- What is actually at stake
- Step 1: Work out whether the GDPR legally applies to you
- Step 2: Understand what a data processing agreement actually requires
- Step 3: Check whether you need to appoint an EU representative
- Step 4: Map your existing practices against the GDPR's processor requirements
- Step 5: Make a commercial decision if the GDPR does not technically apply to you
- How Artificer Legal can help
- The one thing to take away
You are running an Australian business and everything feels under control — your privacy policy references the Privacy Act 1988 (Cth), you handle customer data carefully, and you have not had a complaint. Then a client in Germany or France sends through a new contract and it includes a clause requiring you to comply with the General Data Protection Regulation (GDPR). Or they ask you to sign a document called a "data processing agreement" before the engagement can proceed. You have no EU office. You did not think EU law touched you. Now you are not sure.
What is actually at stake
The GDPR is an EU regulation that governs how personal data of individuals in the European Union is handled. It is not limited to EU-based organisations. Under Article 3(2) of the GDPR, the regulation applies to any business — wherever in the world it is located — that either offers goods or services to individuals in the EU (whether or not a payment is involved) or monitors the behaviour of individuals in the EU.
This means an Australian business can be directly subject to the GDPR without having a single office in Europe, simply because it sells to, services, or tracks the behaviour of EU-based individuals.
When the GDPR does apply, the penalties are substantial. Article 83 sets out fines for the most serious infringements of up to €20 million, or 4% of total worldwide annual turnover — whichever is higher. Even lower-tier violations attract fines of up to €10 million or 2% of global annual turnover.
But the more immediate practical pressure for most Australian businesses is simpler: your EU customer cannot engage you unless you can demonstrate compliance. Losing the contract is the immediate risk; regulatory exposure is the longer-term one.
Step 1: Work out whether the GDPR legally applies to you
Before agreeing to anything, understand whether you are legally obliged to comply or whether this is a commercial request.
The GDPR distinguishes between two roles, defined in Article 4:
- Controller: the party that determines why and how personal data is processed. Your EU customer collecting end-user data and directing you on how to handle it is the controller.
- Processor: a party that processes personal data on behalf of a controller. If you are receiving, storing, analysing, or otherwise handling personal data on your EU customer's instructions, you are a processor.
A processor is bound by the GDPR even if all of its processing occurs outside the EU. That is the key extraterritorial hook.
Ask yourself these questions:
- Do I handle any personal data (names, email addresses, behavioural data, any information that could identify an individual) as part of servicing this customer?
- Is the underlying data about individuals located in the EU?
- Am I acting on the customer's instructions about what to do with that data?
If the answer to each is yes, you are likely a processor and the GDPR likely applies to you directly, not only by contract.
If you cannot answer these questions confidently after reviewing the engagement, that itself is a reason to seek advice before signing.
Step 2: Understand what a data processing agreement actually requires
If you are a processor, Article 28 of the GDPR requires that the relationship between you and the controller (your EU customer) be governed by a written contract — the data processing agreement (DPA). This is not a formality. It is a substantive document that sets out enforceable obligations.
Under Article 28(3), the DPA must record that you as processor will:
- process personal data only on the documented instructions of the controller
- ensure that the people handling the data are bound by a duty of confidentiality
- implement appropriate security measures to protect the data
- not engage any sub-processor without the controller's prior written authorisation, and impose equivalent obligations on any sub-processor you do engage (remaining fully liable if the sub-processor fails)
- assist the controller in responding to requests from data subjects exercising their rights under the GDPR
- assist the controller in meeting its obligations around security, breach notification, and data protection impact assessments
- delete or return all personal data at the end of the contract, as the controller directs
- make available all information necessary to demonstrate compliance, and submit to audits or inspections by the controller
- notify the controller immediately if you are instructed to do something that would infringe the GDPR or applicable EU data protection law
On breach notification specifically: under Article 33, a processor must notify the controller without undue delay upon becoming aware of a personal data breach. The controller then has 72 hours from becoming aware of the breach to notify the relevant EU supervisory authority (unless the breach is unlikely to result in a risk to individuals' rights and freedoms). Your timely notification underpins the controller's ability to meet that deadline.
If the DPA comes from your customer, read it in full before signing. The obligations are real and enforceable. If you are uncertain about what you are agreeing to, that is the moment to seek advice — not after the breach occurs.
Step 3: Check whether you need to appoint an EU representative
Article 27 of the GDPR requires controllers and processors that fall within the GDPR's extraterritorial scope under Article 3(2) to designate a representative established in the EU in writing. This representative acts as a contact point for EU supervisory authorities and data subjects.
There is a narrow exemption: the obligation does not apply if the processing is occasional, does not involve large-scale processing of sensitive categories of data or criminal offence data, and is unlikely to result in a risk to individuals. In practice, this exemption is interpreted narrowly by EU regulators. If you are providing services to an EU business on an ongoing basis and regularly handling personal data, you almost certainly do not qualify.
Appointing an EU representative does not mean establishing a full legal presence or subsidiary in the EU. It means engaging an individual or organisation in an EU member state to act on your behalf. However, it does require a written mandate and the representative must be reachable by EU regulators.
If you are uncertain whether this requirement applies, get advice before committing to the DPA, because the DPA itself may impose obligations that presuppose you have a representative in place.
Step 4: Map your existing practices against the GDPR's processor requirements
Do not assume your current data handling practices are GDPR-compliant just because they comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). The OAIC has noted that while the two regimes share common ground — particularly around accountability and privacy-by-design — there are differences, including individual rights under the GDPR (such as the right to erasure) that have no direct equivalent under the Privacy Act.
Before signing a DPA, work through the following:
- Records: Can you produce records of your processing activities as required by Article 30?
- Security: Are your current technical and organisational security measures documented and defensible against an audit?
- Sub-processors: Do you use any third-party service providers — cloud storage, analytics platforms, CRMs — that would also be processing the personal data? You will need written authorisation from the controller and equivalent DPAs with each sub-processor.
- Breach response: Do you have a documented internal process for identifying, assessing, and escalating a personal data breach quickly enough to meet the "without undue delay" notification requirement to the controller?
- Data deletion: At the end of the contract, will you be able to return or securely delete all personal data as the controller instructs and certify that you have done so?
Gaps identified at this stage are better addressed before you commit than discovered during an audit by your customer or an EU regulator.
Step 5: Make a commercial decision if the GDPR does not technically apply to you
Some customers ask Australian service providers to comply with the GDPR even when there is no strict legal obligation. This can happen because the customer believes (correctly or incorrectly) that you are a processor, as an internal policy requirement, as a contractual precaution, or to satisfy the customer's own legal counsel.
If your analysis in Step 1 shows the GDPR does not legally apply to you, you still face a commercial question: is the relationship worth the compliance cost?
The GDPR's processor obligations are not trivial. Implementing appropriate security measures, maintaining processing records, managing sub-processor contracts, and building a breach notification process all take time and money. Depending on the scope of the engagement, you may also need ongoing support to maintain compliance.
Weigh the revenue and strategic value of the relationship against the genuine cost of compliance — and be honest about whether you can actually deliver what the DPA requires. Committing to obligations you cannot meet in practice creates its own exposure.
How Artificer Legal can help
The moment a data processing agreement appears in your inbox is the right time to get advice, before you sign or negotiate. The situation is manageable, but the obligations in a GDPR-compliant DPA are enforceable and non-trivial.
If you bring this situation to Artificer Legal, we would:
- Review whether the GDPR actually applies to your business given the specific services you provide and the data involved, so you know whether you are legally obliged or merely commercially pressured
- Analyse the DPA your customer has provided, identify the obligations that create real risk, and advise on what can be negotiated
- Advise on whether you need to appoint an EU representative under Article 27 and how to structure that arrangement
- Map your current practices against the processor obligations in Article 28 and identify the gaps
- Draft or review your own template DPA if you service multiple EU-based clients, so you are not starting from scratch each time
- Help you build or review internal processes for breach detection and notification to meet the timelines the DPA requires
The one thing to take away
The GDPR's most under-appreciated feature for Australian processors is this: your EU customer remains liable if you mishandle their data, but you are directly liable too — to EU regulators, under EU law, regardless of where your servers are or where you are incorporated. Signing a DPA is not a transfer of risk to you from your customer; it is confirmation that both of you are independently on the hook. The time to understand the obligations is before you sign, not after the breach.
The key points from this article are: the GDPR can apply directly to Australian businesses that process personal data of EU individuals, even without any EU presence; Australian processors are required to enter into a written data processing agreement with their EU controller-customers that imposes substantive obligations; non-EU businesses caught by the GDPR may also need to appoint an EU representative in writing; and existing compliance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) does not automatically mean GDPR compliance, as the two regimes differ in meaningful ways.