HIPAA & privacy

What is a data processing agreement (DPA)?

A data processing agreement (DPA) is a contract, required under GDPR Article 28, between a data controller and a data processor that processes personal data on the controller’s behalf. It sets out the scope, purpose, and duration of processing, the processor’s security obligations, its use of sub-processors, and how it assists the controller with data-subject rights and breach notification.

Controller vs processor

The controller decides why and how personal data is processed; the processor acts on the controller’s instructions. A DPA is the contract that governs that relationship whenever a processor handles personal data for a controller.

What a DPA must include

Article 28 requires terms covering the subject matter and duration, the nature and purpose of processing, the types of personal data and categories of data subject, security measures, sub-processor rules, assistance with data-subject requests and breaches, and deletion or return of data at the end.

When you need one

Any time a vendor processes personal data on your behalf (or you process it on a customer’s behalf), a DPA should be in place. It is the business-to-business contract that sits behind your public privacy notice.

FAQ

Is a DPA the same as a privacy policy?

No. A privacy policy is your public notice to individuals about how you handle their data. A DPA is a contract between two organizations (controller and processor).

Do US companies need DPAs?

If you process EU or UK personal data as a processor, or you use processors that do, then yes. GDPR obligations follow the data, not the company’s location.

Related

What is GDPR? → Do I need to comply with GDPR if I am a US company? → Vendor risk in Keel →

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free