What is a data processing agreement (DPA)?

Learn why a Data Processing Agreement (DPA) is essential for compliance. Explore key clauses, jurisdictional differences, and tips for negotiating safe data terms.

6 min readUpdated September 2026

The short answer

A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor. It outlines the scope, nature, and purpose of data processing activities, ensuring that both parties comply with privacy regulations like GDPR, CCPA, or the Digital Personal Data Protection Act. The agreement specifies how personal data is handled, stored, and protected, preventing unauthorized use. Essentially, it ensures that processors only act on the instructions of the controller while maintaining strict security standards for all sensitive information.

Have the contract in front of you? upload it for a free contract review with Lawly AI and see the exact wording in your own document.

The Core Purpose of a DPA

A Data Processing Agreement serves as a roadmap for how personal information is handled by third parties. It is not just a best practice but a legal requirement under frameworks like the EU's GDPR and the UK's version of the same law. Without a DPA, a company sharing user data with a cloud provider or marketing agency could face massive fines for non-compliance.

The document clearly defines the roles of the 'Controller' (who decides why data is collected) and the 'Processor' (who handles data on behalf of the controller). By signing this, the processor commits to providing sufficient guarantees regarding technical and organizational security measures.

Jurisdictional Differences and Standards

In the European Union and UK, the GDPR mandates specific language in DPAs, including the processor's duty to assist in audits and breach notifications. In the United States, there is no single federal law, but state laws like the CCPA/CPRA require similar contractual protections for 'service providers' handling California residents' data.

In India, the Digital Personal Data Protection Act (DPDP) has introduced stricter requirements for data fiduciaries and processors. While the terminology varies, the global trend is moving toward mandatory written contracts that penalize the unauthorized sub-processing of data without the controller's prior written consent.

  • EU/UK GDPR: Mandatory specific clauses under Article 28.
  • USA (CCPA): Focuses on prohibiting the sale of personal data.
  • India (DPDP): Emphasizes the duty of data fiduciaries to protect data.
  • Standard Contractual Clauses (SCCs): Used for international data transfers.
  • Liability: Often a major point of friction during negotiations.

Sub-processing and Transparency

One of the most critical aspects of a DPA is the control over sub-processors. A sub-processor is a third party hired by the processor to help perform their duties. Controllers must know where their data goes, so DPAs usually require processors to get approval before adding new sub-contractors.

Transparency is maintained through regular updates to the sub-processor list. If a controller objects to a new sub-processor for security reasons, the DPA should provide a mechanism for the controller to terminate the service without heavy penalties.

Security Measures and Audits

A DPA must detail the specific security standards the processor will implement, such as encryption, pseudonymization, and regular vulnerability testing. It is not enough to say security will be 'adequate'; the contract should reference specific certifications like ISO 27001 or SOC 2.

Furthermore, the right to audit is a standard requirement. The controller or an independent auditor should be allowed to inspect the processor's facilities or digital logs to ensure compliance with the agreed terms.

  • Encryption of data at rest and in transit.
  • Confidentiality obligations for all personnel handling data.
  • Mandatory 24-72 hour breach notification windows.
  • Assistance with Data Subject Access Requests (DSARs).
  • Data deletion or return protocols after contract ends.

Data Deletion and Return

When a business relationship ends, the DPA dictates what happens to the remaining data. The processor cannot simply keep the data in their archives indefinitely. They must either delete it entirely or return it to the controller in a usable format.

This clause protects the controller from 'vendor lock-in' and ensures that the data subject's right to be forgotten is respected. The processor should provide a written certification that all copies of the data, including backups, have been purged.

Sample clause language

Illustrative wording, written for this guide — not copied from any real contract.

General Sub-processor Clause
The Processor may engage third-party sub-processors at its sole discretion without notifying the Controller. The Processor shall not be liable for the data breaches of such sub-processors, and the Controller waives the right to audit these third parties.

This is highly risky. It removes all transparency and accountability, leaving the controller liable for the processor's unknown partners.

Standard Sub-processor Clause
The Processor shall notify the Controller of any intended changes concerning the addition or replacement of sub-processors at least 30 days in advance. The Controller may object to such changes on reasonable grounds, in which case the parties will work in good faith to find a solution.

This is balanced. It allows the processor to grow while giving the controller visibility and a right to object to risky partners.

Red flags to look for

  • Clauses that allow the processor to use data for their own marketing purposes.
  • Indemnity caps that limit the processor's liability for data breaches.
  • Vague language regarding the timeline for notifying the controller of a breach.
  • Terms that waive the controller's right to conduct a security audit.
  • Provisions allowing the processor to move data to high-risk jurisdictions without consent.
  • No clear procedure for deleting data after the contract expires.

Not sure whether your contract has these problems? Lawly AI reads the whole document, quotes the risky wording back to you, and scores the overall risk in about a minute.

What to ask for

  • Demand a maximum 48-hour window for data breach notifications.
  • Specify that sub-processors must be held to the same contractual standards as the primary processor.
  • Ensure the right to audit is not buried under high administrative fees.
  • Clarify that 'anonymized data' must be truly irreversible to be used by the processor.
  • Link the DPA to the main service agreement's termination clause.

Check this in your own contract

Upload a PDF, Word file, or photo of your agreement and Lawly AI will pull out the clauses that matter, quote the exact wording, flag the deadlines, and explain the risk in plain English. Your first five documents are free.

Frequently asked questions

Is a DPA required if the data is already encrypted?

Yes. Encryption is a security measure, but a DPA covers legal rights, responsibilities, and instructions that apply regardless of the data's technical state.

What happens if there is no DPA in place?

Both parties may face regulatory fines, and the controller could be held fully liable for any breaches occurring at the processor's level.

Can a DPA be part of the main contract?

Yes, it is often included as an addendum or a specific 'Data Protection Clause' within the primary service agreement.

Does a DPA apply to employee data?

Yes, if a third party (like a payroll provider) processes employee data on behalf of an employer, a DPA is required.

Related guides

This guide is general educational information about how these clauses usually work. It is not legal advice, and contract law differs by jurisdiction. For a decision that matters, speak to a qualified lawyer.