Glossary: Data Processing Agreement
A legal contract defining how a vendor may process personal data on behalf of a company.
A Data Processing Agreement (DPA) is a legal contract between a company and a vendor that defines how the vendor may process personal data on the company’s behalf, as required under regulations like GDPR. It sets out responsibilities, security obligations, and data handling terms.
Examples
A company signs a DPA with its analytics provider before sending it any user data.
A DPA specifies that a vendor must delete user data within a set period after a contract ends.
An enterprise customer requests a signed DPA as part of its vendor security review.
Related reading
Explore PII (Personally Identifiable Information), Server-side Tracking, and Data Collection.
FAQs
When is a DPA required?
Under GDPR, a controller must use a contract that meets Article 28 when a processor handles personal data on the controller’s behalf. Other laws and roles may impose different requirements; assess the actual processing relationship and applicable rules.
What does a DPA typically cover?
Data handling responsibilities, security measures, sub-processor terms, breach notification, and data deletion obligations.
Does signing a DPA alone make processing compliant?
No. A DPA documents responsibilities between parties, but compliance also depends on the lawful basis, notices, security, data minimization, retention, transfers, and the parties’ actual practices.
The data platform onchain apps
Get actionable analytics and attribution for crypto and DeFi.
Stay up to date with weekly product updates and the latest industry insights.
Platform