract | A standalone addendum or document, often called a "DPA", that has to be signed or accepted separately |
IF the platform can't produce a written data processing agreement covering Article 28(3) → treat it as a red flag, however good the rest of the sales pitch sounds.
IF the platform won't disclose its sub-processors → ask directly, and get the list in writing before signing.
IF the platform or its sub-processors are based outside the EU/EEA → check the transfer basis separately, see the dedicated article on third-country transfers.
IF the platform only points to being "GDPR-compliant" without producing an actual agreement → that's not the same as a data processing agreement, and it doesn't satisfy Article 28 on its own.
The example below is made up to illustrate how a review can be structured — it isn't an assessment of named platforms and isn't Make Influence customer data.
A brand compares two platforms against the checklist's six points, giving each platform one point per item it clearly satisfies (max 6 points):
| Check item | Platform A | Platform B |
|---|---|---|
| Standard DPA ready | 1 | 1 |
| All eight Article 28 elements covered | 1 | 0 (missing deletion deadline) |
| Sub-processors published | 1 | 0 |
| Clear deletion/return deadline | 1 | 0 |
| Third-country transfer covered | 1 | 1 |
| Breach notification deadline stated | 1 | 0 |
| Total | 6/6 | 2/6 |
Platform B might well have a better price or a better creator database — but on the data protection point alone, it's missing four of the six elements Article 28 assumes the agreement actually contains. That's not by itself a reason to pick Platform A, but it's a concrete negotiating point to raise with Platform B before the contract is signed.
In our experience, the data processing agreement question often only comes up late in a platform selection — typically right before contract signature, once price and tracking setup are already negotiated. We recommend asking for the vendor's standard DPA as early as possible in the process, ideally alongside the first pricing quote, so it doesn't become the last hurdle that delays an otherwise agreed deal.
Yes, if they process personal data on your behalf — for example creators' bank details or click tracking data. The assessment is the same as for an influencer marketing platform: does it process the data on your instructions, or is it independently a controller for that specific processing?
No. An NDA protects trade secrets and confidential information generally. A data processing agreement is a statutory requirement that specifically governs the processing of personal data, per Article 28 — the two documents cover different things and don't exclude each other.
Both parties can become liable, but at different points: the platform, as processor, has to notify the brand of the breach without undue delay, and the brand, as controller, has its own duty to notify Datatilsynet within 72 hours if the breach poses a risk. A good data processing agreement fixes exactly how fast the platform has to notify you, so you can meet your own deadline.
Most brands use the platform's standard DPA — that's normal practice and often the fastest route. But you should still read it against the eight points in Article 28(3), and negotiate specific gaps, rather than assuming "standard" automatically means "complete".
That should be a dealbreaker. Article 28 isn't optional once the platform is processing personal data on your behalf — a vendor that won't enter into a data processing agreement puts you in a position where you can't demonstrate compliance with your own GDPR obligations.
Yes — the requirement depends on whether the tool processes personal data on your behalf, not on how much other work the platform does for you. See how to choose an influencer marketing platform for the difference between software tools, marketplaces and managed platforms.
Make Influence
Find creators with real audience data, run collaborations in one place, and see clicks and sales per creator while the campaign is live.
Book a demoCreate accountMake Influence
Apply to campaigns from brands that are actively looking, follow your own clicks and sales, and get paid without chasing invoices.
Create creator profileMore creator guidesMake Influence
Briefs, agreed terms, tracking links and results sit together — so brands and creators see the same numbers.
See how it worksBrowse the Academy