Glossary
DPA (Data Processing Agreement)
A DPA (Data Processing Agreement) is the contract required by Article 28 of the GDPR between a controller and its processor. It sets the subject matter, duration, nature and purpose of the processing, the categories of data and data subjects, and the obligations on security, confidentiality, assistance and return or deletion of data.
The clauses GDPR makes mandatory
A compliant DPA provides at minimum that the processor: processes data only on documented instructions from the controller; ensures confidentiality of authorised personnel; implements the Article 32 security measures; respects the authorisation regime for sub-processors; assists the controller with data subject requests, breach notifications and impact assessments; deletes or returns the data at the end of the contract; and makes available the information needed for audits.
A signed DPA is not demonstrated compliance
The DPA is a contractual artefact, not proof of security. It states what the processor commits to, not what it does. A TPRM programme complements it with a technical assessment — questionnaire, certifications, evidence — and by linking the DPA to the relevant processing activity in the records, the only way to answer an auditor asking "on what contractual basis is this transfer made?".
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours