What Is a Data Processing Agreement (DPA)?
A Data Processing Agreement (DPA) is a legally required contract under GDPR between a data controller (the company that decides why and how personal data is processed) and a data processor (a third party that processes that data on the controller's behalf). It sets out each party's obligations for keeping personal data secure and compliant.
A DPA is not optional paperwork; GDPR Article 28 requires one whenever a company shares personal data with a third-party processor, such as a payroll provider or an EOR, and processing without one is itself a compliance violation.
Data Processing Agreement at a Glance
| Attribute | Description |
|---|---|
| Legal Basis | Article 28, GDPR |
| Required Between | Data controllers and data processors |
| Key Contents | Scope of processing, security measures, sub-processor rules, breach notification duties |
| Common Use Cases | Payroll providers, HR software, EOR relationships, cloud storage vendors |
| Missing a DPA | Considered a GDPR violation, exposing both parties to Tier 1 fines |
| Best For | Any relationship involving a third party processing personal data |
Why Does It Matter?
Any time a company hands employee or customer data to a third party for processing, whether a payroll platform, a background-check vendor, or an Employer of Record, GDPR requires a signed DPA governing that relationship. Without one, both the controller and the processor are exposed to regulatory penalties, and the controller retains liability for how its data is handled even after handing it off.
When Is It Used?
A DPA is relevant whenever a company:
- Engages a third-party payroll provider, HR platform, or Employer of Record to process employee data.
- Shares candidate or customer personal data with an external vendor for any processing purpose.
- Needs to confirm how a processor will handle data breaches, audits, and sub-processor relationships.
A US company hires employees in Italy through an Employer of Record. Before any employee data is shared, the company (as data controller) and the EOR (as data processor) sign a DPA specifying how payroll and HR data will be processed, stored, and protected, and outlining the EOR's obligations if it needs to engage its own sub-processors.
Common Misconceptions
No. GDPR requires a specific DPA with defined content, a standard commercial contract does not satisfy this requirement on its own.
No. Any company sharing personal data with a third-party processor needs one, regardless of company size.
No. The data controller retains responsibility for ensuring the processor handles data compliantly, even with a DPA in place.
No. DPAs should be reviewed when processing activities, sub-processors, or data transfer arrangements change.
A Data Processing Agreement is a mandatory GDPR contract that governs how a third party handles personal data on a company's behalf, covering security, breach notification, and sub-processor rules. Any company using external payroll, HR, or EOR services needs a properly executed DPA in place before sharing employee data.
Sharing employee data with vendors?
We'll put a compliant Article 28 DPA in place before any employee data changes hands.
AUG (Authorized User Group) Certified
IND Recognised Sponsor
Nasscom Certified
SNA Certified
Nasscom Certified