Skip to main content
Back to knowledge base
Use case

Use case: Datacenter and GDPR compliance

A datacenter provides colocation and hosting services to hundreds of clients. As a processor of personal data, the datacenter must establish DPAs, manage sub-processors and demonstrably meet strict security requirements. This practical example shows how a medium-sized datacenter organises this.

28 March 20267 min read

The situation

A Dutch datacenter with two locations serves over 200 clients with colocation, managed hosting and cloud services. Clients range from small webshops to financial institutions and government organisations.

The datacenter itself uses external services:

  • Network: upstream providers, DDoS mitigation service, peering partners
  • Monitoring: network monitoring, environmental monitoring, CCTV systems
  • Security: physical access control service, fire detection, emergency power maintenance
  • Management: ticketing system, client portal, invoicing software
  • Certification: ISO 27001 auditors, security advisors

The challenges

DPAs with hundreds of clients

Every client processing personal data on the datacenter's infrastructure is entitled to a DPA. With 200+ clients, this means hundreds of agreements that must stay current.

Complex chain responsibility

The datacenter is a processor, but its clients may themselves be processors on behalf of their own clients. These chains make it difficult to delineate responsibilities clearly.

Demonstrating physical and logical security

Clients want proof of security measures: ISO 27001 certificate, SOC 2 report, pentest report, physical security measures. This must be centrally available.

Communicating sub-processor changes

When switching a DDoS mitigation service or upstream provider, all clients must be informed. With 200+ clients, a manual process is costly and error-prone.

The approach

Step 1: Standard DPA

The datacenter creates a standard DPA compliant with Art. 28, with technical and organisational measures as an annex referencing current certifications.

Step 2: Digital signing

New clients receive and sign the DPA digitally via the platform. Existing clients are migrated in phases.

Step 3: Certificate vault

All certificates and reports are stored centrally with expiry dates and automatic renewal reminders. Clients can access them via the platform.

Step 4: Sub-processor register and notifications

The sub-processor register is maintained in the platform. Changes trigger automatic notifications to all clients with an objection period.

Step 5: Processing register

The processor register (Art. 30(2)) is automatically generated from client agreements and service categories.

The result

  • 200+ DPAs managed digitally with current security annexes
  • 70% faster client onboarding through digital signing
  • Certificates always available for client audits without manual delivery
  • Sub-processor changes automatically communicated to all clients
  • Processing register always current and directly available for auditors
  • Reduced burden on the legal department

Lessons learned

  • Datacenters are often overlooked as processors, but the GDPR is clear: if you provide infrastructure on which personal data is processed, you are a processor
  • A standard DPA with modular annexes works better than bespoke agreements per client
  • Clients increasingly expect a self-service portal for certificates and compliance information
  • Physical security measures belong in the DPA as technical measures
  • Invest in automated sub-processor notification: it saves hours of work per change

GDPR compliance for your datacenter?

DPAkit helps datacenters and hosting providers manage DPAs, sub-processors and certificates centrally for all their clients.

Start for free