GlossaryCompliance operations

Data processing agreement

Short answer

A data processing agreement (DPA) is the contract the GDPR requires between a company that decides how personal data is used (the controller) and a supplier that processes that data on its behalf (the processor). It sets out what the processor may do with the data and how it must protect it.

When it is needed

Whenever a supplier handles personal data on the company's behalf: cloud and SaaS providers, payroll and HR services, IT support with access to systems, marketing platforms, call centres or security providers. Without a DPA, using the supplier is itself a breach of the GDPR.

What it must include

Article 28 sets the minimum content: the subject, duration, nature and purpose of the processing, the types of data and categories of people concerned, and the processor's obligations. These include acting only on documented instructions, confidentiality of staff, appropriate security measures, using sub processors only with authorisation and under the same terms, helping the controller with data subject requests and breach notifications, deleting or returning data at the end, and allowing audits.

International transfers

If the processor or its sub processors handle data outside the European Economic Area, the DPA must also cover the transfer mechanism, usually the European Commission's standard contractual clauses or an adequacy decision.

DPAs and security

The DPA is also where security expectations become contractual: certifications such as ISO 27001, breach notification deadlines and audit rights. Reviewing these terms is part of third party risk management. In Spain, the AEPD publishes guidance on these contracts.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub