security
Glossary ↗Data Processing Agreement (DPA)
A data processing agreement is the contract that governs a vendor's handling of personal data on a customer's behalf. Under GDPR-style regimes the customer is the controller — they decide why and how the data is used — and the SaaS vendor is the processor, acting only on documented instructions. The DPA writes that relationship down: the categories of data and people involved, the purpose and duration, the security measures the processor maintains, the rules for engaging sub-processors, what happens on termination, and the processor's duty to assist with data-subject requests and breach notification. For SaaS teams the DPA is not only a legal artefact; it constrains the product. A commitment to delete data on termination has to be true of backups and analytics copies as well as the primary database. A sub-processor clause usually requires a published list and advance notice of changes, which means adding a new AI provider or logging vendor is a customer-facing event rather than a purely technical decision. Cross-border transfer terms determine which regions you may process in. And the assistance obligations imply that export and deletion for a single individual must actually be operable, not theoretically possible. Practically, most B2B deals now require a DPA before signature, so having a standard one available alongside the security documentation removes a common source of delay — and it is worth checking that what the DPA promises matches what the system does, because that gap is exactly what an audit finds.
Related terms