What is DPA?
Data Processing Agreement. Required when someone else processes personal data on your behalf — e.g. cloud providers.
DPA stands for Data Processing Agreement. It is an agreement you need in place as soon as someone else handles personal data for you. Imagine handing your customers' address list to an external party so they can do something with it — you want a written promise that they will look after the data properly. That promise is a DPA.
The most common situation is cloud services and suppliers. When you use an email tool, accounting software or cloud provider that stores your customer data, they are "processing" personal data on your behalf. GDPR then requires you to have a DPA that describes what they may do, how data must be protected and what happens if something goes wrong.
Without a DPA, both you and the supplier breach GDPR — even if the data handling itself is otherwise perfect.
Why does a DPA matter for your business?
A DPA is not just a formality — it is a legal requirement. If you lack agreements with your suppliers, you remain liable if something leaks, and you can face fines.
The agreement also gives you reassurance: it clarifies who is responsible for what, so you do not have to guess when it matters.
DPA in practice
An accounting firm using cloud-based bookkeeping software handles clients' personal data in that system. The firm then needs a DPA with the system supplier, setting out how the data may be processed and protected.
At ZORC we help you keep track of which suppliers require a DPA and build systems where data flows are clear and secure.
Common questions about DPA
What does DPA mean?
DPA stands for Data Processing Agreement. It is an agreement required when someone else handles personal data on your behalf, such as a cloud provider.
When do I need a DPA?
You need a DPA whenever an external party processes personal data for you, for example a cloud service, email tool or accounting program.
Is a DPA a legal requirement?
Yes, GDPR requires a DPA between you and anyone processing personal data on your behalf. Without it, both parties breach the rules.
Related terms
Consent Mode
Google's standard for passing consent to its services. Consent Mode v2 has been required since March 2024.
GDPR
The EU's data protection regulation. Governs how businesses may process personal data. Break it and fines can reach millions.
DPF
EU-US Data Privacy Framework. The replacement for Privacy Shield. Allows data transfers to certified US companies.
DPIA
Data Protection Impact Assessment. A required impact assessment for high-risk processing under GDPR Article 35.
IMY
Sweden's data protection authority — the regulator for GDPR. Handles complaints and can issue fines.
Data Processing Agreement
A written agreement for everyone who handles your customers' data on your behalf. Complicated name, simple idea: you decide, they promise to behave.