Key takeaways

  • What are DPAs: Data processing agreements (DPAs) define how controllers and processors handle personal data, including security, confidentiality, and each party's role.
  • When a DPA is needed: Companies need a DPA when a third-party provider processes personal data on their behalf.
  • Why DPAs are important: DPAs help companies set expectations for the data processing relationship.
  • Compliance considerations: Global companies need to consider privacy laws, including GDPR requirements, when managing relationships with third-party service providers that process personal data

As your company expands into new markets, you'll likely work with a growing number of third-party providers that support your operations. These relationships involve access to personal data, so it's important to understand:

    • who can access that information
    • how third parties process it
    • what protections are in place to safeguard it

A data processing agreement (DPA) helps establish expectations between data controllers and processors. This legal and binding contract outlines how the parties handle personal data, including the scope of processing, security measures, and duties each party must follow.

While many associate DPAs with the EU's General Data Protection Regulation (GDPR), other privacy laws around the world can include similar requirements for protecting and managing personal data. Understanding when you need a DPA can help your company build stronger data protection strategies and support your privacy obligations in the regions where you operate. In this guide, you'll learn what a DPA is, what it involves, when you need one, and more.

What is a data processing agreement?

A DPA is a legal contract between data controllers and data processors that sets out how personal data will be handled. It explains each party's responsibilities, including:

  • The types of personal data the processor can access: a DPA identifies the information involved in the processing relationship and specifies how the processor can use it.
  • The security measures the processor has to follow: Agreements can detail requirements for protecting data, such as confidentiality practices, access controls, and other safeguards.
  • The duties of both parties: A DPA establishes clear expectations for each party throughout the processing relationship, including those related to security, confidentiality, and compliance.

Companies use DPAs when working with third-party providers that process personal data on their behalf, support various business operations, and need access to personal information. Examples include:

  • HR technology: HR platforms process information related to team members, candidates, and workforce management activities.
  • Email management outsourcing: Email service providers can process contact information and communications.
  • Financial accounting: Accounting platforms and providers can access financial records, employee information, and other business data while supporting financial operations.
  • Data collection or digitization: External providers can help collect, organize, or convert data into more accessible digital formats.
  • Cloud storage: Cloud providers can store personal data and business backups on behalf of companies and need to follow agreed-upon security requirements to protect that information.
  • Payroll support: Payroll providers process sensitive tax and compensation information needed to support payment and employee-related activities.
  • Customer relationship management (CRM) platforms: CRM providers can process customer information to support sales, service, and communication.

A DPA creates a shared understanding of how processing activities will occur. It can identify the scope of the relationship, establish security requirements, and clarify how each organization should approach its privacy obligations.

Why are DPAs important?

A DPA helps companies better understand how parties share data and set out accountability for protecting it. By establishing responsibilities before a controller/processor relationship begins, companies build a stronger foundation for managing privacy requirements and reducing uncertainty. 

A DPA can help businesses operate more efficiently as they expand across borders by creating consistent expectations for how third parties handle personal data. Rather than replacing a company's broader privacy policy and compliance duties, a DPA is one part of a broader approach to protecting personal data.

How GDPR affects data processing agreements

The EU’s GDPR places greater emphasis on DPAs by establishing specific requirements for agreements between data controllers and data processors. Under Article 28 of the GDPR, controllers have to work with processors that give sufficient guarantees for protecting data and need to set up contracts that address responsibilities for both parties.

These requirements apply when the GDPR covers processing activities. While GDPR originated in the EU, it can also apply to scenarios where companies outside the EU process personal data of individuals within the region.

Data processing agreements on the global stage

GDPR is among the most widely recognized data privacy frameworks in the world. Companies can need to consider similar contractual commitments when working with third-party providers that process personal data, even when they're not operating within the EU. Privacy laws vary among countries, and an organization's obligations depend on:

    • where it operates
    • whose data it processes
    • what services it provides

Knowing when your company needs a DPA can help you create clearer processes for protecting personal data and support your privacy requirements no matter where you operate.

When is a data processing agreement needed?

DPAs are necessary whenever one organization processes personal data on behalf of another. Under GDPR, companies need a DPA when sharing personal data creates a controller-processor relationship. In these situations, the agreement helps define:

    • how a provider can use the information
    • what protections apply
    • how both parties should approach the arrangement.

Some common examples of when companies need a DPA include using:

    • a payroll provider
    • an HR platform
    • cloud storage
    • other technology vendor that can process employee, customer, or business data

The DPA sets out clear expectations before processing begins.

When is a data processing agreement not needed 

Not every relationship involving personal data needs a DPA. Common scenarios include:

  • Independent controllers: Independent third parties can determine how and why they process personal data. This means they operate under their own privacy responsibilities rather than acting as processors.
  • Professional service providers: Certain providers, including those that offer legal, accounting, and financial advisory services, have separate confidentiality and privacy responsibilities based on the nature of their businesses.
  • Limited data access relationships: A provider can access data incidentally without processing it on behalf of another organization.
  • Public authorities and regulatory bodies: Companies that process data under their own legal authority can’t operate as processors and don't need a DPA.

When determining whether you need a DPA, consider:

    • who determines the purpose of processing
    • who accesses the information
    • what role each organization plays in the relationship

Understanding the roles in a data processing agreement

In a DPA, two parties play distinct roles: the data controller and the data processor. Understanding the difference between them can help you determine each party's duties when personal data moves between two companies.

What is a data controller?

A data controller is an organization that determines why and how data is processed. It's the party that decides:

    • what information it collects
    • why it's collecting it
    • how the processor can use the data on its behalf

Say your company acts as a data controller when it collects personal information from customers, team members, or other parties to support business activities. If you work with a third-party provider to process that information, your company determines why the provider processes it.

What is a data processor?

A processor is the organization that processes personal data on the controller's behalf. It doesn't determine the purpose of processing or how the data will be used beyond the controller's instructions. It has to follow the controller's specific instructions for processing.

A data processor can include: 

    • technology providers
    • cloud service companies
    • payroll platforms
    • other vendors that process personal data when delivering a service

Their work involves following explicit processing instructions while keeping appropriate safeguards.

What does a data processing agreement include?

A DPA clearly defines how companies handle personal data when a controller works with a processor. Exact details can vary based on applicable privacy laws. Most DPAs address key areas related to data processing activities, security measures, and party responsibilities.

1. Details about data processing activities

DPAs help both parties understand what information is part of the agreement and how processors can use it. The agreement explains the scope of the processing relationship and specifies what the processor can do with the data involved.

Details include:

    • The types of personal data subject to processing
    • The categories of individuals whose information is processed
    • The purpose and nature of processing activities
    • The overall duration of the processing relationship
    • Clear instructions for how the processor can use the data
    • Requirements for returning or deleting personal data after the relationship ends.

Documenting these details helps companies establish expectations before any processing begins. Parties can use the details as a reference point throughout the relationship.

2. Rights, responsibilities, and processing instructions

Agreements need to outline what each party has to do when processing personal data. Controllers provide instructions that processors need to follow. Processors have to carry out agreed-upon processing activities. A DPA needs to specify that the controller, not the processor, retains control over the data and what happens to it.

DPAs can address: 

    • The controller's instructions for how the processor has to use data
    • The processor's responsibilities when performing processing activities
    • The controller's right to get information about activities
    • Each party's duties related to privacy, security, and compliance

When prepared correctly, a DPA can help both parties understand their respective obligations and avoid confusion.

3. Confidentiality and security

Provisions concerning confidentiality and security measures can set expectations for safeguarding personal data. A DPA has to specify what measures a processor will use.

Depending on the services involved, relevant measures can include:

    • Implementing confidentiality agreements for individuals who access the data
    • Strict access controls that limit who can view the information
    • Data encryption and pseudonymization practices
    • Processes supporting data availability, resilience, and recovery
    • Routine reviews and security testing

The specific measures included in a DPA should reflect the type of information involved and the risk associated with processing activities.

4. Requirements for subprocessors

Some processors work with other providers to support their services. Known as subprocessors, these companies can need to follow additional requirements. A DPA needs to include instructions for managing these relationships and cover any extra rules that apply when another organization processes personal data.

Subprocessor provisions cover:

    • Whether processors need authorization before engaging with subprocessors
    • Obligations that apply to subprocessors when they process data
    • How processors monitor subprocessor compliance
    • How processors communicate changes involving subprocessors

Clear requirements for subprocessors give controllers more visibility into how personal data moves across a broader network of service providers.

Support for privacy and compliance obligations

Finally, a DPA needs to explain how a processor can support a controller's privacy responsibilities. Processor activities that focus on support could include:

    • Assisting with data protection impact assessments 
    • Supporting responses to data subject requests
    • Providing information needed for compliance reviews and audits
    • Assisting with breach response
    • Keeping records about processing activities whenever applicable

Defining these details early can help companies respond faster and more effectively should privacy or security concerns arise.

What happens after a data breach under a DPA?

If a personal data breach is likely to pose a risk to the rights and freedoms of affected individuals, the companies involved need to take specific, immediate actions. Companies have to notify the relevant supervisory authority within 72 hours of becoming aware of the breach.

If the breach poses a high risk, companies have to notify those individuals as well. If the company already has effective technical and organizational risk reduction protocols in place, a notification isn’t necessary.

Say a company uses a third-party provider to store customer information. If the provider (processor) experiences a security incident that exposes personal data, the provider needs to notify the company (controller) so that the organization can evaluate the breach and determine the appropriate next steps. 

Depending on the circumstances, the company needs to notify regulators, affected individuals, or both. The response can depend on factors such as the:

    • information involved
    • number of people affected
    • protections already in place

What are the risks of not meeting DPA requirements?

  1. When privacy laws require companies to have a data processing agreement, failing to set up one can create compliance risks. Under GDPR, controllers and processors can face penalties if they don’t meet data protection obligations, including requirements related to controller-processor agreements.
  2. If a data breach occurs and regulators find an organization was noncompliant, they can take enforcement actions. Potential actions can include:
      • A formal warning or reprimand
      • Temporary or permanent restrictions on data processing activities
      • Administrative fines of up to EUR 20 million or 4% of the company's total annual worldwide turnover, whichever is higher
  3. The specific consequences depend on the nature of the violation, the impact on affected individuals, and the organization's response. Either way, noncompliance can create operational and reputational challenges.

Managing DPAs across multiple vendors, jurisdictions, and internal teams can create additional administrative challenges for growing companies.

Without clear oversight, many struggle to identify gaps in their data protection practices and respond quickly when privacy issues arise.

Establishing a structured approach to data processing agreements can help businesses improve visibility, stay consistent, and support responsible growth across borders.

Build global teams with G-P

When you’re building international teams, data privacy is an important consideration. Work with G-P to support your cross-border employment needs. Our Global Employment Platform helps companies hire, onboard, manage and pay professionals worldwide while working through employment requirements. 

Having the right processes and expertise in place can help your organization manage data privacy considerations as you grow. As a global EOR, G-P helps you hire and pay talent in 180+ countries without setting up local entities. We take data privacy seriously, helping businesses like yours support international employment processes and manage local labor requirements.

At G-P, we help you streamline your hiring processes by combining technology with human expertise. Using our Global Employment Platform, you can hire and onboard your new team members more efficiently, saving time and simplifying your approach to growth.

Request a proposal today, or contact us to learn how G-P can support your global hiring strategy.

Frequently asked questions

When is a DPA not required for global companies?

A DPA isn’t needed when a third party doesn’t process personal data on a company’s behalf.  Independent controllers, certain professional service providers, and companies that access data under their own legal authority can have separate privacy responsibilities. The need for a DPA depends on each party's role and how they handle the data.

Controller vs processor: how do you tell which you are?

The difference between the two roles comes down to who determines how and why the data is processed. Controllers decide the purpose of processing and how it's used, while processors handle data on the controller's behalf while following their instructions.

What is a Data Processing Agreement (DPA)?

A data processing agreement is a contract between a data controller and a data processor that defines how the parties will handle personal data. It outlines the scope of the processing, covers security measures, and defines each party's role in the relationship

When is a DPA required for global companies?

Companies need a DPA when they share data with a third party that processes it on their behalf, establishing a controller-processor relationship. Agreement specifics will depend on applicable privacy laws, the companies involved, and the nature of the data processing.