In GDPR, DPA is the Data Processing Agreement. Under Article 28 GDPR, a controller may only use a processor that provides sufficient guarantees, and the relationship must be governed by a written contract. That contract is the Data Processing Agreement, usually shortened to DPA.
Most organisations have DPAs in place. Fewer have DPAs that would survive scrutiny. The common failure points are predictable: sub-processor clauses that provide notice without any real objection window, audit rights replaced entirely by a vendor’s own certification, and security obligations described in a single sentence that references no actual measure.
This guide sets out the ten mandatory elements under Article 28(3), the clauses that most often fail on review, how a DPA interacts with international transfer mechanisms, and a template you can adapt.
Key Definitions
| Term | Definition |
|---|---|
| Data Processing Agreement (DPA) | The Article 28 GDPR contract between a controller and a processor |
| Controller | The entity determining the purposes and means of processing |
| Processor | The entity processing personal data on behalf of a controller |
| Sub-processor | A third party engaged by the processor to carry out processing |
| Article 28(3) | The provision listing the mandatory content of a DPA |
| SCCs | Standard Contractual Clauses. A transfer mechanism under Article 46 GDPR |
| IDTA | International Data Transfer Agreement. The UK equivalent transfer mechanism |
| TIA / TRA | Transfer Impact Assessment (EU) / Transfer Risk Assessment (UK) |
When You Need a DPA
A DPA is required whenever a third party processes personal data on your behalf and under your instructions. The test is not whether data is shared. It is whether the recipient determines the purposes of processing.
| Relationship | Instrument required |
|---|---|
| Controller to processor | DPA under Article 28 |
| Controller to controller | No DPA. Data sharing agreement if appropriate |
| Joint controllers | Article 26 arrangement, not a DPA |
| Processor to sub-processor | Back-to-back DPA imposing equivalent obligations |
| Employer to employee | None. Employees are not processors |
Common processor relationships include cloud hosting, payroll providers, CRM platforms, email marketing tools, customer support software, analytics vendors that do not use the data for their own purposes, and AI vendors processing your data under your instructions.
The AI vendor case is the one worth checking carefully. A vendor that uses your data to train its own models is not acting solely on your instructions. That is either a separate controller relationship requiring its own lawful basis, or a processor operating outside its mandate. Broad secondary-use permissions buried in a vendor’s standard DPA are the most common way this happens without anyone noticing.
The Ten Mandatory Elements
Article 28(3) requires every DPA to address the following.
| # | Requirement | Article |
|---|---|---|
| 1 | Subject matter, duration, nature and purpose of processing, data types, and categories of data subject | 28(3) opening |
| 2 | Processing only on documented controller instructions, including on transfers | 28(3)(a) |
| 3 | Confidentiality commitments from authorised personnel | 28(3)(b) |
| 4 | Article 32 security measures | 28(3)(c) |
| 5 | Sub-processor authorisation and equivalent obligations | 28(3)(d), 28(2), 28(4) |
| 6 | Assistance with data subject rights requests | 28(3)(e) |
| 7 | Assistance with Articles 32 to 36 obligations | 28(3)(f) |
| 8 | Deletion or return of data at end of service | 28(3)(g) |
| 9 | Information provision and audit rights | 28(3)(h) |
| 10 | Notification where an instruction appears unlawful | 28(3), final paragraph |
A DPA missing any of these is non-compliant regardless of how comprehensive it looks.
Where DPAs Usually Fail
Sub-processor clauses with no real objection right
General authorisation is permitted under Article 28(2), but it requires the processor to inform the controller of intended changes and give the controller an opportunity to object. A clause providing 10 days’ notice with the change taking effect regardless of objection is not an objection right. It is a notification.
Workable drafting gives at least 30 days’ notice, a defined objection process, and a consequence if the objection stands, usually a right to terminate the affected service without penalty.
Audit rights replaced by self-certification
Article 28(3)(h) contains two distinct obligations: make available all information necessary to demonstrate compliance, and allow and contribute to audits. A clause that offers only an annual SOC 2 report satisfies neither in full.
Reasonable limitations are acceptable: advance notice, business hours, once per year absent a breach, cost allocation. A total substitution of third-party certification for any audit right is not.
Security described but not specified
“The processor shall implement appropriate technical and organisational measures” restates the statute without committing to anything. Article 32 measures should be set out in a schedule: encryption at rest and in transit, access control model, logging, backup and restoration, personnel vetting, and testing cadence.
This matters commercially as well as legally. When a breach occurs, the security schedule is the document that determines whether the processor met its obligations.
Deletion obligations without evidence
Article 28(3)(g) requires deletion or return at the end of service. The clause should specify which of the two applies, the format for return, the deadline, the treatment of backups, and whether written confirmation of deletion is provided.
DPAs and International Transfers
A DPA governs the processing relationship. It does not authorise a transfer to a third country. Where the processor is outside the EEA or UK without an adequacy decision, a separate transfer mechanism is required.
| Processor location | Instruments required |
|---|---|
| EEA | DPA only |
| UK (from an EU controller) | DPA only, adequacy renewed to 27 December 2031 |
| Adequacy country | DPA only |
| Non-adequacy country (EU controller) | DPA plus SCCs plus TIA |
| Non-adequacy country (UK controller) | DPA plus IDTA or UK Addendum plus TRA |
Where SCCs are used, Module Two contains Article 28 content in its own right. Running a separate DPA alongside SCCs is common but creates a risk of inconsistency. Where the two conflict, the SCCs prevail. Draft the DPA to complement rather than duplicate them.
Data Processing Agreement Template
The template below covers the Article 28(3) requirements. Square brackets indicate content to be completed. Schedules 1 and 2 carry most of the operational weight and should not be left generic.
DATA PROCESSING AGREEMENT
This Data Processing Agreement (“Agreement”) is entered into between:
[Controller name], a company registered in [jurisdiction] under number [number], with registered office at [address] (“Controller”); and
[Processor name], a company registered in [jurisdiction] under number [number], with registered office at [address] (“Processor”).
1. Definitions
1.1 “Data Protection Law” means Regulation (EU) 2016/679, the UK GDPR, the Data Protection Act 2018, and any other applicable data protection legislation, in each case as amended.
1.2 “Personal Data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in Data Protection Law.
1.3 “Services” means the services described in [the Main Agreement / Schedule 1].
1.4 “Sub-processor” means any processor engaged by the Processor to process Personal Data on behalf of the Controller.
2. Scope and Roles
2.1 The Controller is the controller and the Processor is the processor in respect of the Personal Data described in Schedule 1.
2.2 The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of data subject are set out in Schedule 1.
3. Processor Obligations
3.1 The Processor shall process Personal Data only on documented instructions from the Controller, including in relation to transfers of Personal Data to a third country, unless required to do so by law to which the Processor is subject. Where such a legal requirement applies, the Processor shall inform the Controller before processing unless that law prohibits such notification on important grounds of public interest.
3.2 The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes Data Protection Law.
3.3 The Processor shall ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.4 The Processor shall implement and maintain the technical and organisational measures set out in Schedule 2, which shall meet the requirements of Article 32 of the GDPR.
3.5 The Processor shall not process Personal Data for its own purposes, including the training, development, or improvement of any model, product, or service, without the prior written authorisation of the Controller.
4. Sub-processors
4.1 The Controller grants the Processor general authorisation to engage the Sub-processors listed in Schedule 3.
4.2 The Processor shall give the Controller at least [30] days’ written notice before adding or replacing a Sub-processor.
4.3 The Controller may object to a proposed Sub-processor on reasonable data protection grounds within [15] days of notice. Where an objection is not resolved, the Controller may terminate the affected Services without penalty.
4.4 The Processor shall impose on each Sub-processor, by written contract, data protection obligations equivalent to those in this Agreement. The Processor remains fully liable to the Controller for the performance of each Sub-processor’s obligations.
5. Assistance
5.1 Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures in fulfilling the Controller’s obligation to respond to requests for exercising data subject rights.
5.2 The Processor shall notify the Controller without undue delay and in any event within [24] hours of becoming aware of a personal data breach affecting Personal Data, providing the information required to enable the Controller to meet its obligations under Articles 33 and 34 of the GDPR.
5.3 The Processor shall assist the Controller in ensuring compliance with Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the Processor.
5.4 The Processor shall notify the Controller without undue delay of any request received from a supervisory authority or law enforcement agency relating to the Personal Data, unless prohibited by law.
6. International Transfers
6.1 The Processor shall not transfer Personal Data outside [the EEA / the United Kingdom] without the Controller’s prior written authorisation.
6.2 Where a transfer is authorised, the parties shall enter into [the Standard Contractual Clauses / the International Data Transfer Agreement], which are incorporated into this Agreement. In the event of conflict between those clauses and this Agreement, those clauses prevail.
7. Audit and Information
7.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with Article 28 of the GDPR.
7.2 The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. Audits shall be conducted on [30] days’ notice, during business hours, no more than once per year, save where the Controller has reasonable grounds to suspect a breach of this Agreement or a personal data breach has occurred.
7.3 The Processor may satisfy paragraph 7.1 in part by providing a current independent third-party audit report, but this does not displace the Controller’s rights under paragraph 7.2.
8. Deletion and Return
8.1 On termination or expiry of the Services, the Processor shall, at the Controller’s election, delete or return all Personal Data and delete existing copies, within [30] days of the Controller’s instruction.
8.2 Paragraph 8.1 does not apply to the extent that Union or member state law requires continued storage, in which case the Processor shall inform the Controller of that requirement and shall continue to protect the Personal Data in accordance with this Agreement.
8.3 The Processor shall provide written confirmation of deletion on request.
8.4 Backup copies shall be deleted in accordance with the Processor’s documented backup cycle, which shall not exceed [90] days, and shall remain subject to this Agreement until deleted.
9. Liability and Term
9.1 This Agreement takes effect on [date] and continues for the duration of the Services.
9.2 Clauses 3.3, 7, and 8 survive termination.
9.3 This Agreement is governed by the law of [jurisdiction].
SCHEDULE 1: PROCESSING DETAILS
| Item | Detail |
|---|---|
| Subject matter | [e.g. provision of hosted CRM services] |
| Duration | [Term of the Main Agreement plus deletion period] |
| Nature and purpose | [e.g. storage, retrieval, and display of customer records] |
| Types of Personal Data | [e.g. name, business email, job title, correspondence history] |
| Special category data | [None / specify] |
| Categories of data subject | [e.g. Controller’s employees, customers, prospects] |
| Frequency of processing | [Continuous / periodic] |
SCHEDULE 2: TECHNICAL AND ORGANISATIONAL MEASURES
| Measure | Implementation |
|---|---|
| Encryption in transit | [e.g. TLS 1.3] |
| Encryption at rest | [e.g. AES-256] |
| Access control | [Role-based access, least privilege, MFA on administrative access] |
| Authentication | [Specify] |
| Logging and monitoring | [Access logs retained for [x] months, alerting on anomalous access] |
| Backup and restoration | [Frequency, retention, tested restoration cadence] |
| Personnel | [Background checks, confidentiality undertakings, annual data protection training] |
| Physical security | [Data centre certifications and controls] |
| Testing | [Penetration testing frequency, vulnerability scanning cadence] |
| Incident response | [Documented plan, escalation path, notification timeline] |
| Certifications | [ISO 27001 / SOC 2 / other, with scope] |
SCHEDULE 3: APPROVED SUB-PROCESSORS
| Sub-processor | Service provided | Location |
|---|---|---|
| [Name] | [e.g. cloud hosting] | [Country] |
What This Template Does Not Do
It covers Article 28(3). It does not cover the transfer mechanism itself, which requires SCCs, the IDTA, or the UK Addendum as a separate instrument. It does not address sector-specific requirements in financial services, health, or telecoms. It does not address DORA’s Article 30 contractual requirements for financial entities, which go considerably further than Article 28 on audit rights, exit assistance, and service levels.
Schedules 1 and 2 are where most templates are weakest. A Schedule 2 that lists measure categories without specifying implementations gives you nothing to point to when a supervisory authority asks what was actually in place.
FAQ
What does DPA stand for in GDPR?
DPA (Data Processing Agreement) is the Article 28 contract between controller and processor. In UK usage it can also mean the Data Protection Act 2018, and in EU usage it can mean Data Protection Authority. Context determines which.
Can we use the vendor’s standard DPA?
Often yes, after review against the Article 28(3) checklist. The clauses to examine closely are sub-processor objection rights, audit rights, secondary use permissions, and the security schedule. Vendor templates are drafted to protect the vendor, which is expected rather than sinister.
Does a DPA need to be a separate document?
No. Article 28(9) requires writing, including electronic form. In GDPR, DPA can be a schedule to a master services agreement or incorporated into terms of service, provided the mandatory content is present and applies to the processing.
Who is liable if the processor breaches?
The controller remains liable to data subjects. The processor has direct liability under Articles 28 and 32 and can be fined in its own right. A processor acting outside the controller’s instructions becomes a controller for that processing under Article 28(10). Contractual allocation between the parties is a separate matter from regulatory liability.
What are the penalties for not having a DPA?
Article 28 infringements fall in the lower tier: up to €10 million or 2% of worldwide annual turnover under EU GDPR, £8.7 million or 2% under UK GDPR. In practice, missing DPAs tend to surface as an aggravating factor during a breach investigation rather than as a standalone enforcement action.
Do we need a DPA with an AI vendor?
If the vendor processes personal data on your instructions, yes. Check whether the vendor’s terms permit use of your data for model training. If they do, the vendor is not acting solely as your processor for that activity, and you need to assess the lawful basis and transparency position for it separately.
How often should DPAs be reviewed
Annually, and on any change to the services, the sub-processor list, the data categories, or the processor’s location. The DUAA amendments to UK GDPR in February 2026 did not change Article 28 requirements, so existing DPAs remain valid on that point.
Legal Disclaimer
This guide reflects Regulation (EU) 2016/679 and the UK GDPR as at August 2026. The template is a starting point for adaptation, not a finished contract for any specific relationship. It is published by European Compliance Suite for general informational purposes and does not constitute legal advice.
