Data processing agreement, the contract UK and EU GDPR make compulsory
A data processing agreement is the written contract UK and EU GDPR require whenever a controller has a processor handle personal data on its behalf. Article 28(3) sets out what it must contain — subject matter, duration, purpose, categories of data, security measures, sub-processing, deletion and audit rights — and none of it is optional. Also called DPA, Article 28 agreement.
What Article 28 requires
A DPA must be in writing, and must set out the subject matter and duration of the processing, its nature and purpose, the types of personal data and categories of data subject, and the controller's obligations and rights. It must then bind the processor to a specific set of duties: process only on documented instructions, ensure the confidentiality of staff, implement appropriate security measures, engage no sub-processor without authorisation, assist with data-subject rights and breach obligations, delete or return the data at the end, and make available the information needed to demonstrate compliance — including submitting to audits.
Terms that purport to remove any of these do not work. The obligations run from the regulation; a contract that contradicts it simply leaves the processor in breach of the regulation.
Where it fits in vendor risk
The DPA is the one artefact that tells you which vendors touch personal data at all, so it belongs in the register rather than in a legal folder nobody reads. Three fields earn their place: whether a DPA exists, which sub-processors it authorises, and what the deletion obligation says at exit.
That last one is where programmes tend to fail. Deletion is contracted, the vendor is offboarded, and nobody asks for confirmation — so the data stays. Verifying destruction is a discrete step with a discrete piece of evidence, and it is the step most often skipped; at RiskXchange it is a named part of NOVA's offboarding work for exactly that reason. International transfers are the other live question: a DPA is not a transfer mechanism, and moving data outside the UK or EEA needs its own basis.
Common questions
When do we need a data processing agreement?
What is the difference between a DPA and a controller-to-controller agreement?
Does a DPA cover international data transfers?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.