What Is a Data Processing Agreement (DPA) and When You Need One
A DPA is the contract GDPR requires between you and any vendor that processes personal data on your behalf. Here's when you need one, what it has to cover, and how to get one in place fast.
If your business uses an email platform, an analytics tool, a payment processor, or basically any third-party service that touches customer data, GDPR requires a specific kind of contract to be in place with that vendor: a Data Processing Agreement. It’s one of the more mechanical GDPR requirements, mostly a matter of checking a box exists, not a judgment call.
What a DPA actually is
Article 28 of GDPR requires that when a “controller” (you, deciding what data to collect and why) uses a “processor” (a vendor that processes that data on your instructions), there has to be a binding contract governing that relationship. That contract, the DPA, has to specify things like:
- The subject matter, duration, and purpose of the processing
- The types of personal data and categories of individuals involved
- The processor’s obligations to only process data on your documented instructions
- Confidentiality commitments for anyone handling the data
- Security measures the processor has in place
- What happens to the data when the relationship ends (deletion or return)
- Whether and how the processor can use sub-processors
When you need one
Basically any time a third party processes personal data on your behalf and under your instructions, rather than for their own independent purposes. Common examples: your email marketing platform, your analytics provider, your customer support/chat tool, your payment processor, your hosting provider, your consent management platform. If a vendor sees, stores, or processes personal data because you sent it to them for a defined purpose, you need a DPA with them.
When you probably don’t
If a third party processes data for their own purposes, independent of your instructions, they’re typically a separate controller, not your processor, and the relationship works differently (often still requiring some contractual terms, but not a DPA in the Article 28 sense). This distinction gets genuinely fact-specific, when in doubt, treat it as needing a DPA and let the vendor tell you if a different agreement applies.
CookieYes
Your consent management platform is itself a processor handling visitor data on your behalf, confirm it has a DPA available, the same as any other vendor. CookieYes provides one as part of its standard terms.
How to actually get one in place
The good news: you almost never have to draft a DPA from scratch. Most established vendors, especially anything built for a business audience, publish a standard DPA you can accept, either built into their terms of service or available on request. The practical steps:
- List your vendors that touch personal data (this overlaps directly with the data inventory step in our compliance checklist).
- Check each vendor’s site or terms for a published DPA. Search “[vendor name] DPA” or “[vendor name] data processing agreement”, most major SaaS platforms have one.
- If you can’t find one, ask. A vendor processing EU personal data without a DPA available on request is a signal worth taking seriously, not a small oversight.
- Keep a record of which DPAs are signed or accepted, as part of your accountability documentation.
The bottom line
A missing DPA is one of the more common, easily-fixed gaps we see. Unlike judgment calls around lawful basis or legitimate interest, this one is close to binary: either the paperwork exists or it doesn’t, and closing the gap is usually a matter of finding a link on a vendor’s site, not a legal negotiation.
This guide is educational and not legal advice. For your specific vendor relationships and DPA terms, consult a privacy attorney.