Data Processing Agreement
A Data Processing Agreement (DPA) is a legally binding contract that sets out the rights and obligations of the parties involved when one organization processes personal data on behalf of another. It typically governs the relationship between a data controller (the entity that decides why and how data is processed) and a data processor (the entity that handles the data on the controller's instructions). The agreement commonly addresses matters such as security, the use of subprocessors, and how requests from individuals about their data are handled.
A DPA is a contractual instrument, distinct from data protection regulation itself, that allocates responsibilities and liabilities between a data controller and a data processor with respect to the processing of personal data. Its provisions generally cover definitions and interpretation, the scope and nature of processing, obligations on processor personnel, security measures, the engagement of subprocessors, and support for data subject rights. A DPA derives legal force from the contract between the parties; note that in certain jurisdictions and sectors such agreements may be required or shaped by applicable law, though the specific triggering conditions, mandatory clauses, and enforcement vary by jurisdiction and should be verified against the current authoritative text. This entry defines the instrument generally and does not itself specify the statutory requirements of any particular regime, nor does it substitute for professional judgment applied to specific circumstances.
Why it matters
A Data Processing Agreement matters because it converts abstract data protection responsibilities into concrete, enforceable contractual terms between the party that decides why and how personal data is processed (the controller) and the party that acts on its instructions (the processor). Without such an instrument, the parties may lack clarity on who bears responsibility for security measures, how subprocessors are authorized, and how requests from individuals about their data are handled. The DPA is the mechanism through which the controller extends its expectations down the processing chain and through which the processor documents the limits of its role.
It is important to keep the DPA distinct from data protection regulation itself. The agreement derives its legal force from the contract between the parties, not from being a statute; in some jurisdictions and sectors applicable law may require or shape such agreements, but the triggering conditions, mandatory content, and enforcement differ across regimes and should be verified against the current authoritative text. A DPA is therefore best understood as the contractual layer that sits alongside, and may be prompted by, the regulatory layer rather than as a substitute for it.
For organizations, a well-drafted DPA reduces ambiguity in the event of a security incident, an audit, or a dispute over liability. Because it allocates obligations and liabilities between the parties, its terms often become the first reference point when questions arise about who was responsible for a given control. Its practical value depends heavily on how accurately its scope, security provisions, and subprocessing terms reflect the actual processing arrangement.
Who it's relevant to
Inside DPA
Common questions
Answers to the questions practitioners most commonly ask about DPA.

