Data processing agreement (DPA) definition
A data processing agreement (DPA) is a contract between a data controller and processor that sets out how personal data is collected, used, and protected.
A data processing agreement (DPA) is a contract between a data controller and processor that sets out how personal data is collected, used, and protected.
A data processing agreement (DPA) is a legal contract between a data controller and a data processor that sets out how the processor may handle personal data on the controller's behalf. It covers what the processor can do with the data, the security measures it must apply, and what happens once the relationship ends.
A DPA is put in place before a processor begins handling any personal data. It typically covers the scope and purpose of processing, the categories of data involved, the processor's security obligations, rules for using sub-processors, and how the processor assists with data subject rights requests and breach notifications.
Under GDPR, a written DPA is required any time a controller uses a processor, and its absence is treated as a violation on its own. CCPA and CPRA require a similar written contract with service providers and contractors. For the full framework, including who needs one, key components, and a step-by-step process, see Clym's guide to what a data processing agreement is and when you need one.
Scope and purpose of the processing
Categories of personal data and data subjects covered
Security measures the processor must apply
Rules for using sub-processors
Breach notification timelines
What happens to the data when the contract ends
It is a contract that sets the rules for how a vendor may use, store, and protect personal data it processes on another company's behalf, and what happens to that data once the contract ends.
No. A privacy policy is a public-facing document that tells individuals how a business handles their data. A DPA is a private contract between a business and a specific vendor that governs how that vendor is allowed to process data.
Both the data controller and the data processor sign a DPA. A controller should have one in place with every vendor that processes personal data on its behalf, and a processor should have a standard DPA ready to offer its customers.
See the full guide linked above for who needs a DPA, its key components, how it compares to related agreements, and a step-by-step process for putting one in place.
Learn how Clym's legal document management solution helps you keep your privacy documentation organized alongside your vendor agreements.