What is a data processing agreement (DPA)?
A data processing agreement (DPA) is a contract, required under GDPR Article 28, between a data controller and a data processor that processes personal data on the controller’s behalf. It sets out the scope, purpose, and duration of processing, the processor’s security obligations, its use of sub-processors, and how it assists the controller with data-subject rights and breach notification.
Controller vs processor
The controller decides why and how personal data is processed; the processor acts on the controller’s instructions. A DPA is the contract that governs that relationship whenever a processor handles personal data for a controller.
What a DPA must include
Article 28 requires terms covering the subject matter and duration, the nature and purpose of processing, the types of personal data and categories of data subject, security measures, sub-processor rules, assistance with data-subject requests and breaches, and deletion or return of data at the end.
When you need one
Any time a vendor processes personal data on your behalf (or you process it on a customer’s behalf), a DPA should be in place. It is the business-to-business contract that sits behind your public privacy notice.
FAQ
Is a DPA the same as a privacy policy?
No. A privacy policy is your public notice to individuals about how you handle their data. A DPA is a contract between two organizations (controller and processor).
Do US companies need DPAs?
If you process EU or UK personal data as a processor, or you use processors that do, then yes. GDPR obligations follow the data, not the company’s location.
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free