Data processing agreement (DPA)

The binding contract that GDPR Article 28 requires between a controller and a processor, limiting processing to the controller's documented instructions and setting security duties.

Full guide: Data Security Roles: Owner, Custodian, Controller and Processor for CISSP

A data processing agreement is the contract, or other binding legal act, governing how a processor handles personal data for a controller. GDPR Article 28(3) requires one and sets out its content: the subject matter, duration, nature and purpose of the processing, the types of personal data and categories of data subjects, and processor obligations including processing only on documented instructions, confidentiality for the staff who handle the data, security measures under Article 32, conditions for using sub-processors, help with data subject requests, deletion or return of the data when the service ends, and cooperation with audits.

The agreement binds the data processor; it does not transfer the accountability of the data controller. A controller that outsources processing still answers for its lawfulness. Under Article 28(10), a processor that starts deciding the purposes and means of processing is treated as a controller for that processing. The acronym DPA is also used for a data protection authority and for statutes such as the UK Data Protection Act 2018, so context decides which is meant.

Exam relevance: a scenario is likely to describe personal data outsourced to a cloud or payroll provider and ask what must be in place, or who remains accountable. Candidates are expected to see that the contract constrains the processor while accountability stays with the controller.