DPA full form is Data Processing Agreement. Learn when GDPR Article 28 requires a DPA, what it must include, how it works with SCCs, and how to review a vendor DPA.
In data privacy, the full form of DPA is Data Processing Agreement. A DPA is a legally binding contract between a data controller and a data processor that sets out how the processor may handle personal data on the controller's behalf. Article 28 of the GDPR requires a DPA whenever a business uses a vendor, such as a cloud host, email platform or CRM, to process personal data for it. A DPA is also called a Data Processing Addendum when it is attached to a main service agreement.
DPA has several meanings. This page is about the Data Processing Agreement.
| Field | DPA full form |
|---|---|
| Data privacy contracts | Data Processing Agreement (or Addendum) |
| Data privacy regulators | Data Protection Authority, the national regulator that enforces the GDPR |
| UK law | Data Protection Act 2018 |
| US law | Durable Power of Attorney |
| Media | Deutsche Presse-Agentur, the German press agency |
A DPA exists because the GDPR splits responsibility between two roles:
Common examples of processors include email marketing tools, CRMs, cloud hosting and storage, customer support and chat tools, payroll and HR software, analytics providers, payment processors for some services, and consent management platforms.
You need a DPA whenever a processor handles personal data on your behalf. Under Article 28(3), that processing must be governed by a contract or another legal act that binds the processor to the controller.
You need a DPA when:
You usually do not need an Article 28 DPA when:
The DPA must be in writing, which includes electronic form (Article 28(9)). Many vendors offer a standard DPA that you accept online or that forms part of their terms of service.
Article 28(3) of the GDPR lists what a DPA must cover. It must describe:
It must also require the processor to:
Most DPAs also include:
If a processor, or one of its sub-processors, handles EU personal data outside the European Economic Area, the DPA must also cover the transfer. The most common tools are:
A DPA and SCCs are not the same thing. The DPA governs how the processor handles the data. The SCCs are an additional safeguard for transfers outside the EEA. Many vendors include both in one document.
The European Commission has also published standard contractual clauses between controllers and processors under Article 28(7) (Implementing Decision (EU) 2021/915), which organizations can use as a ready-made DPA for processing within the EEA.
| Law | Contract requirement |
|---|---|
| UK GDPR | Same Article 28 requirements as the EU GDPR. |
| California CCPA/CPRA | Contracts with service providers and contractors must limit how they use personal information and include specific terms. |
| Other US state privacy laws | Laws such as those in Virginia, Colorado, Connecticut and Texas require a contract between controller and processor setting out instructions, confidentiality, deletion and audit terms. |
| Brazil LGPD | Operators (processors) must follow the controller's instructions; contracts are the standard way to set these. |
| India DPDP Act | A data fiduciary may engage a data processor only under a valid contract. |
| China PIPL | Entrusted processing requires an agreement on purpose, duration, method, data types, protection measures and rights and obligations. |
Learn more about US state privacy laws, Brazil's LGPD, India's DPDP Act and China's PIPL.
Before you sign, check that the DPA:
Keep signed DPAs with your records of processing activities, so you can show regulators which vendors process which data.
When you use UniConsent to collect cookie consent, you are the controller and UniConsent acts as your processor for consent records. Our Data Processing Agreement sets out the Article 28 terms, and our list of sub-processors shows which providers help us deliver the service.
UniConsent is a Google-certified and IAB Europe-registered consent management platform. It helps you stay compliant on your websites and apps by:
In data privacy, DPA stands for Data Processing Agreement, the contract between a controller and a processor. It can also mean Data Protection Authority, the national privacy regulator, or the UK Data Protection Act 2018.
A DPA in the GDPR is the contract required by Article 28 between a controller and a processor. It sets out what personal data the processor handles, for what purpose, for how long, and the security and other obligations it must follow.
Yes. Under the GDPR, whenever a processor processes personal data on behalf of a controller, a contract meeting Article 28 must be in place. Processing without one can lead to fines for both parties.
Either party can. In practice, large vendors usually provide their own standard DPA, while larger customers may ask vendors to sign theirs. What matters is that it meets Article 28.
It must be in writing, which includes electronic form. Accepting a DPA online or as part of terms of service is common and valid, as long as it is binding on the processor.
A DPA is a Data Processing Agreement, a contract with a vendor. A DPO is a Data Protection Officer, the person who advises on and monitors data protection compliance inside an organization.
No. A DPA governs how a processor handles personal data. Standard Contractual Clauses are an additional safeguard for transferring data outside the EEA. Many vendors combine both in one document.
Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up