Academy

/

Data Processing Agreements Between a Brand and an Influencer Marketing Platform: What GDPR Actually Requires

Guide

Influencer Marketing Basics

Brands

Data Processing Agreements Between a Brand and an Influencer Marketing Platform: What GDPR Actually Requires

When a brand uses an influencer marketing platform to handle tracking, fee payouts or campaign data, the brand is normally the GDPR controller and the platform is the processor. Article 28 requires a written Data Processing Agreement (DPA) between them before processing begins, covering eight specific elements: subject matter, duration, nature, purpose, data types, categories of data subjects, the processor's obligations, and the rules for sub-processors. A missing DPA is itself a GDPR violation — independent of whether a breach ever happens.

This is practical guidance from Make Influence, not legal advice. Use it as a checklist of what to get in place with a vendor — get the specific legal assessment of your own agreement from a lawyer.

Why this is a different question from the general GDPR article

Influencer Marketing and GDPR: What Brands Need to Know covers the whole field — what personal data is involved, the lawful basis under Article 6, and a short introduction to the data processing agreement. This article goes one level deeper on exactly one of those points: the vendor relationship between the brand and the platform running the campaign. That's a different question from "do we have a lawful basis to process the influencer's data" — it's about what the contract with the vendor itself has to contain, and what happens if it's missing.

When is the platform a processor — and when is it something else?

GDPR Article 4(7) and 4(8) define the two roles: the controller decides the purpose and means of processing; the processor processes data on the controller's behalf, on documented instructions. When a brand uses an influencer marketing platform to run tracking links, fee payouts or creator communication, the platform is typically a processor for exactly that part of the processing — it acts on the brand's instructions and may not use the campaign data for its own purposes.

But that only covers the processing the platform carries out on the brand's behalf. Most platforms are simultaneously an independent controller for their own purposes — for example when they create and manage creators' own user accounts, run their own customer relationship with the brand, or use aggregated, anonymized figures for their own product development. A platform can be a processor for your campaign data and a controller for its own data within the same contractual relationship at the same time — it isn't either/or, and it's worth keeping the two roles apart when you read a platform's terms.

SituationPlatform's role
The platform tracks clicks and sales through your tracking links and pays out fees on your instructionProcessor for the brand
The platform creates and manages creators' own logins and user profiles for its own purposeController for that part, independent of the brand
The platform uses aggregated, anonymized campaign figures to improve its own productController for the anonymized statistics — but only if the data is genuinely anonymized, not merely pseudonymized
The platform passes your campaign data to a payment provider to execute payoutsStill a processor, with the payment provider as a sub-processor — see the section below

The eight elements Article 28(3) requires in the agreement itself

The data processing agreement isn't a formality that a single line in a platform's general terms of service can satisfy. Article 28(3)(a)-(h) lists eight specific elements the agreement has to contain:

ElementWhat it means in practice for an influencer marketing platform
(a) Subject matter and durationWhat the platform processes data about — campaign participants, tracking clicks, fee recipients — and how long the agreement runs, typically tied to your subscription or campaign period
(b) Nature and purposeTracking, attribution, fee payout, reporting — described concretely, not as "general data processing"
(c) Type of personal data and categories of data subjectsCookie IDs, click IDs, IP addresses, creators' names and bank details, competition entrants' emails
(d) The controller's obligations and rightsThe brand's right to instruct, audit and halt the processing
(e) Processing only on documented instructionsThe platform may not use the campaign data for its own purposes — e.g. to target its own marketing at your customers
(f) ConfidentialityStaff at the platform with access to the data must be bound by confidentiality
(g) Security measures (Article 32)Encryption, access control and other technical and organizational measures, matched to the risk
(h) Assistance to the controllerThe platform must help the brand respond to data subject requests (e.g. a creator asking to see their own data), assist with security incidents and data protection impact assessments, delete or return data once the engagement ends, and make available information that demonstrates compliance

An agreement that skips one or more of these points doesn't satisfy Article 28 — no matter how thorough it otherwise looks. This is one of the places where a generic vendor contract differs from an actual data processing agreement: see the comparison below.

Sub-processors: what do Article 28(2) and 28(4) require?

Most influencer marketing platforms use their own sub-vendors — cloud hosting, payment providers, email tools. GDPR calls them sub-processors, and Article 28 sets two specific requirements for them:

  • Prior authorization (Article 28(2)). The platform may only use a sub-processor with the brand's general or specific written authorization. Under general authorization, the platform has to give the brand a chance to object to changes before a new sub-processor is added — not just inform it afterward.
  • Flow-down obligations (Article 28(4)). The sub-processor has to be bound by the same data protection obligations the platform itself has toward the brand, in a written agreement. If the sub-processor doesn't meet them, the platform itself remains fully liable to the brand for the sub-processor's part of the work.

In practice, that means you as a brand have a right to know which sub-processors the platform actually uses — most reputable platforms publish a list, often on their own site under "subprocessors" or a similarly named page. If that list is missing entirely, it's a specific point to ask about before signing.

What happens if there's no data processing agreement?

A missing or deficient data processing agreement is itself a GDPR violation — independent of whether a breach ever happens. That follows directly from Article 28 being a standalone obligation, not a formality that only gets triggered if something goes wrong. Article 83(4)(a) places violations of Article 28 in the lower fine tier — up to EUR 10 million or 2% of annual global turnover, whichever is higher — separate from the higher tier for violations of the basic processing principles.

Beyond the fine risk itself, a missing agreement weakens your ability to demonstrate compliance with the accountability principle in Article 5(2) — the principle that the controller must be able to show compliance, not just claim it. If a breach happens at the platform and there's no agreement setting out the platform's obligations to assist and notify you, you're typically worse placed to respond to Datatilsynet and the affected individuals within your own deadline.

Vendor contract vs. data processing agreement — what's the difference?

Ordinary vendor contractData processing agreement (Article 28)
GovernsPrice, service level, notice period, liability capsHow personal data may specifically be processed
Content requirementFreely agreed between the partiesEight statutory minimum elements, per Article 28(3)
Can one replace the other?No — the two documents govern different things and typically exist side by sideNo — it doesn't replace the collaboration contract with the individual creator either
Typical form at a platformStandard terms or an individually negotiated contractA standalone addendum or document, often called a "DPA", that has to be signed or accepted separately

Checklist: what to actually check before signing with a platform

  • Does the platform have a standard data processing agreement ready, or do you have to draft it yourselves?
  • Does the agreement cover all eight elements in Article 28(3) — not just security and confidentiality?
  • Does the platform publish a list of its sub-processors, and are you notified before a new one is added?
  • Is there a clear deletion or return deadline for data once the engagement ends?
  • Does the agreement cover transfers of data outside the EU/EEA, if the platform or its sub-processors are based there? See GDPR's international transfer rules for non-EU influencers and agencies for the full mechanics.
  • Is there a specific deadline by which the platform has to notify you of a security incident?

Decision framework

IF the platform can't produce a written data processing agreement covering Article 28(3) → treat it as a red flag, however good the rest of the sales pitch sounds.

IF the platform won't disclose its sub-processors → ask directly, and get the list in writing before signing.

IF the platform or its sub-processors are based outside the EU/EEA → check the transfer basis separately, see the dedicated article on third-country transfers.

IF the platform only points to being "GDPR-compliant" without producing an actual agreement → that's not the same as a data processing agreement, and it doesn't satisfy Article 28 on its own.

Worked example: a hypothetical review of two platforms

The example below is made up to illustrate how a review can be structured — it isn't an assessment of named platforms and isn't Make Influence customer data.

A brand compares two platforms against the checklist's six points, giving each platform one point per item it clearly satisfies (max 6 points):

Check itemPlatform APlatform B
Standard DPA ready11
All eight Article 28 elements covered10 (missing deletion deadline)
Sub-processors published10
Clear deletion/return deadline10
Third-country transfer covered11
Breach notification deadline stated10
Total6/62/6

Platform B might well have a better price or a better creator database — but on the data protection point alone, it's missing four of the six elements Article 28 assumes the agreement actually contains. That's not by itself a reason to pick Platform A, but it's a concrete negotiating point to raise with Platform B before the contract is signed.

Make Influence's operational perspective

In our experience, the data processing agreement question often only comes up late in a platform selection — typically right before contract signature, once price and tracking setup are already negotiated. We recommend asking for the vendor's standard DPA as early as possible in the process, ideally alongside the first pricing quote, so it doesn't become the last hurdle that delays an otherwise agreed deal.

FAQ

Does a UGC platform or an affiliate network also need a data processing agreement?

Yes, if they process personal data on your behalf — for example creators' bank details or click tracking data. The assessment is the same as for an influencer marketing platform: does it process the data on your instructions, or is it independently a controller for that specific processing?

Is a data processing agreement the same as an NDA?

No. An NDA protects trade secrets and confidential information generally. A data processing agreement is a statutory requirement that specifically governs the processing of personal data, per Article 28 — the two documents cover different things and don't exclude each other.

Who's liable if the platform itself has a data breach?

Both parties can become liable, but at different points: the platform, as processor, has to notify the brand of the breach without undue delay, and the brand, as controller, has its own duty to notify Datatilsynet within 72 hours if the breach poses a risk. A good data processing agreement fixes exactly how fast the platform has to notify you, so you can meet your own deadline.

Can we use the platform's standard terms, or do we need to negotiate our own DPA?

Most brands use the platform's standard DPA — that's normal practice and often the fastest route. But you should still read it against the eight points in Article 28(3), and negotiate specific gaps, rather than assuming "standard" automatically means "complete".

What if the platform refuses to sign a data processing agreement?

That should be a dealbreaker. Article 28 isn't optional once the platform is processing personal data on your behalf — a vendor that won't enter into a data processing agreement puts you in a position where you can't demonstrate compliance with your own GDPR obligations.

Does this also apply to a pure software tool, not just a full managed platform?

Yes — the requirement depends on whether the tool processes personal data on your behalf, not on how much other work the platform does for you. See how to choose an influencer marketing platform for the difference between software tools, marketplaces and managed platforms.

Make Influence

Want influencer marketing to be easier?

Find creators with real audience data, run collaborations in one place, and see clicks and sales per creator while the campaign is live.

Book a demoCreate account

Make Influence

Get paid for the audience you built

Apply to campaigns from brands that are actively looking, follow your own clicks and sales, and get paid without chasing invoices.

Create creator profileMore creator guides

Make Influence

One place for the whole collaboration

Briefs, agreed terms, tracking links and results sit together — so brands and creators see the same numbers.

See how it worksBrowse the Academy