DPA Full Form: Data Processing Agreement

DPA full form is Data Processing Agreement. Learn when GDPR Article 28 requires a DPA, what it must include, how it works with SCCs, and how to review a vendor DPA.

DPA Full Form: What Is a Data Processing Agreement?

In data privacy, the full form of DPA is Data Processing Agreement. A DPA is a legally binding contract between a data controller and a data processor that sets out how the processor may handle personal data on the controller's behalf. Article 28 of the GDPR requires a DPA whenever a business uses a vendor, such as a cloud host, email platform or CRM, to process personal data for it. A DPA is also called a Data Processing Addendum when it is attached to a main service agreement.

Other Meanings of DPA

DPA has several meanings. This page is about the Data Processing Agreement.

FieldDPA full form
Data privacy contractsData Processing Agreement (or Addendum)
Data privacy regulatorsData Protection Authority, the national regulator that enforces the GDPR
UK lawData Protection Act 2018
US lawDurable Power of Attorney
MediaDeutsche Presse-Agentur, the German press agency

Controllers and Processors

A DPA exists because the GDPR splits responsibility between two roles:

  • A controller decides why and how personal data is processed. A business collecting customer data on its website is a controller.
  • A processor processes personal data on behalf of the controller and only on its instructions. Vendors that store, send, analyse or host that data for the business are processors.
  • A sub-processor is a vendor the processor uses to help deliver its service, such as the cloud provider behind a SaaS tool.

Common examples of processors include email marketing tools, CRMs, cloud hosting and storage, customer support and chat tools, payroll and HR software, analytics providers, payment processors for some services, and consent management platforms.

When Do You Need a DPA?

You need a DPA whenever a processor handles personal data on your behalf. Under Article 28(3), that processing must be governed by a contract or another legal act that binds the processor to the controller.

You need a DPA when:

  • You use a SaaS tool that stores or processes customer, employee or website visitor data
  • You outsource IT support, hosting, payroll, marketing or customer service
  • Your processor uses sub-processors, which must be bound by the same obligations (Article 28(4))

You usually do not need an Article 28 DPA when:

  • The other party decides its own purposes for the data and is an independent controller. A data sharing agreement is often used instead.
  • Two organizations decide the purposes together as joint controllers. They need a joint controller arrangement under Article 26.
  • Only anonymous data is shared.
  • The data is processed by your own employees.

The DPA must be in writing, which includes electronic form (Article 28(9)). Many vendors offer a standard DPA that you accept online or that forms part of their terms of service.

What Must a DPA Include?

Article 28(3) of the GDPR lists what a DPA must cover. It must describe:

  • The subject matter and duration of the processing
  • The nature and purpose of the processing
  • The types of personal data processed
  • The categories of data subjects, such as customers, employees or website visitors
  • The obligations and rights of the controller

It must also require the processor to:

  1. Process personal data only on the controller's documented instructions, including for international transfers, and tell the controller if an instruction breaks data protection law.
  2. Ensure everyone authorised to process the data is bound by confidentiality.
  3. Take appropriate technical and organisational security measures under Article 32.
  4. Use sub-processors only with the controller's prior written authorisation, inform the controller of changes, and pass the same obligations on to them.
  5. Help the controller respond to data subject requests, such as access, deletion and correction.
  6. Help the controller with security, breach notification, data protection impact assessments and prior consultation with regulators (Articles 32 to 36).
  7. Delete or return all personal data at the end of the service, unless the law requires it to be kept.
  8. Provide all information needed to demonstrate compliance, and allow and contribute to audits and inspections.

Common additional clauses

Most DPAs also include:

  • An annex describing the technical and organisational measures (TOMs), such as encryption, access control and backups
  • A list of approved sub-processors and how changes are notified
  • Breach notification timelines, for example notifying the controller without undue delay and within a set number of hours
  • International transfer terms, usually the EU Standard Contractual Clauses (SCCs)
  • Liability, indemnity, governing law and how the DPA relates to the main contract

DPAs and International Data Transfers

If a processor, or one of its sub-processors, handles EU personal data outside the European Economic Area, the DPA must also cover the transfer. The most common tools are:

  • The EU Standard Contractual Clauses adopted in 2021, using the controller-to-processor or processor-to-processor module
  • The EU-US Data Privacy Framework, for US companies certified under it
  • The UK International Data Transfer Agreement or UK Addendum to the SCCs for transfers from the UK

A DPA and SCCs are not the same thing. The DPA governs how the processor handles the data. The SCCs are an additional safeguard for transfers outside the EEA. Many vendors include both in one document.

The European Commission has also published standard contractual clauses between controllers and processors under Article 28(7) (Implementing Decision (EU) 2021/915), which organizations can use as a ready-made DPA for processing within the EEA.

Why DPAs Matter

  • They are a legal requirement. Using a processor without a compliant contract breaches Article 28 and can lead to fines of up to €10 million or 2% of global annual turnover, and both controller and processor can be fined.
  • They protect personal data by setting clear security, confidentiality and deletion obligations.
  • They make incident response faster, because breach notification duties and contacts are agreed in advance.
  • They support accountability. Regulators and customers often ask to see DPAs during audits and procurement.
  • They make international transfers lawful when combined with SCCs or another transfer tool.

DPA Requirements Under Other Privacy Laws

LawContract requirement
UK GDPRSame Article 28 requirements as the EU GDPR.
California CCPA/CPRAContracts with service providers and contractors must limit how they use personal information and include specific terms.
Other US state privacy lawsLaws such as those in Virginia, Colorado, Connecticut and Texas require a contract between controller and processor setting out instructions, confidentiality, deletion and audit terms.
Brazil LGPDOperators (processors) must follow the controller's instructions; contracts are the standard way to set these.
India DPDP ActA data fiduciary may engage a data processor only under a valid contract.
China PIPLEntrusted processing requires an agreement on purpose, duration, method, data types, protection measures and rights and obligations.

Learn more about US state privacy laws, Brazil's LGPD, India's DPDP Act and China's PIPL.

How to Review a Vendor's DPA

Before you sign, check that the DPA:

  • Covers every Article 28(3) requirement listed above
  • Describes the data, data subjects and purposes that match how you actually use the service
  • Lists sub-processors and gives you notice and a right to object to new ones
  • Sets a breach notification timeline you can work with, given your own 72-hour deadline to notify regulators
  • Includes SCCs or another valid transfer tool if data leaves the EEA or UK
  • Explains how data is returned or deleted when the contract ends
  • Gives you audit rights, or accepts independent certifications such as ISO 27001 or SOC 2 reports

Keep signed DPAs with your records of processing activities, so you can show regulators which vendors process which data.

UniConsent's Data Processing Agreement

When you use UniConsent to collect cookie consent, you are the controller and UniConsent acts as your processor for consent records. Our Data Processing Agreement sets out the Article 28 terms, and our list of sub-processors shows which providers help us deliver the service.

UniConsent is a Google-certified and IAB Europe-registered consent management platform. It helps you stay compliant on your websites and apps by:

  • Collecting GDPR-compliant consent and blocking non-essential cookies until visitors agree
  • Keeping consent records as proof for audits
  • Scanning your site with a cookie scanner to list every cookie and tracker, which also shows which third-party vendors receive visitor data
  • Passing consent signals to vendors through Google Consent Mode v2 and IAB TCF v2.3

Frequently Asked Questions

What is the full form of DPA?

In data privacy, DPA stands for Data Processing Agreement, the contract between a controller and a processor. It can also mean Data Protection Authority, the national privacy regulator, or the UK Data Protection Act 2018.

What is a DPA in GDPR?

A DPA in the GDPR is the contract required by Article 28 between a controller and a processor. It sets out what personal data the processor handles, for what purpose, for how long, and the security and other obligations it must follow.

Is a DPA mandatory?

Yes. Under the GDPR, whenever a processor processes personal data on behalf of a controller, a contract meeting Article 28 must be in place. Processing without one can lead to fines for both parties.

Who prepares the DPA, the controller or the processor?

Either party can. In practice, large vendors usually provide their own standard DPA, while larger customers may ask vendors to sign theirs. What matters is that it meets Article 28.

Does a DPA need to be signed?

It must be in writing, which includes electronic form. Accepting a DPA online or as part of terms of service is common and valid, as long as it is binding on the processor.

What is the difference between a DPA and a DPO?

A DPA is a Data Processing Agreement, a contract with a vendor. A DPO is a Data Protection Officer, the person who advises on and monitors data protection compliance inside an organization.

Is a DPA the same as Standard Contractual Clauses?

No. A DPA governs how a processor handles personal data. Standard Contractual Clauses are an additional safeguard for transferring data outside the EEA. Many vendors combine both in one document.

Further Reading

UniConsent Consent Manager for GDPR Compliance

  • Cookies scan and disclosing
  • JavaScript tags blocking and cookies blocking
  • Google Consent Mode v2 support
  • Certified IAB CMP
  • One-tag Implementation
  • Multiple languages support
  • Easy self-serve solution
  • Learn more from GDPR Compliance Guide

Microsoft certified CMP - UniConsent CMPIAB certified CMP - UniConsent CMPIAB TCF V2 certified CMP - UniConsent CMPIAB TCF Canada certified consent manager - UniConsent CMPGoogle-certified CMP Gold tire - UniConsent CMPGoogle-certified CMP partner

Comply With Global Privacy Regulations

Trusted by 5000+ of global publishers and marketers
  • sej
  • football365
  • sharethrough
  • districtm
  • pf1
  • tower cast

Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc

Sign up