Data Processing Agreement (DPA) FAQ
Answers to common questions about DPAs — when you need one, what GDPR requires, and key terms to include.
Basics
What is a Data Processing Agreement?
▾
A DPA is a contract between a data controller and a data processor that governs how personal data is processed. Under GDPR Article 28, a DPA is mandatory whenever a controller engages a processor to handle personal data on its behalf.
When do I need a DPA?
▾
You need a DPA whenever you share personal data with a third party that processes it on your behalf. Common scenarios: using cloud hosting, email services, analytics providers, CRM systems, payment processors, or any SaaS tool that handles your users personal data.
What must a GDPR-compliant DPA include?
▾
Article 28 requires: subject matter and duration of processing, nature and purpose, types of personal data and categories of data subjects, controller obligations and rights, processor obligations (security, sub-processor approval, breach notification, data return/deletion), and audit rights.
Ready to Create Your Contract?
Describe your deal in plain English. Three AI agents draft, review, and refine your contract in minutes.
Get StartedAI-generated draft for review. Not legal advice.