Technology, Data & Privacy

Data Processing Agreement

A data processing agreement defines how a service provider processes personal data on documented instructions and allocates security, subprocessor, rights-request, transfer, incident, audit, deletion, and assistance duties.

Direct answer

What is the purpose of Data Processing Agreement?

Use a DPA when one party processes personal data for another and tailor roles, instructions, locations, transfers, and security measures to the actual data flow and applicable privacy law.

01

What Data Processing Agreement does

A data processing agreement defines how a service provider processes personal data on documented instructions and allocates security, subprocessor, rights-request, transfer, incident, audit, deletion, and assistance duties.

A useful document turns the parties' actual arrangement into measurable duties, approvals, timing, remedies, and a reliable execution record. Its terms should be reconciled to the transaction rather than copied from an unrelated form.

02

When this agreement is commonly used

  • A cloud or service vendor handles customer-controlled personal data
  • A company appoints an analytics, payroll, support, or infrastructure processor
  • An existing service expands to new data categories, regions, subprocessors, or purposes

03

When another document or professional review may be better

The document name alone does not determine the right structure. Consider a different instrument or qualified legal review when any of these conditions applies:

  • Do not use processor language where both parties independently determine purposes and means without analyzing the correct roles.
  • A DPA cannot legitimize undisclosed, excessive, insecure, or otherwise unlawful product behavior.

04

Information to collect before drafting

Record exact facts before clauses are written. Names, authority, dates, amounts, defined terms, dependencies, and incorporated materials should be verifiable and consistent.

  • Parties’ privacy roles, services, instructions, purposes, duration, and contacts
  • Data subjects, categories, sensitive data, systems, locations, retention, and deletion
  • Security measures, access, subprocessors, transfer mechanisms, and change notices
  • Incident reporting, rights requests, assessments, audits, regulator support, and return process

05

Key decisions to make

These decisions shape the allocation of responsibility and should not be left for boilerplate to decide:

  • Which party determines each purpose and essential means
  • Which systems, data, people, and jurisdictions are in scope
  • How subprocessor changes and cross-border transfers are controlled
  • What incident, rights-request, audit, return, and deletion timing is feasible

06

Provisions the agreement commonly addresses

  • Scope, roles, documented instructions, and confidentiality
  • Security measures and personal-data incident response
  • Subprocessors and international transfers
  • Individual rights, assessments, records, audit, and regulator assistance
  • Return, deletion, survival, liability, and governing terms

Every provision should use the same parties, dates, standards, defined terms, and document hierarchy. A clause that is reasonable by itself can still create a conflict when it is not reconciled with payment, default, termination, or another exhibit.

07

How to prepare a Data Processing Agreement

  1. 01Describe the intended result and the relationship in plain language.
  2. 02Confirm parties, authority, governing jurisdiction, dates, money, property, services, and approvals.
  3. 03Resolve the key decisions and identify every schedule, exhibit, disclosure, consent, or filing.
  4. 04Draft the provisions as one consistent system, then review the complete execution set before signature.

08

Material risks and source-backed checks

Generic DPAs often misstate roles or security and ignore actual subprocessors and product telemetry. Contract terms must follow the mapped data lifecycle and applicable jurisdictions.

09

Supporting documents and the complete package

The main agreement may establish the framework while schedules, exhibits, disclosures, consents, or operational records supply transaction-specific details.

  • Processing-details annex
  • Technical and organizational measures
  • Subprocessor and transfer-mechanism schedule

Each incorporated document should be identified precisely, use the same names and effective date, and follow a stated order of precedence if terms conflict.

10

Review and execution checklist

Complete a data map and role analysis, attach real security measures and subprocessors, establish request and incident contacts, implement transfer safeguards, and verify deletion settings.

  • Confirm legal names, roles, capacity, addresses, and signing authority
  • Reconcile dates, amounts, definitions, cross-references, schedules, and exhibits
  • Confirm that duties, deadlines, approvals, acceptance standards, and payment triggers are measurable
  • Check that default, termination, remedies, and surviving obligations work together
  • Complete jurisdiction-specific forms, notices, witnesses, notarization, filings, or professional review when applicable
  • Deliver and preserve the complete signed package with its incorporated documents

11

Authoritative references and further reading

These sources provide federal, state-resource, regulatory, or institutional context. They do not replace checking the law and required forms applicable to the parties, transaction, and governing jurisdiction.

  1. Source 1

    General Data Protection Regulation, Article 28

    European Union. Official processor-contract requirements in EU data-protection law.

  2. Source 2

    Guidelines 07/2020 on controller and processor concepts

    European Data Protection Board. Institutional guidance for assigning GDPR privacy roles.

  3. Source 3

    Data Security

    Federal Trade Commission. Federal business guidance for reasonable data-security practices.

  4. Source 4

    California Consumer Privacy Act

    California Department of Justice. Official California privacy-law resources.

Frequently asked questions

Questions about Data Processing Agreement

What does a Data Processing Agreement establish?

A data processing agreement defines how a service provider processes personal data on documented instructions and allocates security, subprocessor, rights-request, transfer, incident, audit, deletion, and assistance duties.

When is a Data Processing Agreement usually the wrong document?

Do not use processor language where both parties independently determine purposes and means without analyzing the correct roles. A DPA cannot legitimize undisclosed, excessive, insecure, or otherwise unlawful product behavior.

Is a DPA required whenever two companies share personal data?

Not always. The requirement and form depend on applicable law and the parties’ roles. Controller-to-controller sharing may need a different agreement and transparency analysis.

Which decisions should be settled before drafting a Data Processing Agreement?

Before drafting, the parties should resolve these agreement-specific questions: Which party determines each purpose and essential means; Which systems, data, people, and jurisdictions are in scope; How subprocessor changes and cross-border transfers are controlled; What incident, rights-request, audit, return, and deletion timing is feasible. They should reconcile those choices with the governing jurisdiction and the verified intake facts, including: Parties’ privacy roles, services, instructions, purposes, duration, and contacts.

What may need to accompany a Data Processing Agreement?

The execution package may include Processing-details annex, Technical and organizational measures, Subprocessor and transfer-mechanism schedule. The parties should attach only the materials that apply and identify each one by name, date, or version.

Related contract guides

Documents commonly considered alongside this agreement