TERM · SECURITY

Data processing agreement (DPA)

What is a data processing agreement (DPA)?

A data processing agreement (DPA) is the contract between a company and every supplier that stores or handles its customers’ data — the host, the email platform, the accounting software. An outside support team counts too. It records what data is processed, for what purpose, for how long, under which security measures, and what happens to it when the contract ends. GDPR requires it in writing.

Example

A company site sits on a host, sends its newsletter through an outside platform, takes enquiries in a form and passes orders to accounting software. Four suppliers see personal data. The company decides what the data is used for, which makes it the controller; the suppliers act on its instructions, which makes them processors. Each of them needs a written agreement.

A courier is a different case: it carries duties of its own under law and is usually a separate controller rather than a processor. That distinction is settled explicitly, not assumed, because it decides who answers for what when something goes wrong.

Why it matters for a business

The agreement names the subject matter, the duration, the kinds of data and the categories of people, but the useful clauses are the others: processing only on documented instructions, confidentiality for everyone with access, security measures, rules for sub-processors — who may be brought in and how you are told, help with a customer request, help during a breach, and what happens to the data at the end, returned or deleted, with confirmation.

Where the data physically sits is a separate check. When the supplier or one of its sub-processors is outside the EU, the transfer runs on a Chapter V ground, most often the European Commission’s standard contractual clauses. This is not paperwork for its own sake: it is the first thing asked about in an audit. Which system holds customer records usually starts with the CRM.

What to ask

  • Is there a signed agreement with every supplier that sees data, and where are those agreements kept?
  • Who are the supplier’s sub-processors, and how are you told about a new one?
  • Where is the data stored, and is any of it transferred outside the EU?
  • How quickly does the supplier help with an access or deletion request?
  • What happens to the data when the contract ends, and within what period?

The list of suppliers around a site changes with every new integration, which is why we review it during website maintenance.

A term you do not recognise? Write to us and we will add it.

The glossary grows with the questions we are asked.