Glossary · Data protection
Data Processing Agreement (DPA)
The contract required between a controller and processor that governs how the processor may handle personal data.
What a DPA is
A Data Processing Agreement is the contract that Article 28 GDPR requires whenever a processor handles personal data on behalf of a controller, for example a payroll provider, a cloud host or a SaaS tool. It sets out the subject matter, duration, nature and purpose of processing, the types of data and data subjects, and the obligations of both parties.
What Article 28(3) requires it to contain
- Processing only on documented instructions from the controller, including for transfers to third countries.
- A duty of confidentiality for everyone authorised to process the data.
- Technical and organisational measures under Article 32.
- Rules for engaging sub-processors: prior authorisation and the same obligations passed down by contract.
- Assistance with data subject rights, breach notification and data protection impact assessments.
- Deletion or return of the data at the end of the service.
- Information and audit rights for the controller, including inspections.
In practice
The European Commission publishes standard contractual clauses for Article 28 that can be used as they are. Large providers offer their own DPA, which is acceptable as long as every element above is covered. The DPA belongs in the record of processing activities against the processor, and the technical measures it promises should be checked against what the provider actually operates rather than filed unread.