
How to Contract hosted this webinar with Laura Frederick, Founder and CEO of How to Contract, in the host seat. She was joined by Robby Reggers, Founder and Senior Legal Counsel at AMST Legal, and Marta Hovanesian, Founder of Nor Law. Robby came at the subject as a commercial contracts generalist who runs into data privacy at the end of almost every deal, and Marta came at it as a privacy specialist who spent a decade on data protection and now helps US companies scale into the EU. That pairing worked well, because most of us sit exactly where Robby sits and need the specialist answer translated into something we can use on a redline.
Want unlimited access to 110+ webinar replays? Our paid members get permanent access to webinar recordings from 2024 and 2025, plus 30+ hours of courses courses, certifications, and our massive expert library. If you just want an individual webinar, register in advance to get access to the recording for 14 days. You can sign up for our auto registration list so you are registered for every webinar we host. Learn more about our membership →
The conversation moved from the big picture of when GDPR reaches a US company through the controller and processor distinction, Article 28 and documented instructions, international transfers and standard contractual clauses, data subject rights assistance, and the sub-processor chain. It closed on liability, including super caps for data breaches and whether regulator fines sit inside or outside the cap.
Here are our top ten takeaways from the speakers' comments during the webinar:
Assume there is personal data until you have confirmed otherwise. Robby warned against the reflex answer that a deal has no personal data in it. The line he hears most often is that it is only work email, and that answer is usually wrong, because other data sitting alongside it can identify a person. Ask how the product gets sold, how customer names get stored, and what happens to the data after the sale. Merely viewing data on your screen counts as processing.
Work out the controller and processor roles before you pick a template. Robby's shorthand was that the employer controls employee data and the HR platform just does what the employer tells it to do. Marta's test was sharper. Look at who decides what data gets collected, whose data it is, who gets access, who it goes to, and how long it stays. Also check whether a law obligates the processing, because the law often names the controller for you.
Do not treat vendor status as automatic. Most vendors are processors, and that rule of thumb gets you started, but Robby told a story about a data protection officer who arrived at a large company, spent a month reading everything, and concluded the company had been calling itself a processor for years when it was actually a controller for part of its services. Every contract had to be rewritten. The same entity can be a controller for one activity and a processor for another.
Handle joint and co-controller relationships as their own contracting problem. No DPA is required when both sides are controllers, which surprises people. What you do need is an arrangement covering who answers individual requests, how the two of you cooperate on a breach, and how liability sits between you, since an individual can come after either party for the full amount. Marta noted the essentials of that arrangement have to be public, in a privacy notice or on a sign-up page.
Put a DPA in place even when someone tells you it is not necessary. Robby's advice was to not let sales or procurement talk you out of it, because scope changes constantly in software and tech. New products, new services, and new data show up after signature. He also flagged old DPAs and stale security annexes as a renewal problem worth catching. Marta added that a DPA is a good idea regardless of GDPR, since roughly 163 countries now regulate data use and most US state laws copied the GDPR requirements for a DPA.
Keep documented instructions workable instead of literal. Marta does not read the documented instructions requirement as needing an email every time you want your processor to do something. The services agreement scopes them, the DPA description of services scopes them, and platform settings and feature choices can count as instructions too. What matters is that you can tell the processor to change a retention period or stop collecting something and they actually comply. A processor that ignores instructions becomes a controller by operation of law and inherits compliance gaps it never planned for.
Incorporate the clause text by reference and attach the annexes. Marta used to attach the full standard contractual clauses to the agreement, but once a deal needs six different sets, that stops working. She now incorporates the clauses by reference and attaches the three annexes as a physical document. Annex one covers the parties and the description of processing, annex two covers security measures, and annex three lists sub-processors. She adds all three to a DPA even with no transfer, because you always need the security measures and the processing description anyway.
Map your transfers beyond the EU. The EU clauses are only part of the picture now. Marta listed Saudi Arabia, the Dubai International Financial Centre, Argentina, Brazil, and China as jurisdictions with their own transfer clause requirements, and the UK needs its own addendum. Switzerland accepts the EU set with tweaks so that references to the EU read as Switzerland. For multinational clients she covers intra-affiliate transfers in a single intra-affiliate agreement and handles vendors market by market.
Treat US adequacy as conditional. Marta explained that US companies are adequate recipients only when they self-certify under the Data Privacy Framework, and everyone else still needs clauses. The predecessors to that framework were invalidated, litigation against it continues, and the framework rests on executive orders that can be changed or withdrawn. On top of the clauses, you still owe a transfer impact assessment of whether the receiving country actually protects the data at an equivalent level. Her read was that US transfers are more a geopolitical question than a legal one.
Get ready to answer individual requests before one lands. Robby has had clients tell him they simply were not going to respond, and his answer was that they were going to. The rights to know, correct, and erase are real, and the fines are real, including a recent penalty of more than 800 million euros against Uber over driver deactivations. The rights are not absolute, so you can push back on a request for every email and call in a spreadsheet, but you owe a professional answer either way. Marta added that the processor side of this belongs in the DPA, along with who pays when assistance goes beyond what the product already does.
Subscribe to Stay in the Loop
Our weekly newsletter keeps you current on upcoming How to Contract webinars and brings you recaps like this one when you cannot make the live session. Subscribe now and get the practical takeaways delivered to you.








