← Back to news 23.07.2026

Two lists nobody reconciles

The data processing agreement and the register of processors describe the same service providers, from two angles. Legally they belong together, in practice they are two separate lists that drift apart. Why exactly this gap surfaces in an audit, and how the register entry can be derived from the contract itself.

A data processing agreement and the register of processors describe the same service providers, just from two angles. The contract governs the conditions under which a provider may process personal data, under Article 28 of the GDPR. The register demonstrates to the supervisory authority whom you work with, as part of accountability. Legally the two belong together. In practice they are two separate lists.

Two lists always drift apart

The reason is mundane and human. The contract is concluded by legal or procurement, the register is maintained by data protection. A new contract is signed and filed, the entry in the register happens later, or not at all. At the next audit the assessor asks about exactly this gap: here is a contract, where is the processor in the register? And the other way around, for this listed provider, where is the contract?

Connect what belongs together anyway

This gap is not closed with more discipline but by joining the two lists into one. Whoever creates a data processing agreement names the provider and its role in it anyway. From exactly that the register entry can be derived, instead of typing it a second time by hand. The contract becomes the source, the register entry the consequence, and the two can no longer drift apart.

How isidaten connects it

That is exactly how contract management in isidaten works: create a contract of the type data processing agreement, and the matching processor appears automatically in the data protection administration, with name and role taken from the contract and uniquely assigned via the contract number. The entry stays editable but is there from the start, instead of waiting for someone to add it. On top comes what a contract module has to do anyway: keeping terms and notice periods in view, reminders before expiry, a standard catalog of common contract types. So the contract does not remain a loose sheet but carries the accountability with it.

More is shown on the contract management module page. How the other data protection duties come together in one place is covered by the GDPR solution page.

Matching solution isidaten for DSGVO

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.