Data Processing Agreement (DPA)

The contract required before a vendor touches your users' data: what they may do with it, how they protect it, what happens when you leave.

the paperwork vendors ask forthe privacy contract with subprocessorsdpadata processing addendumdata proccessing agreementvendor privacy contractthe contract that lets a tool touch my users' datagdpr contract with a vendor

See it

Live demo coming soon

What it is

A DPA is the contract that has to be in place before a vendor handles personal data on your behalf. It pins down the boring but load-bearing details: what data, for what purpose, for how long, what security they keep, whether they may hire subprocessors, how they help you answer user deletion requests, and what they delete or return when you leave. Under GDPR it is not optional paperwork, it is required before a processor may process anything. What it does not do is make the processing lawful. A DPA satisfies the Article 28 contracting requirement; you still need your own lawful basis for the processing, and a valid transfer mechanism if the data crosses a border.

In practice you sign more of these than you write. Every serious SaaS publishes a standard DPA (often called a data processing addendum) that you accept with a click or a countersignature, usually with the Standard Contractual Clauses bolted on for transfers outside the EU. If you sell to businesses, expect to publish your own so your customers can tick their box.

Gotcha: signing a DPA does not offload the risk, it documents it. You are still the controller, so you still have to pick vendors that can actually meet the terms and re-check when they change. The clause people skip is the subprocessor-change notice window: if it says 'we may update the list at any time' you have no real chance to object.

Ask AI for it

Draft a Data Processing Agreement for us as the processor, structured as an addendum to our main terms. Include: definitions, subject matter and duration, nature and purpose of processing, categories of data subjects and personal data, processing only on documented instructions, confidentiality of staff, security measures (list concrete controls), subprocessor authorisation with a 30-day objection window and a linked public list, assistance with data subject requests and breach notification timelines, audit and information rights, international transfer mechanism, and deletion or return of data on termination. Flag every spot where I must fill in a company-specific fact rather than accept a default.

You might have meant

data controller and data processorsubprocessorstandard contractual clausescross border data transferdata retention policy

Go deeper