Skip to content
Glossary

Data Processing Agreement (DPA)

Definition

A Data Processing Agreement defines the legal obligations between controller and processor when handling personal data. It's mandatory under GDPR Article 28 whenever a service provider gains access to customer data, employee data, or other personal information on behalf of the controller. Without a DPA, fines can reach up to €10 million or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher.

A DPA differs from the privacy policy you show end customers. While the latter informs data subjects about the processing, the DPA defines instruction authority: you remain the controller, the vendor may only act on your instructions. In marketing automation with US tools like HubSpot or Mailchimp, this distinction becomes practically relevant. The vendor processes your contact data but makes no independent decisions about purpose or method. This instruction-bound role makes them a processor, not a joint controller.

In daily B2B operations, you need DPAs for virtually every SaaS vendor handling personal data: CRM systems, email tools, analytics platforms, chatbot providers. Most US vendors offer standardized DPAs you can accept online. With Customer Data Platforms or AI agents, it gets more complex because data flows to third countries without adequacy decisions require additional safeguards. Since Schrems II, standard contractual clauses are no longer automatically sufficient: you have to assess case by case whether the law of the destination country undermines the contractual guarantees, and only where that assessment shows gaps do you need supplementary measures such as encryption or pseudonymization that make access by local authorities practically impossible.

The biggest trap lies in the illusion of compliance. A signed DPA doesn't automatically protect you from fines. Supervisory authorities increasingly audit whether you actually monitor compliance with contractual obligations. That means regular audits, documentation of data breaches, proof of deletion deadlines. With AI systems, many vendors cannot fully isolate training data. If your customer data flows into a model other customers use, that violates instruction-bound processing. Costs arise less from the DPA itself than from ongoing compliance work: legal counsel, data protection officers, technical audits.

When selecting vendors, ensure the DPA specifies concrete technical and organizational measures, not just general declarations of intent. Check whether the vendor uses subprocessors and how their oversight is regulated. For data privacy in marketing: the more sensitive the data, the tighter the instruction authority. For newsletter delivery, a standard DPA suffices. For predictive analytics with health data, you need individual agreements that precisely define purpose limitation and deletion periods. The DPA isn't a form but a control instrument for data flows that requires active management.

This is how this technology works in practice.

See how we put technologies like this to work for companies, or talk to us directly.