Data Processing Agreement
A Data Processing Agreement, commonly abbreviated as DPA, is a legal contract between a data controller, the entity that determines why and how personal data is processed, and a data processor, the entity that processes that data on the controller's behalf, outlining how personal data will be handled, protected, and used in a manner consistent with applicable privacy laws. DPAs have become a standard requirement under regulations such as the EU's GDPR whenever personal data is shared with a third-party vendor or service provider. A typical DPA specifies the scope and purpose of data processing, the security measures the processor must maintain, how long data will be retained, what happens to the data at the end of the relationship, and the processor's obligations in the event of a data breach. It also often addresses whether and how the processor can engage sub-processors, and what cross-border data transfer safeguards apply if data will move between countries. For companies with international operations, DPAs are commonly required not just with external vendors but also internally between different entities within the same corporate group when personal data, such as employee records, moves between offices in different countries. Employers working with an Employer of Record or global payroll provider typically need a DPA in place to govern how employee data is shared and protected throughout that relationship.