Glossary

Data Processing Agreement (DPA)

A data processing agreement (DPA) is the contract between a data controller (your customer, typically) and a data processor (you, or your vendors) that governs how personal data is handled: what processing is permitted, what security measures apply, how breaches are notified, and what happens to the data when the contract ends. Under GDPR Article 28, it’s mandatory whenever a processor handles personal data on a controller’s behalf.

When you’ll be asked for one

The moment a European customer’s legal team reviews your contract — and increasingly from US customers too, as state privacy laws adopt similar requirements. SaaS companies typically publish a standard DPA and incorporate it by reference into their terms, rather than negotiating each one individually.

What a reviewer checks

The sub-processor list and update mechanism, international transfer safeguards (standard contractual clauses, usually), breach notification timelines, deletion commitments, and audit rights. A DPA that contradicts your actual architecture — claiming EU-only storage while your logs sit in a US region — is a finding waiting to be discovered, which is why the DPA belongs in compliance review scope, not just legal’s.

DPA vs BAA

A DPA covers personal data under privacy law; a business associate agreement covers protected health information under HIPAA. Health-tech companies selling into both markets commonly need both, and they are not interchangeable.

Related Terms

Business Associate Agreement — A BAA is the HIPAA-required contract between covered entities and vendors handling PHI — what it must contain and why missing BAAs trigger enforcement.

Sub-processor — A sub-processor is any third party your company uses to process customer personal data — your cloud host, email provider, analytics. You must disclose them.