Glossary Terms

Data Processing Agreement (DPA)

A contract that governs how a processor handles personal data on behalf of a controller.
On this page

What is a data processing agreement?

A data processing agreement, often abbreviated as DPA, is a contract that governs how one party processes personal data on behalf of another. It is commonly used between a controller and a processor and sets out the scope, duration, purpose, data categories, affected people and documented instructions for the service.

The agreement should reflect the real processing rather than repeat generic legal language. It normally addresses confidentiality, security, sub-processors, assistance with individual rights, breach notification, audits, deletion or return of data and international transfers.

Why is a DPA important?

A DPA converts privacy obligations into clear operational responsibilities. It defines what the processor may do, which activities are prohibited and how the parties will cooperate. Without a suitable agreement, the controller may lack visibility or enforceable rights over important parts of the processing.

The contract also supports accountability during due diligence and audits. It provides evidence that roles, instructions and safeguards were considered before data was shared.

What should a DPA include?

Core terms usually include the subject matter and duration, nature and purpose of processing, types of personal data, categories of data subjects and controller rights. The processor should commit to follow lawful instructions, ensure confidentiality, implement appropriate security and support the controller with requests, impact assessments and regulatory enquiries.

The DPA should also regulate sub-processors, including approval or notification, equivalent contractual duties and responsibility for their performance. Transfer mechanisms and hosting or access locations should be consistent with the actual service.

How should a DPA be managed after signature?

Contracting is not the end of vendor governance. The organisation should link the agreement to the vendor record, systems, data flows, security assessment and renewal date. Product changes, acquisitions, new sub-processors or new locations may require review.

Offboarding should confirm deletion or return of data and removal of access. Material incidents and unresolved audit findings should be tracked against the contractual obligations.

Frequently asked questions

Is a DPA the same as a privacy policy?

No. A DPA is a contract between parties, while a privacy policy or notice explains processing to individuals.

Does every vendor need a DPA?

A DPA is generally relevant when the vendor processes personal data on behalf of the organisation. Other role relationships may require different terms.

Can a vendor’s standard DPA be accepted?

It can be, but the terms should be reviewed against the actual service, risk and applicable requirements. Standard language may contain gaps.

What is a sub-processor clause?

It governs the processor’s use of additional providers and normally covers approval, notice, equivalent duties and onward-transfer safeguards.

Should a DPA describe security measures?

Yes. Measures may appear in the agreement or an attached schedule and should be specific enough to support assessment and accountability.

Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.