Data Processing Agreement(DPA)
A contract required under data-protection law (notably GDPR Article 28) between a data controller and a data processor that defines the scope, purpose, security, and obligations of personal-data processing.
What it means
A Data Processing Agreement (DPA) is mandatory whenever a controller engages a processor to handle personal data subject to the GDPR (EU) or analogous laws (UK GDPR, CCPA/CPRA in California). It must specify the subject matter, duration, nature and purpose of processing, types of data, categories of data subjects, and the controller's rights and obligations. Sub-processor approval, security measures, and international-transfer mechanisms (SCCs) are standard.
Read more
- GDPR Data Processing Agreements: A Plain-English Guide — Everything you need to know about GDPR Data Processing Agreements (DPAs): what Article 28 requires, mandatory clauses, sub-processors, SCCs, and common mistakes.