Skip to main content
Back to knowledge base
Guide

What is a data processing agreement?

A data processing agreement (DPA) is a legally required contract between a controller and a processor. In this article we explain when you need one, what it must contain, and how to get started in practice.

28 March 20268 min read

Controller versus processor

The GDPR distinguishes between two roles in the processing of personal data. The controller determines the purpose and means of processing. The processor processes personal data on behalf of the controller.

If you use a payroll provider to run your payroll, you are the controller and the payroll provider is the processor. The GDPR requires you to have a data processing agreement in place.

When is a data processing agreement required?

Article 28(3) of the GDPR stipulates that processing by a processor shall be governed by a contract. This is mandatory in every situation where an external party processes personal data on your behalf, regardless of the scale or type of data.

Common situations requiring a DPA:

  • A cloud provider storing your customer data (SaaS platforms, hosting)
  • A payroll provider running your payroll administration
  • A marketing agency using email addresses for campaigns
  • An IT administrator with access to your systems
  • A call centre handling customer enquiries on your behalf

What must a data processing agreement contain?

Article 28(3) GDPR prescribes a number of mandatory provisions. A DPA must contain at least the following:

1. Subject matter and duration of processing

Clearly describe which processing activities the processor carries out and for what period. This gives both parties clarity about the scope of the engagement.

2. Nature and purpose of processing

Why are the personal data being processed? Think of payroll administration, customer service, cloud storage or marketing campaigns.

3. Type of personal data and categories of data subjects

Specify which data are processed (name, email, national ID number, health data) and whose data they are (employees, customers, patients).

4. Obligations and rights of the controller

The controller retains the right to give instructions to the processor and must ensure that the legal basis for processing is in order.

5. Instruction-bound processing

The processor may only process personal data on the basis of documented instructions from the controller (Art. 28(3)(a)).

6. Confidentiality

Persons authorised to process the personal data at the processor must be bound by a confidentiality obligation (Art. 28(3)(b)).

7. Security measures

The processor implements appropriate technical and organisational measures pursuant to Art. 32 GDPR to ensure an appropriate level of security.

8. Sub-processors

The processor does not engage another processor (sub-processor) without prior consent of the controller. Where a general written authorisation is given, the processor must inform the controller of any changes.

9. Assistance with data subject rights

The processor assists the controller in responding to data subject requests (access, rectification, erasure, etc.) under Art. 15-22 GDPR.

10. Assistance with breach notification and DPIAs

The processor assists the controller in complying with obligations around data breaches (Art. 33-34) and data protection impact assessments (Art. 35-36).

11. Deletion or return after termination

After the end of the processing services, the processor deletes all personal data or returns them, unless storage is required by law.

12. Audit rights

The processor makes available all information necessary to demonstrate compliance and allows for audits and inspections (Art. 28(3)(h)).

Common mistakes

  • Not having a DPA at all — this is mandatory even for small vendors
  • Using a generic template without customisation — the agreement must be specific to the processing
  • Forgetting to address sub-processors — a common source of non-compliance
  • Not tracking when agreements expire — renewals and reassessments are essential

Practical tips

  • Inventory all external parties that process personal data on your behalf
  • Use a template that covers all Art. 28 requirements, but customise it per vendor
  • Maintain a central register of all DPAs with expiry dates
  • Schedule annual reviews to check agreements are still up to date
  • Use a tool like DPAkit to generate, send and centrally manage data processing agreements

Summary

A data processing agreement is an essential element of GDPR compliance whenever you have an external party process personal data. Art. 28 GDPR prescribes exactly what it must contain. By managing your DPAs in a structured way, you avoid fines and demonstrate to auditors that you take compliance seriously.

Manage data processing agreements with DPAkit

Generate, send and manage data processing agreements from a single platform. GDPR-compliant and hassle-free.

Start for free