[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-data-processing-agreement::en":3,"gloss-cluster-data-processing-agreement::en":26,"gloss-next-data-processing-agreement::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"data-processing-agreement","security","Data Processing Agreement (DPA)","A data processing agreement is the contract that governs a vendor's handling of personal data on a customer's behalf. Under GDPR-style regimes the customer is the controller — they decide why and how the data is used — and the SaaS vendor is the processor, acting only on documented instructions. The DPA writes that relationship down: the categories of data and people involved, the purpose and duration, the security measures the processor maintains, the rules for engaging sub-processors, what happens on termination, and the processor's duty to assist with data-subject requests and breach notification. For SaaS teams the DPA is not only a legal artefact; it constrains the product. A commitment to delete data on termination has to be true of backups and analytics copies as well as the primary database. A sub-processor clause usually requires a published list and advance notice of changes, which means adding a new AI provider or logging vendor is a customer-facing event rather than a purely technical decision. Cross-border transfer terms determine which regions you may process in. And the assistance obligations imply that export and deletion for a single individual must actually be operable, not theoretically possible. Practically, most B2B deals now require a DPA before signature, so having a standard one available alongside the security documentation removes a common source of delay — and it is worth checking that what the DPA promises matches what the system does, because that gap is exactly what an audit finds.","A DPA sets the controller-processor terms for handling personal data — and why its sub-processor, deletion and transfer clauses constrain the product itself.",null,[11,14,17,20,23],{"slug":12,"name":13},"data-residency","Data Residency",{"slug":15,"name":16},"data-subject-access-request","Data Subject Access Request (DSAR)",{"slug":18,"name":19},"gdpr","GDPR (General Data Protection Regulation)",{"slug":21,"name":22},"security-questionnaire","Security Questionnaire",{"slug":24,"name":25},"sub-processor","Sub-processor",[27,31,35,39,42,45,48,51,54,57,60,63],{"slug":28,"category":5,"name":29,"updated_at":30},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":32,"category":5,"name":33,"updated_at":34},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":36,"category":5,"name":37,"updated_at":38},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":40,"category":5,"name":41,"updated_at":38},"bridge-letter","Bridge Letter",{"slug":43,"category":5,"name":44,"updated_at":38},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":46,"category":5,"name":47,"updated_at":30},"byok","Bring Your Own Key (BYOK)",{"slug":49,"category":5,"name":50,"updated_at":38},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":52,"category":5,"name":53,"updated_at":34},"data-classification","Data Classification",{"slug":55,"category":5,"name":56,"updated_at":38},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":58,"category":5,"name":59,"updated_at":38},"data-minimization","Data Minimization",{"slug":61,"category":5,"name":62,"updated_at":38},"data-poisoning","Data Poisoning",{"slug":64,"category":5,"name":65,"updated_at":30},"data-retention","Data Retention Policy"]