Skip to content
atlas

Data processing agreement (DPA)

Also known as: DPA, data processing addendum

A written contract that sets how a supplier may handle personal data on your behalf.

Draft - this entry has not been reviewed yet.

Formal

The binding contract GDPR Article 28 requires between a data controller and a data processor, setting the subject, duration and purpose of the processing, the security measures, the use of sub-processors, help after a breach and whether data is returned or deleted at the end.

In plain English

Like the written rules you leave for a house-sitter - which rooms they may enter, who else may come in, and what to do if something goes missing.

In practice

A Danish accounting firm moving client files to a cloud document system signs a DPA with the supplier stating that the files stay in the EU, that sub-suppliers need approval and that everything is deleted when the contract ends.

Why it matters

Handing personal data to a supplier without one is itself a GDPR breach, and without the agreed terms there is no way to demand audits, the removal of data or a warning after a leak.

Technical deep dive

GDPR Art. 28(3) prescribes the minimum content of the contract or other legal act binding the processor. It must set out the subject matter and duration, the nature and purpose of processing, the type of personal data and categories of data subjects, and the controller's obligations and rights, and it must stipulate that the processor (a) acts only on documented instructions, including on third-country transfers, (b) ensures staff confidentiality, (c) takes all measures required by Art. 32, (d) respects the conditions in Art. 28(2) and (4) for engaging sub-processors, (e) assists with data subject rights, (f) assists with Arts. 32-36 (security, breach notification, DPIAs and prior consultation), (g) deletes or returns all personal data at the end of the service, and (h) makes available all information necessary to demonstrate compliance and allows for and contributes to audits and inspections. Art. 28(9) requires the agreement to be in writing, which includes electronic form, so click-through terms referencing a published DPA are valid.

Art. 28(7) and (8) allow standard contractual clauses. The Commission adopted SCCs for controller-processor relationships in Implementing Decision (EU) 2021/915, distinct from the transfer SCCs in Implementing Decision (EU) 2021/914, whose modules 2 and 3 already embed Art. 28 terms for transfers outside the EEA. Datatilsynet's standard contractual clauses were the first adopted by a supervisory authority under Art. 28(8), following EDPB Opinion 14/2019, and are widely used as the Danish template (databehandleraftale). Using a standard set does not remove the need to fill in the annexes accurately.

The annexes are where agreements usually fail. They should describe the processing concretely, list the technical and organisational measures at a verifiable level (encryption at rest and in transit, access control model, logging, backup and restore testing, locations), name approved sub-processors with their processing locations, and define the audit mechanism: frequency, whether third-party reports such as ISAE 3000 or ISO 27001 certificates are accepted, and who pays. Breach clauses often set a concrete notification window, for example 24 or 48 hours, because Art. 33(2)'s "without undue delay" must leave the controller time to meet its own 72-hour deadline.

A DPA is only required where there is a genuine controller-processor relationship. Controller-to-controller sharing needs a legal basis and often a data sharing agreement, and joint controllers need an Art. 26 arrangement instead. Labelling a supplier as processor in a DPA does not make it one if it in fact determines purposes, as Art. 28(10) makes clear. The abbreviation also collides with "data protection authority", so contracts should spell out the term. Operationally, the DPA is only as good as its follow-up: controllers are expected to review sub-processor changes and audit evidence at least periodically, as part of supplier management.

What to learn first

Everything this builds on, foundations first.

  1. Confidentiality
  2. →Personal data
  3. →GDPR
  4. →Data processing agreement (DPA)

Relationships

Mitigates
Data breach
Mandated by
GDPR

Sources & further reading

Standards & official texts

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.