A data processing agreement, or DPA, sets the terms under which one party processes personal data on behalf of another. It allocates instructions, safeguards, assistance duties and accountability between the controller or business and its processor or service provider.
What does a DPA usually address?
- Subject matter, duration and purpose of processing
- Types of personal data and data subjects
- Documented processing instructions
- Confidentiality and security measures
- Subprocessor appointment and oversight
- Incident, rights-request and audit support
- Return or deletion at the end of service
Why does it matter in outsourcing?
A BPO or software provider may access customer, employee, supplier or transaction data while performing the service. The DPA should reflect the actual workflow, systems, locations and subprocessors rather than relying only on broad contract language.
DPA vs. privacy policy
A privacy policy explains how an organization handles personal data to individuals or the public. A DPA is a contract between organizations governing processing responsibilities. One does not replace the other.
What should be checked before signature?
Map the data flows, roles, countries, retention periods, security controls and incident process. Confirm that the schedules, transfer mechanism and subprocessor list match the proposed service and applicable law.
What should be monitored after signature?
Review material service changes, new subprocessors, security incidents, audit findings, deletion requests and cross-border transfers. The operating record should link approvals and remediation to the current agreement version.

