What is Data Processing Agreement?
A written agreement for everyone who handles your customers' data on your behalf. Complicated name, simple idea: you decide, they promise to behave.
A data processing agreement (DPA — in Swedish, personuppgiftsbiträdesavtal or PUB-avtal) is an agreement between you and a supplier that processes personal data on your behalf. It sounds bureaucratic, but the idea is simple: when someone else handles your customers' or employees' data on your instruction, there should be a document setting out what they may and may not do.
In GDPR terms, you are the "data controller" — you decide why and how the data is used. The supplier that does the actual work, such as your email provider, accounting software, or web agency, is the "data processor". Think of yourself as the boss and the processor as a hired tradesperson who promises to follow your instructions.
The agreement covers things like: which data is processed, for what purpose, for how long, how it is protected, whether sub-processors may be used, and what happens if an incident occurs. It gives you control and a clear division of responsibility if something goes wrong.
Why is a data processing agreement important for your business?
Under GDPR, you are required to have DPAs with everyone who processes personal data on your behalf. Without them you are breaking the law, regardless of how good the supplier is. That can lead to fines and leave you liable if the supplier is careless.
Equally important: the agreement protects you. If your supplier causes a leak, it is written down who was responsible for what. Without an agreement, you risk carrying the full blame.
Data processing agreement in practice
Say you run a business and use a newsletter tool to email your customers. The tool stores your customers' names and email addresses — personal data. You need a DPA with that supplier.
Most serious cloud services offer a ready-made agreement you approve in the settings. Your job is to keep track of which services handle personal data and ensure an agreement exists for each. A simple list of your suppliers and their agreements keeps you ready the day someone asks.
Common questions about Data Processing Agreement
What is a data processing agreement?
It is an agreement under GDPR between you and a supplier that processes personal data on your behalf. The agreement sets out what the supplier may and may not do with the data, and how it must be protected.
When do you need a data processing agreement?
You need a DPA when an external party processes personal data on your behalf — for example cloud services, accounting firms, or newsletter tools. It is a legal requirement under GDPR.
What is the difference between data controller and data processor?
The data controller decides why and how the data is used, while the processor carries out the processing on the controller's instruction. Your business is usually the controller, and your suppliers are processors.
Related terms
Consent Mode
Google's standard for passing consent to its services. Consent Mode v2 has been required since March 2024.
GDPR
The EU's data protection regulation. Governs how businesses may process personal data. Break it and fines can reach millions.
DPA
Data Processing Agreement. Required when someone else processes personal data on your behalf — e.g. cloud providers.
DPF
EU-US Data Privacy Framework. The replacement for Privacy Shield. Allows data transfers to certified US companies.
DPIA
Data Protection Impact Assessment. A required impact assessment for high-risk processing under GDPR Article 35.
IMY
Sweden's data protection authority — the regulator for GDPR. Handles complaints and can issue fines.