A legally binding contract between a data controller and a data processor that outlines how personal data will be handled, stored, and protected.
Security & Compliance
In our reference library
A legally binding contract between a data controller and a data processor that outlines how personal data will be handled, stored, and protected. The data processing agreement (DPA) defines the rules of engagement for personal data: purpose limits, security measures, retention and deletion terms, sub-processor rules, and obligations on breach notification. For buyers, the DPA is where privacy promises become enforceable, so its review belongs in procurement, not after signature. Key clauses to verify include scope of processing, whether the vendor processes data only on instructions, rights for individuals' requests, and what happens on contract termination. Sub-processor provisions matter because they determine notice and objection rights when vendors add providers. Vendors that publish clear, current DPAs demonstrate mature compliance programs, while those resisting standard terms create negotiating friction that signals weaker governance. Buyers in regulated sectors should engage legal review of the DPA before finalizing any purchase.