Skip to content
atlas

Data processing agreement (DPA)

Also known as: DPA, data processing addendum

A written contract that sets how a supplier may handle personal data on your behalf.

Draft - this entry has not been reviewed yet.

Formal

The binding contract GDPR Article 28 requires between a data controller and a data processor, setting the subject, duration and purpose of the processing, the security measures, the use of sub-processors, help after a breach and whether data is returned or deleted at the end.

In plain English

Like the written rules you leave for a house-sitter - which rooms they may enter, who else may come in, and what to do if something goes missing.

In practice

A Danish accounting firm moving client files to a cloud document system signs a DPA with the supplier stating that the files stay in the EU, that sub-suppliers need approval and that everything is deleted when the contract ends.

Why it matters

Handing personal data to a supplier without one is itself a GDPR breach, and without the agreed terms there is no way to demand audits, the removal of data or a warning after a leak.

How to put it into practice

The usual steps, in order. Adapt them to your organisation.

  1. Classify each supplier relationship first as processor, independent controller or joint controller, using EDPB Guidelines 07/2020, because an Art. 28 agreement only fits a genuine processor.
  2. Before any personal data is shared, sign a written agreement (electronic is fine) covering every Art. 28(3) item, preferably based on Datatilsynet's template or the Commission's clauses in Decision (EU) 2021/915.
  3. Fill in the annexes concretely with the processing, data categories, documented instructions, technical and organisational measures, processing locations and approved sub-processors.
  4. Set a breach notification deadline for the processor, for example 24 or 48 hours, so you can still meet your own 72-hour deadline towards Datatilsynet.
  5. Check whether the processor or its sub-processors transfer data outside the EU/EEA, and cover each transfer with an adequacy decision or standard contractual clauses and a transfer assessment.
  6. Agree the audit mechanism, including how often, which evidence is accepted (such as ISAE 3000 reports or ISO 27001 certificates) and who pays.
  7. Keep a register of agreements linked to the record of processing, supervise each processor on a risk-based schedule and review every notice of a new sub-processor.
  8. When the contract ends, have the data deleted or returned as agreed and get written confirmation that it has been done.

Common pitfalls

  • Accepting the supplier's standard agreement without reading or completing the annexes, where the real obligations are.
  • Calling a supplier a processor in the contract although it in fact decides the purposes of the processing itself.
  • Signing the agreement and never following up with the supervision it provides for.
  • Confusing the transfer clauses in Decision 2021/914 with the Art. 28 clauses in Decision 2021/915.

Good guides

Technical deep dive

GDPR Art. 28(3) prescribes the minimum content of the contract or other legal act binding the processor. It must set out the subject matter and duration, the nature and purpose of processing, the type of personal data and categories of data subjects, and the controller's obligations and rights, and it must stipulate that the processor (a) acts only on documented instructions, including on third-country transfers, (b) ensures staff confidentiality, (c) takes all measures required by Art. 32, (d) respects the conditions in Art. 28(2) and (4) for engaging sub-processors, (e) assists with data subject rights, (f) assists with Arts. 32-36 (security, breach notification, DPIAs and prior consultation), (g) deletes or returns all personal data at the end of the service, and (h) makes available all information necessary to demonstrate compliance and allows for and contributes to audits and inspections. Art. 28(9) requires the agreement to be in writing, which includes electronic form, so click-through terms referencing a published DPA are valid.

Art. 28(7) and (8) allow standard contractual clauses. The Commission adopted SCCs for controller-processor relationships in Implementing Decision (EU) 2021/915, distinct from the transfer SCCs in Implementing Decision (EU) 2021/914, whose modules 2 and 3 already embed Art. 28 terms for transfers outside the EEA. Datatilsynet's standard contractual clauses were the first adopted by a supervisory authority under Art. 28(8), following EDPB Opinion 14/2019, and are widely used as the Danish template (databehandleraftale). Using a standard set does not remove the need to fill in the annexes accurately.

The annexes are where agreements usually fail. They should describe the processing concretely, list the technical and organisational measures at a verifiable level (encryption at rest and in transit, access control model, logging, backup and restore testing, locations), name approved sub-processors with their processing locations, and define the audit mechanism: frequency, whether third-party reports such as ISAE 3000 or ISO 27001 certificates are accepted, and who pays. Breach clauses often set a concrete notification window, for example 24 or 48 hours, because Art. 33(2)'s "without undue delay" must leave the controller time to meet its own 72-hour deadline.

A DPA is only required where there is a genuine controller-processor relationship. Controller-to-controller sharing needs a legal basis and often a data sharing agreement, and joint controllers need an Art. 26 arrangement instead. Labelling a supplier as processor in a DPA does not make it one if it in fact determines purposes, as Art. 28(10) makes clear. The abbreviation also collides with "data protection authority", so contracts should spell out the term. Operationally, the DPA is only as good as its follow-up: controllers are expected to review sub-processor changes and audit evidence at least periodically, as part of supplier management.

What to learn first

Everything this builds on, foundations first.

  1. Confidentiality
  2. →Personal data
  3. →GDPR
  4. →Data processing agreement (DPA)

Relationships

Mitigates
Data breach
Mandated by
GDPR

Sources & further reading

Standards & official texts

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.