Article 28 of GDPR requires that any processing by a data processor on behalf of a controller is governed by a binding contract, commonly known as a Data Processing Agreement (DPA). This contract must set out the subject matter, duration, nature, and purpose of the processing, the type of personal data, categories of data subjects, and the obligations and rights of the controller. Failure to have a compliant DPA in place is a direct GDPR violation that can trigger fines under the lower tier of up to EUR 10 million or 2% of global turnover. This guide covers every aspect of DPA compliance.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
Monthly billing · cancel anytime · 30-day money-back guarantee
A DPA is a legally binding contract required by GDPR Article 28 between a data controller and a data processor. It governs how the processor handles personal data on behalf of the controller, including the subject matter, duration, nature, and purpose of processing, and incorporates eight mandatory provisions specified in Article 28(3).
A DPA is required whenever a controller engages a processor to process personal data on its behalf. This includes any third-party vendor, cloud provider, or service provider that accesses, stores, or processes personal data under the controller's instructions. The DPA must be in place before processing begins.
A DPA is required by GDPR for EU personal data processing, while a BAA is required by HIPAA for US healthcare data. Both govern third-party data handling but have different legal frameworks, required provisions, and penalties. Organizations handling both types of data may need both agreements with a single vendor.
The 2021 Standard Contractual Clauses can be used as part of a DPA, particularly for international transfers. Module Two (controller-to-processor) and Module Three (processor-to-processor) include Article 28 provisions. However, many organizations supplement SCCs with additional provisions specific to their processing relationship.
Failing to have a compliant DPA constitutes a violation of Article 28, subject to the lower fine tier of up to EUR 10 million or 2% of global annual turnover. Additionally, without a DPA, the controller lacks contractual mechanisms to enforce GDPR obligations on the processor, creating significant compliance and liability exposure.
The processor must obtain prior specific or general written authorization before engaging sub-processors. With general authorization, the processor must notify the controller of changes and allow time to object. Sub-processors must be bound by equivalent data protection obligations, and the processor remains fully liable for sub-processor compliance.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
PoliWriter creates all the policies you need for GDPR compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free