Skip to content

What a Data Processing Agreement (DPA) must contain

By Sam Rivera, Founder, SentinelPanda · June 17, 2026 · 2 min read · Compliance

If a vendor handles personal data on your behalf, you owe a DPA. Here is what a defensible one actually contains.

Controller, processor, and why it matters

The controller decides why and how personal data is processed; the processor acts on the controller’s instructions. The moment a vendor processes personal data on your behalf — a payroll provider, an analytics tool, a support desk — GDPR Article 28 (and most modern privacy laws) require a written agreement governing that relationship. That agreement is the DPA.

The clauses that carry weight

  • Subject matter, duration, nature and purpose of processing, and the categories of data and data subjects.
  • A processing-on-documented-instructions clause — the processor acts only on the controller’s instructions.
  • Confidentiality obligations on everyone who touches the data.
  • Technical and organizational security measures (often an annex mirroring your ISO 27001 / SOC 2 controls).
  • Subprocessor terms: prior authorization, a current list, and flow-down of the same obligations.
  • Breach notification timelines and the assistance the processor owes the controller.
  • International transfer mechanism (e.g., Standard Contractual Clauses) where data leaves its origin region.
  • Deletion or return of data at the end of the engagement, and audit / inspection rights.

Where the DPA meets your other frameworks

The security-measures annex of a DPA is usually a restatement of controls you already maintain for SOC 2 or ISO 27001. The subprocessor list overlaps your vendor-management program. Treat the DPA as another consumer of the same evidence — not a separate universe of work.

Use a template, then get it reviewed

A good DPA template gives you every required clause and sensible defaults, so you are editing rather than drafting from scratch. It is a starting point only: jurisdiction, transfer mechanism, and liability terms must be reviewed by qualified counsel before you sign or send it.

Vendor risk management Cross-framework control mapping

Run your compliance program in one workspace.