TPRM glossary

Data processing agreement, the contract UK and EU GDPR make compulsory

A data processing agreement is the written contract UK and EU GDPR require whenever a controller has a processor handle personal data on its behalf. Article 28(3) sets out what it must contain — subject matter, duration, purpose, categories of data, security measures, sub-processing, deletion and audit rights — and none of it is optional. Also called DPA, Article 28 agreement.

What Article 28 requires

A DPA must be in writing, and must set out the subject matter and duration of the processing, its nature and purpose, the types of personal data and categories of data subject, and the controller's obligations and rights. It must then bind the processor to a specific set of duties: process only on documented instructions, ensure the confidentiality of staff, implement appropriate security measures, engage no sub-processor without authorisation, assist with data-subject rights and breach obligations, delete or return the data at the end, and make available the information needed to demonstrate compliance — including submitting to audits.

Terms that purport to remove any of these do not work. The obligations run from the regulation; a contract that contradicts it simply leaves the processor in breach of the regulation.

Where it fits in vendor risk

The DPA is the one artefact that tells you which vendors touch personal data at all, so it belongs in the register rather than in a legal folder nobody reads. Three fields earn their place: whether a DPA exists, which sub-processors it authorises, and what the deletion obligation says at exit.

That last one is where programmes tend to fail. Deletion is contracted, the vendor is offboarded, and nobody asks for confirmation — so the data stays. Verifying destruction is a discrete step with a discrete piece of evidence, and it is the step most often skipped; at RiskXchange it is a named part of NOVA's offboarding work for exactly that reason. International transfers are the other live question: a DPA is not a transfer mechanism, and moving data outside the UK or EEA needs its own basis.

Common questions

When do we need a data processing agreement?
Whenever a third party processes personal data on your behalf — hosting, support tooling, analytics, payroll, a marketing platform. It is required by UK and EU GDPR Article 28 and is not limited to vendors who obviously "hold data": a support tool whose staff can view customer records is a processor.
What is the difference between a DPA and a controller-to-controller agreement?
A DPA governs a controller and a processor, where the processor acts only on the controller’s instructions. Where both parties decide their own purposes for the same data, they are separate or joint controllers, and Article 28 does not apply — joint controllers instead need an arrangement under Article 26 setting out who does what.
Does a DPA cover international data transfers?
No. A DPA is required regardless of where processing happens; transferring personal data outside the UK or EEA needs its own lawful basis, such as an adequacy decision or standard contractual clauses with a transfer risk assessment. The two are usually executed together, which is why they are often mistaken for one document.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.