What is a data processing agreement (DPA)?

Short answer

A data processing agreement, or DPA, is a contract between a business and a supplier that handles personal data for it. Under the GDPR it sets out what the supplier may do with the data, how it keeps it safe and what happens to it when the service ends.

Also called: DPA, data processing addendum, GDPR Article 28 agreement.

By Updated

What a DPA covers

  • What data is processed, about whom, for what purpose and for how long.
  • That the supplier only acts on your instructions and keeps the data confidential.
  • The security measures the supplier has in place.
  • Which other companies (subprocessors) the supplier uses, and how you are told about changes.
  • Help with people's requests to see or delete their data, and deleting or returning the data at the end.

When you need one

Article 28 of the GDPR requires a written contract whenever a processor handles personal data on your behalf. A chatbot that stores your customers' names, emails and conversations is a processor, and so are your email tool, your CRM and your booking system.

In GDPR terms, your business is the controller and the supplier is the processor. Many suppliers publish a standard DPA you can accept or sign. This is general information, not legal advice, so check the details with your own adviser.

The SimplyBoost DPA

SimplyBoost's data processing agreement is at /dpa. SimplyBoost is hosted in Europe, and the company is registered in the Netherlands and based in Utrecht.

Questions people ask

Is a DPA required under the GDPR?

Yes, when a supplier processes personal data for you. Article 28 of the GDPR requires a contract with specific terms, and a DPA is that contract.

Who signs a DPA?

Your business, as the controller, and the supplier, as the processor. Some suppliers include it in their terms; others have you sign a separate document.

Where can I find SimplyBoost's DPA?

On the data processing agreement page at /dpa.

More on privacy and security