Data Processing Agreement
A Data Processing Agreement (DPA) is a legal contract that sets out the rights and obligations of the parties involved when one organization handles personal data on behalf of another. It typically defines how data is handled between the party that decides why and how data is processed and the party that carries out that processing. The goal is to make responsibilities for data handling and security explicit in writing.
A DPA is a binding legal agreement, commonly entered into between a data controller and a data processor, that governs the processing of personal data. It outlines the rights and obligations of the parties and typically addresses the categories of personal data involved, the handling procedures, and the terms under which processing occurs. In many arrangements a DPA is incorporated as an integral part of a broader service agreement and applies specifically to the processing of defined categories of personal data. It is generally used to help the parties demonstrate compliance with applicable data protection obligations, though the specific terms and enforceable commitments vary by contract and jurisdiction.
Why it matters
A Data Processing Agreement matters because it converts assumptions about who handles personal data, and how, into explicit written obligations. When one organization processes personal data on behalf of another, ambiguity about responsibilities can create both legal exposure and security gaps. A DPA reduces that ambiguity by defining the rights and obligations of the parties, the categories of personal data involved, and the handling procedures that apply. Without such an agreement, the parties may disagree over who is responsible for security controls, breach handling, or the boundaries of permitted processing.
For security leaders, the DPA is where governance and vendor risk management intersect with contract law. It typically forms an integral part of a broader service agreement and applies specifically to the processing of defined categories of personal data. This is important because signing a DPA does not, by itself, guarantee compliance with any particular data protection regime; the enforceable commitments vary by contract and jurisdiction. A DPA supports the parties in demonstrating compliance with applicable data protection obligations, but the substance depends on the terms actually negotiated and whether both parties operate as described.
A common and important distinction is between accountability and the practical work of processing. Even where a processor carries out data handling on a controller's behalf, the controller generally retains its own obligations under applicable law. A virtual or fractional CISO advising on a DPA should treat it as a governance and risk instrument rather than a purely technical checkbox, and should be clear that a signed agreement does not transfer the client's own regulatory responsibilities unless the law and contract specifically provide for it.
Who it's relevant to
Inside DPA
Common questions
Answers to the questions practitioners most commonly ask about DPA.