Skip to content

Compliance & Privacy

Data Processing Agreement (DPA)

A contract between a data controller and data processor governing the processing of personal data in compliance with privacy regulations.

Overview

A contract between a data controller and data processor governing the processing of personal data in compliance with privacy regulations.

  • Multi-Jurisdiction Support
  • Draft in Minutes
  • AI-Assisted Drafting

Who Needs This Document?

Companies using third-party data processors, cloud service providers, SaaS vendors, and any business processing data on behalf of another entity.

When Do You Need This?

Required under GDPR and similar regulations whenever a business (controller) engages a third party (processor) to handle personal data on its behalf.

Key Provisions

A well-drafted document should include the following essential provisions:

  • Subject matter and duration of processing
  • Nature and purpose of processing, types of personal data
  • Technical and organizational security measures
  • Sub-processor obligations and notification requirements

Frequently Asked Questions

What is the difference between a data controller and a data processor in a DPA?
The controller decides why and how personal data is processed and bears primary responsibility for compliance, while the processor handles data on the controller's behalf and strictly according to its instructions. A DPA formalizes this relationship, making clear the processor can't use the data for its own separate purposes beyond what the controller has authorized.
Can a data processor bring in a sub-processor without the controller's approval?
Generally no; most DPAs require either specific prior approval for each sub-processor or, at minimum, advance notice giving the controller a chance to object before a new sub-processor is engaged. This matters because the controller remains accountable for how the data is ultimately handled, even by parties several layers removed from the original agreement.
What details must a DPA specify about how data will be processed?
A DPA should specify the subject matter and duration of processing, the categories of personal data and data subjects involved, the purpose of the processing, and the security measures the processor commits to maintaining. Leaving these details generic rather than specific to the actual arrangement undermines the DPA's purpose of creating real accountability.

Related Documents

Back to Document Library