Sometimes, the deciding factor is not that they send you an invoice. GDPR distinguishes between someone processing personal data under your direct authority and someone processing it on your behalf as a separate processor. The first needs instructions and confidentiality. The second needs an Article 28 contract. A freelancer can be either, and which one they are is a question about how the relationship actually works.
This article covers the three positions a contractor can occupy, the statutory provision that separates them, the factors that decide which applies, what to put in place for each, and why the answer has consequences beyond data protection.
The Question Is Whose Authority, Not Whose Payroll
GDPR has a category most people forget sits between "employee" and "vendor." Article 4(10) defines a third party as anyone other than the data subject, controller, processor, "and persons who, under the direct authority of the controller or processor, are authorised to process personal data." Article 29 then says those persons must not process personal data except on the controller's instructions. Article 32(4) repeats the obligation as a security measure.
That category is what covers your employees. It is why you do not sign a DPA with your own staff. And nothing in the wording limits it to people on payroll — it turns on direct authority, not on employment contracts or tax treatment.
So the real question for a freelancer is which side of that line they sit on. If they work under your direct authority, they are within Article 29 and no DPA is required. If they process personal data on your behalf but under their own operational control, they are a processor and Article 28 applies. This is genuinely unsettled at the margins: when the EDPB consulted on its guidelines covering the concepts of controller and processor, one of the formal responses asked it to clarify precisely how Article 29 applies to external workers whose position is close to that of employees. The question being asked by a European federation of data protection officers is a fair signal that it is not obvious.
The Three Positions A Freelancer Can Occupy
Under your direct authority. A long-term contract developer who works in your systems, uses your accounts, follows your security policies, takes day-to-day direction from your team and has no independent discretion over the data. Functionally an employee for these purposes. Article 29 applies; no DPA.
A processor. An agency, a studio or an independent specialist who processes personal data for you but decides how they do it, works on their own infrastructure, serves other clients with the same setup, and exercises operational control. Article 28 applies and a contract is required.
Their own controller. A recruiter, an accountant, an occupational health provider or a lawyer who determines their own purposes and is subject to their own professional obligations. They are not processing on your behalf at all. No DPA — though a data-sharing position needs recording, and if you genuinely set the purposes jointly, Article 26 joint controllership brings its own arrangement requirement.
Most freelance relationships in a small SaaS fall into the first two, and companies default to the second because it feels safer. That default is not free: it means the contract commitments in Article 28(3) actually have to be met by someone who probably cannot meet them.
What Actually Decides It
There is no bright line, and the assessment is fact-specific. The factors that matter are the ones that show who exercises control in practice.
Whose systems is the work done on — your laptop, your SSO, your repositories, or theirs? Who sets the method, not just the outcome? Is the person integrated into your team, in your standups and your Slack, or engaged for a defined deliverable? Do they serve other clients with the same infrastructure? Do they have discretion over how personal data is handled, or do they follow your process?
The more integrated the person is, the stronger the argument that they act under your direct authority. Independent legal analysis of self-employed contractors reaches the same conclusion — the more integrated they are into the organisation, the more persuasive the case that they are in a position akin to an employee. Checked 8 August 2026, that remains the mainstream reading, and it has not been settled by a court.
Where you land, write it down. A one-line note in the engagement record saying which position the person occupies and why is cheap, and it is the difference between a considered judgement and an accident.
What To Put In Place For Each
For someone under your direct authority, you need documented instructions, a confidentiality commitment, access scoped to what the work requires, and offboarding that actually revokes it. Most companies already have an NDA in place, which covers the secrecy part and nothing else — the difference between confidentiality and processor obligations is exactly what separates a DPA from an NDA, and it is why one cannot substitute for the other.
For a processor, you need the Article 28 contract, and the terms that usually cause trouble with a small supplier are deletion or return at the end of the engagement, prior authorisation for anyone they bring in, and processing strictly on documented instructions. Ask a solo freelancer to commit to those and you often discover the relationship is really the first kind.
There is a third consideration that catches people out. If the contractor is outside the UK or EEA and personal data reaches them there, you have a transfer to handle on top of everything else, and the instrument you need for that is a separate question from the DPA itself.
This article is deliberately narrow — it is about employment status and the authority test. The broader question of which vendors need a DPA at all covers the rest of your supplier list.
Common Mistakes With Contractor Data Access
Signing a DPA with everyone to be safe. A DPA with someone who is actually under your direct authority misdescribes the relationship and commits both sides to obligations neither will meet. An unperformed contract is worse evidence than no contract, because it shows you knew the obligation existed.
Relying on the NDA. Confidentiality is one sub-paragraph of the eight things Article 28(3) requires. It says nothing about deletion, sub-processing, assisting with data subject requests or allowing audits, which are the terms that actually bite.
Giving contractors the same standing access as employees and no more paperwork. Whichever position they occupy, access should be scoped and time-bound to the engagement. The most common finding in a vendor review is an active account belonging to someone whose contract ended eleven months ago.
Treating overseas contractors as a purely contractual question. A developer in a third country receiving personal data is an international transfer. It needs a transfer mechanism regardless of how you have classified them for Article 28 purposes.
Assuming an agency's contract covers the individuals it supplies. If you contract with an agency, your Article 28 relationship is with the agency, and the individuals they place work under the agency's authority. If those individuals in practice take direction from you, the paperwork and the reality have diverged and only one of them is what a regulator looks at.
FAQ
Does a freelancer with read-only access still need a DPA?
Read-only access is still processing — retrieval and consultation are both listed as processing operations in Article 4(2). Whether a DPA is required depends on the authority question, not the permission level. A read-only contractor under your direct authority needs instructions and confidentiality; a read-only independent processor still needs Article 28 terms.
What if the contractor never touches customer data, only our internal systems?
Your own staff records are personal data too, so internal-only access does not remove the question. It usually reduces the volume and sensitivity, which affects how much scrutiny the arrangement warrants, but the analysis is the same one.
Can we just add data protection clauses to the services agreement?
Yes. Article 28 requires a contract or other legal act containing the required terms; it does not require a standalone document. A well-drafted schedule to the services agreement is entirely sufficient and often more likely to be signed than a separate DPA.
Does classifying a contractor as under our direct authority create employment risk?
It can, and it is worth flagging to whoever handles your contracts. The factors that support direct authority — integration, your systems, your direction, your process — are close relatives of the factors used to assess employment status for tax and employment rights purposes. The two analyses are legally distinct but they read the same evidence.
Closing Thought
There is an awkward symmetry in this question that is worth naming. The argument that avoids the DPA — this person works under our direct authority, in our systems, following our instructions, integrated into our team — is very close to the argument that they are not really a contractor. You can be comfortable on the data protection side or comfortable on the employment side, and the same set of facts is doing the work in both. Most companies resolve this by not thinking about it in one place at a time, which is fine until someone reads both files.
The honest resolution is to describe the relationship as it actually is and accept the consequences on both sides. ComplyDog can help with the part that faces outward — a compliance portal on your own domain covering your DPA, subprocessor list, data subject request forms and security page, including automated DPA signing through DocuSign and Dropbox Sign when a contract genuinely is needed. Deciding whether a particular contractor is a processor is a judgement about your own working arrangements, and no tool makes it for you.