Clym Logo

Data Processing Agreement (DPA)

Published
AS
AuthorAdam Safar

Data processing agreement (DPA) definition

A data processing agreement (DPA) is a contract between a data controller and processor that sets out how personal data is collected, used, and protected.

Summarize full article with:

What does data processing agreement mean?

A data processing agreement (DPA) is a legal contract between a data controller and a data processor that sets out how the processor may handle personal data on the controller's behalf. It covers what the processor can do with the data, the security measures it must apply, and what happens once the relationship ends.

How does a data processing agreement work?

A DPA is put in place before a processor begins handling any personal data. It typically covers the scope and purpose of processing, the categories of data involved, the processor's security obligations, rules for using sub-processors, and how the processor assists with data subject rights requests and breach notifications.

Under GDPR, a written DPA is required any time a controller uses a processor, and its absence is treated as a violation on its own. CCPA and CPRA require a similar written contract with service providers and contractors. For the full framework, including who needs one, key components, and a step-by-step process, see Clym's guide to what a data processing agreement is and when you need one.

What should a data processing agreement include?

  • Scope and purpose of the processing

  • Categories of personal data and data subjects covered

  • Security measures the processor must apply

  • Rules for using sub-processors

  • Breach notification timelines

  • What happens to the data when the contract ends

Commonly asked questions

It is a contract that sets the rules for how a vendor may use, store, and protect personal data it processes on another company's behalf, and what happens to that data once the contract ends.

No. A privacy policy is a public-facing document that tells individuals how a business handles their data. A DPA is a private contract between a business and a specific vendor that governs how that vendor is allowed to process data.

Both the data controller and the data processor sign a DPA. A controller should have one in place with every vendor that processes personal data on its behalf, and a processor should have a standard DPA ready to offer its customers.

See the full guide linked above for who needs a DPA, its key components, how it compares to related agreements, and a step-by-step process for putting one in place.

Learn how Clym's legal document management solution helps you keep your privacy documentation organized alongside your vendor agreements.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam