Employment contracts
DPA — Data Processing Agreement
A DPA is a mandatory agreement under Article 28 GDPR whenever a controller transfers personal data to a processor (e.g. cloud services, marketing tool, accounting software). It defines the purpose, scope, duration of processing, security measures and data subject rights.
These templates are for illustrative purposes only. They are not legal advice — consult a lawyer before signing.
Contract preview
What the agreement covers
- Subject and purpose of personal data processing
- Categories of data subjects and personal data
- Controller's instructions and processor's obligations
- Technical and organisational security measures
- Engagement of sub-processors
- Deletion or return of data after termination of the agreement
Frequently asked questions
Always before transferring personal data to a processor. Without a signed DPA you are in breach of GDPR and risk a fine of up to EUR 10 million or 2% of global turnover.
