A data processing agreement when a consultant gets access to your Business Central
When a consultant signs in to your Business Central, they can see customer, vendor and employee data. The partner is then normally a data processor, and you are the data controller. That requires a written agreement. This article describes what such an agreement normally covers and what you should ask about. It is not legal advice. Have your own adviser or data protection officer confirm what applies in your case.
Why the agreement exists
GDPR requires a company that lets someone else process personal data on its behalf to have an agreement with them. This also applies if a consultant can only see data during troubleshooting. The agreement describes what the processor may do and what it must ensure.
Ask whether the partner has a standard agreement and whether you have a template of your own. Many companies do.
It is also a good idea to clarify who at the partner can get access, and how many. The fewer people, the easier it is to control. Ask whether the partner gives access only to those who need it.
What an agreement normally contains
A data processing agreement typically describes the following. Check that each point is clear and that it fits the access the consultant actually gets.
- Purpose and duration of the processing
- Which types of personal data and which groups of people it concerns
- That the processor acts only on your instructions
- Confidentiality for the staff who get access
- Security measures, both technical and organisational
- Help with answering access requests and handling breaches
- How and when data is deleted or returned at the end
- Your right to check, for example through audit or documentation
Sub-processors
If the partner uses other suppliers who also get access to data, they are called sub-processors. This could be a support system, an IT operations supplier or an AI tool. The agreement should contain a list of them and a way for you to be told if the list changes.
Ask whether you can object to a new sub-processor and what happens if you do. See also the article on AI tools in support.
Ask for a named list and for what information each of them can access. Check that the partner has concluded agreements with them that impose the same requirements as you impose on the partner.
Transfers outside the EU
If data is processed by a party outside the EU and the EEA, the rules set special requirements for the basis of the transfer. Ask whether any of the partner's employees or subcontractors are located outside the EU and whether they can see your data. Ask for the agreement to state which transfer basis is used. Have your adviser assess it.
Ask also where your data physically sits when a consultant works with it. Microsoft states which region an environment is in, and you can see that in the admin center. But a consultant's own computer, a support system or an AI tool may be somewhere else. That is what the agreement must describe.
Also remember the access arrangements in Business Central
Microsoft Learn says that a delegated administrator appears in your environment as a user with a pseudonym and the company's name, and that actions can be followed in the change log. This makes it easier to document who has had access. Ask the partner who is behind each pseudonym.
Limit access to what is necessary. Microsoft describes that per environment you can switch partner access on and off and restrict it to specific partners. See the article on remote support and access.
Next steps
Ask for the partner's agreement, read it against your checklist, and have your own adviser confirm it. At Addverk you will find information about support on the page about services and prices.
Short, concrete e-mails about what customers most often ask us. We write when we have something worth reading.