Data Processing Agreement (DPA)
Also called: DPA · Data Processing Addendum · Processor Agreement
A data processing agreement governs how one party processes personal data on another’s behalf. It sets out the purpose and scope of processing, security obligations, use of sub-processors, breach notification duties, and what happens to the data when the contract ends.
In more detail
Where a vendor handles personal data for a customer, most modern data-protection regimes require a written agreement covering a defined set of points. A DPA is usually annexed to the main contract rather than negotiated as a separate deal.
The commercially significant terms are sub-processor rights and breach notification. A vendor able to change sub-processors without notice, or with a long breach-notification window, transfers real risk to the customer — who typically remains accountable to regulators and to its own users.
Deletion and return obligations at termination matter more than they appear. A DPA that is silent on what happens to data after the contract ends leaves the customer without a contractual route to get it back or have it destroyed.
The mandatory content of a processing agreement is set by the data-protection law applying to the data subjects, not the vendor’s location. A product serving users across regions may need to satisfy several regimes at once.
What our lawyers check
- Scope and purpose limitation — whether the vendor can use data beyond providing the service
- Sub-processor approval rights and notice of changes
- Breach notification timeframes, and whether they are workable for your own obligations
- Data return and deletion obligations at termination
Contracts where this clause matters
Related terms
This definition is general information about commercial contracting practice, not legal advice. How a clause operates depends on the specific wording of your agreement and the law that governs it. For advice on your contract, have it reviewed by a lawyer.
All glossary terms