Skip to main content
Glossary /

Data Processing Agreement (DPA)

Definition

A Data Processing Agreement (DPA) is a contract required under GDPR (and similar regimes) between a data controller and a data processor, governing how personal data is processed, protected, and returned or destroyed at contract end.
  • A DPA is a GDPR-required contract between a data controller and a data processor.
  • It sets scope, data location, sub-processors, breach notification, audit rights and return-or-destroy at exit.
  • Missing or thin DPA leaves the controller in breach of Article 28 regardless of processor conduct.

A Data Processing Agreement (DPA) is a contract required under GDPR (and similar regimes) between a data controller and a data processor, governing how personal data is processed, protected, and returned or destroyed at contract end. Skip it and the controller inherits the processor's data-handling risk in full.

How a DPA works

A retailer signs with a marketing analytics vendor that will process customer purchase histories in the cloud. Before any data leaves the retailer, both parties execute a DPA setting the scope of processing (segmentation and reporting only), the location of data (EU-hosted), sub-processors named on a schedule with a right-to-object window, breach notification within 72 hours, audit rights, and a return-or-destroy rule at contract end.

Structurally the DPA maps to Article 28 of GDPR: purpose, duration, nature, type of data, categories of data subjects and the obligations of both parties. It is not optional. Regulators treat an absent or thin DPA as a controller-side compliance failure regardless of the processor's conduct.

Where a DPA appears in contracts

A DPA is either signed standalone alongside the commercial agreement, or attached as a schedule to the master service agreement. The commercial contract governs the service; the DPA governs the personal data flowing through it. Vendortell's own processor terms are published on the Vendortell DPA page. Where confidentiality of non-personal information also matters, the DPA sits alongside a confidentiality agreement.

Data Processing Agreement (DPA) FAQ

Who signs a DPA?

The controller and the processor. If a sub-processor is involved, the primary processor flows equivalent terms down to them.

Is a DPA required for every vendor?

Only for vendors that process personal data on the controller's behalf. Vendors that receive only anonymised or aggregated data do not require one.

What happens if there is no DPA?

The controller is in breach of Article 28 of GDPR and remains fully liable for any processor-side incident. Enforcement action and fines follow, independent of the processor's conduct.

Take the next step

See how Vendortell captures contract value.

Book a 45-minute demo and we will structure two of your contracts against your live transactional data - no set-up required.

Book a demo
No credit card required. Cancel anytime.