Data Processing (DPA)
A data processing agreement (DPA) sets out how a supplier may handle personal data on behalf of a customer, as required by data protection law.
What it does
Under the EU General Data Protection Regulation (GDPR), and similar laws elsewhere, a company that decides why and how personal data is used is a controller. A supplier that handles that data on the controller’s instructions, such as a SaaS provider, payroll bureau, or hosting company, is a processor. GDPR Article 28 requires a written contract between the two, with specific mandatory content. That contract is the DPA.
The DPA describes the processing: subject matter, duration, purpose, types of data, and categories of individuals. It sets the processor’s obligations: act only on documented instructions, bind staff to confidentiality, apply appropriate security, use sub-processors only with authorisation, assist the controller with individuals’ rights, notify breaches without undue delay, delete or return data at the end, and allow audits.
The DPA also covers international transfers. Data leaving the European Economic Area needs a lawful transfer mechanism, most often the European Commission’s standard contractual clauses, which the DPA includes or references.
Example wording
The Supplier shall process Personal Data only on the documented instructions of the Customer, shall ensure that persons authorised to process it are bound by confidentiality, shall implement appropriate technical and organisational security measures, shall not engage a sub-processor without the Customer’s prior authorisation, shall notify the Customer without undue delay after becoming aware of a Personal Data Breach, and shall, at the Customer’s choice, delete or return all Personal Data at the end of the Services.
Risks for SMBs
No DPA at all. Many SMBs use SaaS tools, freelancers, and agencies that handle customer or employee data with no DPA in place. The controller remains responsible regardless. If a supplier touches personal data, get a DPA signed.
Signing the supplier’s DPA unread. Large suppliers present a non-negotiable DPA. It usually meets the legal minimum, but check where data is stored and transferred, how sub-processors are approved and changed, and the breach notification timeline. “Without undue delay” in the law often becomes 72 hours or longer in supplier terms, leaving the controller little time to meet its own deadlines.
General sub-processor authorisation. Most DPAs give general authorisation to use sub-processors, with a right to object to new ones. In practice the only remedy on objection is to terminate.
Liability carve-outs. DPAs often interact badly with the main contract’s liability cap. Either data protection liability is capped at a level that would not cover a serious incident, or it is uncapped and the SMB supplier is carrying unlimited risk.
Instructions you did not give. A processor acting outside the controller’s instructions may become a controller itself, with full liability. SMB suppliers should not use customer data for analytics, model training, or product improvement without explicit contractual permission.
Jurisdiction. GDPR applies to organisations in the EU and to many outside it that serve EU individuals. The UK, Switzerland, and others have similar but not identical rules.
Common variants and negotiation points
- Sub-processor changes. A reasonable middle ground is 30 days’ notice of new sub-processors, with a right to object and to terminate the affected service without penalty if the objection cannot be resolved.
- Breach notification. Ask for notification within a defined short period, 24 to 48 hours after awareness is common, with the information the controller needs to assess and report the breach.
- Audit rights. Suppliers typically offer audit reports or certifications instead of on-site audits. Accept these, but keep a right to audit if a report reveals problems or a breach occurs.
- Deletion timelines. Specify how long after termination data is deleted, including from backups, and ask for written confirmation.
Related clauses
- Confidentiality: the general secrecy obligation that sits alongside the DPA.
- Liability cap: how data liability is capped or carved out.
- Subcontracting: sub-processors are subcontractors with extra rules.
- Audit rights: how the controller verifies compliance.
This page is general information about a common contract clause. It is not legal advice and does not account for your jurisdiction, industry, or the specific contract in front of you. Talk to a qualified lawyer before relying on it.
Tracking renewal dates, notice periods, and other contract obligations is what Trackado does.