What is Data Processing Agreement?
Definition
A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor that specifies the terms for processing personal data. Under GDPR Article 28, a DPA is mandatory whenever a controller engages a processor.
In Depth
Data Processing Agreements are a critical contractual mechanism for ensuring that third parties who process personal data meet appropriate security and privacy standards. Under GDPR, a DPA must include specific provisions: the subject matter, duration, nature, and purpose of processing; the types of personal data and categories of data subjects; the obligations and rights of the controller; and detailed processor obligations including processing only on documented instructions, ensuring confidentiality, implementing appropriate security measures, assisting with DSARs and DPIAs, deleting or returning data upon termination, and providing information necessary to demonstrate compliance. Beyond GDPR, DPAs are increasingly common in other regulatory contexts: HIPAA requires similar agreements called Business Associate Agreements (BAAs), and SOC 2 evaluations consider whether appropriate contractual controls are in place for sub-service organizations. Organizations should maintain a register of all DPAs, ensure they are executed before processing begins, include Standard Contractual Clauses for international transfers, and review them when the scope of processing changes.
Related Frameworks
Related Terms
GDPR
The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union that governs how personal data of EU residents is collected, processed, stored, and transferred. It became enforceable on May 25, 2018, and applies to any organization worldwide that processes EU resident data.
Vendor Management
Vendor management in compliance refers to the processes and controls used to assess, monitor, and mitigate risks associated with third-party service providers who access an organization's data or systems. It includes due diligence, contractual requirements, and ongoing monitoring.
Privacy Policy
A privacy policy is a public-facing legal document that describes how an organization collects, uses, shares, and protects personal information. It must be transparent, accurate, and compliant with applicable privacy laws in all jurisdictions where the organization operates.
Data Subject Access Request
A Data Subject Access Request (DSAR) is a formal request made by an individual to an organization asking what personal data is held about them, how it is processed, and to whom it has been disclosed. Under GDPR, organizations must respond within 30 days.
Generate compliance docs with PoliWriter
Stop reading about compliance and start achieving it. PoliWriter generates audit-ready policies customized to your organization in hours.
Get Started Free