Data Processing (DPA)

A data processing agreement (DPA) sets out how a supplier may handle personal data on behalf of a customer, as required by data protection law.

What it does

Under the EU General Data Protection Regulation (GDPR), and similar laws elsewhere, a company that decides why and how personal data is used is a controller. A supplier that handles that data on the controller’s instructions, such as a SaaS provider, payroll bureau, or hosting company, is a processor. GDPR Article 28 requires a written contract between the two, with specific mandatory content. That contract is the DPA.

The DPA describes the processing: subject matter, duration, purpose, types of data, and categories of individuals. It sets the processor’s obligations: act only on documented instructions, bind staff to confidentiality, apply appropriate security, use sub-processors only with authorisation, assist the controller with individuals’ rights, notify breaches without undue delay, delete or return data at the end, and allow audits.

The DPA also covers international transfers. Data leaving the European Economic Area needs a lawful transfer mechanism, most often the European Commission’s standard contractual clauses, which the DPA includes or references.

Example wording

The Supplier shall process Personal Data only on the documented instructions of the Customer, shall ensure that persons authorised to process it are bound by confidentiality, shall implement appropriate technical and organisational security measures, shall not engage a sub-processor without the Customer’s prior authorisation, shall notify the Customer without undue delay after becoming aware of a Personal Data Breach, and shall, at the Customer’s choice, delete or return all Personal Data at the end of the Services.

Risks for SMBs

No DPA at all. Many SMBs use SaaS tools, freelancers, and agencies that handle customer or employee data with no DPA in place. The controller remains responsible regardless. If a supplier touches personal data, get a DPA signed.

Signing the supplier’s DPA unread. Large suppliers present a non-negotiable DPA. It usually meets the legal minimum, but check where data is stored and transferred, how sub-processors are approved and changed, and the breach notification timeline. “Without undue delay” in the law often becomes 72 hours or longer in supplier terms, leaving the controller little time to meet its own deadlines.

General sub-processor authorisation. Most DPAs give general authorisation to use sub-processors, with a right to object to new ones. In practice the only remedy on objection is to terminate.

Liability carve-outs. DPAs often interact badly with the main contract’s liability cap. Either data protection liability is capped at a level that would not cover a serious incident, or it is uncapped and the SMB supplier is carrying unlimited risk.

Instructions you did not give. A processor acting outside the controller’s instructions may become a controller itself, with full liability. SMB suppliers should not use customer data for analytics, model training, or product improvement without explicit contractual permission.

Jurisdiction. GDPR applies to organisations in the EU and to many outside it that serve EU individuals. The UK, Switzerland, and others have similar but not identical rules.

Common variants and negotiation points


This page is general information about a common contract clause. It is not legal advice and does not account for your jurisdiction, industry, or the specific contract in front of you. Talk to a qualified lawyer before relying on it.

Tracking renewal dates, notice periods, and other contract obligations is what Trackado does.