Legal Glossary Term
Understanding Data Processing Agreements (DPAs)
A Data Processing Agreement (DPA) is a contract between a controller and processor that documents how personal data will be handled under GDPR Article 28.
A Data Processing Agreement (DPA) is a legally binding contract that governs how a data processor handles personal data on behalf of a data controller. This agreement is a cornerstone of data protection law, particularly the GDPR. It exists to ensure that a processor acts only on the controller's documented instructions and maintains a high standard of data protection.