• AUG Certified badgeAUG (Authorized User Group) Certified
  • IND Recognised SponsorIND Recognised Sponsor
  • Nasscom Certified badgeNasscom Certified
  • SNA Certified badgeSNA Certified
  • AUG Certified badgeAUG (Authorized User Group) Certified
  • IND Recognised SponsorIND Recognised Sponsor
  • Nasscom Certified badgeNasscom Certified
  • SNA Certified badgeSNA Certified
  • 4.9 stars on G2
European Directives & Compliance

What Is a Data Processing Agreement (DPA)?

European Directives & Compliance 4 min read Updated Jun 2026

A Data Processing Agreement (DPA) is a legally required contract under GDPR between a data controller (the company that decides why and how personal data is processed) and a data processor (a third party that processes that data on the controller's behalf). It sets out each party's obligations for keeping personal data secure and compliant.

Quick Fact

A DPA is not optional paperwork; GDPR Article 28 requires one whenever a company shares personal data with a third-party processor, such as a payroll provider or an EOR, and processing without one is itself a compliance violation.

Data Processing Agreement at a Glance

AttributeDescription
Legal BasisArticle 28, GDPR
Required BetweenData controllers and data processors
Key ContentsScope of processing, security measures, sub-processor rules, breach notification duties
Common Use CasesPayroll providers, HR software, EOR relationships, cloud storage vendors
Missing a DPAConsidered a GDPR violation, exposing both parties to Tier 1 fines
Best ForAny relationship involving a third party processing personal data

Why Does It Matter?

Any time a company hands employee or customer data to a third party for processing, whether a payroll platform, a background-check vendor, or an Employer of Record, GDPR requires a signed DPA governing that relationship. Without one, both the controller and the processor are exposed to regulatory penalties, and the controller retains liability for how its data is handled even after handing it off.

When Is It Used?

A DPA is relevant whenever a company:

  • Engages a third-party payroll provider, HR platform, or Employer of Record to process employee data.
  • Shares candidate or customer personal data with an external vendor for any processing purpose.
  • Needs to confirm how a processor will handle data breaches, audits, and sub-processor relationships.
Example

A US company hires employees in Italy through an Employer of Record. Before any employee data is shared, the company (as data controller) and the EOR (as data processor) sign a DPA specifying how payroll and HR data will be processed, stored, and protected, and outlining the EOR's obligations if it needs to engage its own sub-processors.

Common Misconceptions

“A general services contract covers data protection requirements.”

No. GDPR requires a specific DPA with defined content, a standard commercial contract does not satisfy this requirement on its own.

“Only large companies need a DPA.”

No. Any company sharing personal data with a third-party processor needs one, regardless of company size.

“The processor bears all liability once a DPA is signed.”

No. The data controller retains responsibility for ensuring the processor handles data compliantly, even with a DPA in place.

“A DPA is a one-time document that never needs updating.”

No. DPAs should be reviewed when processing activities, sub-processors, or data transfer arrangements change.

Bottom Line

A Data Processing Agreement is a mandatory GDPR contract that governs how a third party handles personal data on a company's behalf, covering security, breach notification, and sub-processor rules. Any company using external payroll, HR, or EOR services needs a properly executed DPA in place before sharing employee data.

Sharing employee data with vendors?

We'll put a compliant Article 28 DPA in place before any employee data changes hands.

Book a demo