Whenever one organization processes personal data on behalf of another, the GDPR requires a contract between them — and that contract is the GDPR DPA, or Data Processing Agreement. Getting your DPAs right is a core, and often overlooked, part of compliance. This guide explains what a DPA is, when you need one, and exactly what it must contain.

For the wider context, see our complete GDPR guide.
What is a GDPR DPA?
A Data Processing Agreement is a legally binding contract between a controller (which decides why and how personal data is processed) and a processor (which processes the data on the controller’s instructions). Required by Article 28 of the GDPR, the DPA sets out each party’s responsibilities and ensures the processor handles personal data lawfully and securely. Without a compliant DPA in place, both parties are exposed to regulatory risk.
When do you need a DPA?
You need a DPA whenever you engage a third party to process personal data on your behalf — for example a cloud host, a payroll provider, an email marketing platform, or an IT support company. If you are the processor, your customers will expect you to sign one. In modern supply chains, most organizations are party to many DPAs, both as controller and as processor, which is why a reliable template is so useful.
What a GDPR DPA must include
Article 28 sets out the mandatory contents. A compliant DPA must specify:
- The subject matter, duration, nature, and purpose of the processing.
- The types of personal data and categories of data subjects.
- That the processor acts only on documented instructions from the controller.
- Confidentiality commitments for staff handling the data.
- Appropriate technical and organizational security measures.
- Rules on engaging sub-processors, including prior authorisation.
- Assistance to the controller with data subject rights and breach obligations.
- Deletion or return of data at the end of the contract.
- Support for audits and demonstrating compliance.
Controller and processor responsibilities
The DPA formalises a division of duties. The controller must give clear instructions and only use processors that provide sufficient guarantees. The processor must follow those instructions, secure the data, control its sub-processors, assist with rights requests and breaches, and support audits. Understanding which role you hold in each relationship — sometimes both — is essential to getting your DPAs right.
A compliant DPA, ready to use.
Our GDPR Toolkit includes a ready-to-use Data Processing Agreement template covering every Article 28 requirement — plus the wider privacy documentation you need, editable in Word.
Frequently asked questions
What is a GDPR DPA?
A Data Processing Agreement is a contract, required by Article 28 of the GDPR, between a controller and a processor that sets out how the processor may handle personal data on the controller’s behalf.
When is a DPA required?
Whenever a third party processes personal data on your behalf — such as cloud hosts, payroll, marketing platforms, or IT providers.
What must a GDPR DPA contain?
The Article 28 essentials: the scope and purpose of processing, processing only on instructions, confidentiality, security measures, sub-processor rules, assistance with rights and breaches, data deletion or return, and audit support.