Data processing agreement

A data processing agreement (DPA) sets rules for how a service provider handles personal data on a customer’s behalf, as privacy laws often require.

What it means

A DPA is a contract, often an addendum to a main services agreement, that governs how a vendor handles personal data it processes for a customer. Privacy laws drive it. Under the EU’s GDPR, a business that decides how data is used (the “controller”) must have a written contract with specific terms with any vendor that processes the data for it (a “processor”). A growing number of US state privacy laws, including California’s, also require contracts that limit how service providers use personal information.

Say a small online shop uses an email marketing platform and a freelance developer who can access its customer database. The DPA would say the vendor processes the data only on the shop’s instructions, keeps it secure, uses only approved subprocessors, reports breaches promptly, helps with customer privacy requests, and deletes or returns the data when the work ends. If data leaves the EU, the DPA may also include approved transfer terms such as standard contractual clauses.

Vendors usually offer their own DPA, which tends to give them flexibility, for example to add new subprocessors with only a notice. Customers want short breach deadlines and audit rights. Which laws apply depends on where the people whose data is processed are located and what data is involved, so one DPA may need to cover several regimes.

What to watch for

  1. Check that the DPA limits the vendor to processing data only on your documented instructions and for the stated purpose.
  2. Look at how quickly the vendor must notify you of a data breach and what details it must provide.
  3. See how subprocessors are approved, whether you get notice of changes, and whether you can object.
  4. Confirm what happens to the data when the contract ends, including deletion or return and any backups.
  5. Check whether the DPA covers international transfers and the privacy laws that actually apply to your customers.

Example clause

Processor will process Customer Personal Data only on Customer’s documented instructions and will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach. Processor will not engage a new Subprocessor without giving Customer at least 30 days’ prior written notice and an opportunity to object.

The vendor may use your customers’ data only as you direct, must tell you about a breach within two days, and must warn you before bringing in new subcontractors.

Legal glossary