Skip to content
← All terms

Glossary · Privacy & regulation

DPA (data processing agreement)

A data processing agreement (DPA) is the contract required by GDPR Article 28 between a data controller and a data processor, setting out the scope, purpose, and security obligations governing the processor’s handling of personal data on the controller’s behalf.

Whenever a controller hands personal data to another organization to process on its behalf — a hosting provider, an email-delivery service, an analytics vendor that processes identifiable data — GDPR Article 28 requires a written contract, not just a verbal understanding or a line in a terms-of-service page. The DPA has to specify the subject matter and duration of processing, its nature and purpose, the categories of data and data subjects involved, and the controller’s and processor’s respective obligations.

Substantively, a compliant DPA commits the processor to act only on the controller’s documented instructions, to impose confidentiality on anyone processing the data, to implement appropriate technical and organizational security measures, to assist the controller with data-subject rights requests and breach notifications, to delete or return data at the end of the engagement, and to flow the same obligations down to any sub-processor it engages — which is why sub-processor lists and consent mechanisms appear as DPA annexes.

A DPA is a contractual layer, distinct from a transfer mechanism like standard contractual clauses: a DPA governs the relationship and duties between controller and processor, while SCCs (when needed) govern the legal basis for moving data across a border. The two often accompany each other in the same document set when a processor is outside the EU/EEA.

See also

Related terms