Glossary · Term

Data processing agreement (DPA) explained

A data processing agreement is the contract the GDPR requires whenever an external service provider processes personal data on your behalf.

At a glance
Meaning
Contract with a processor under the GDPR
Legal basis
Article 28 GDPR
When it is needed
A provider processes personal data on your behalf
Relation to NIS2
Part of managing service providers
Updated
June 2026
Editorial team
Compliance Compass

What is a data processing agreement?

A Data processing agreement (DPA) lays down in binding form how a service provider – a cloud, IT or payroll provider, for example – may handle the personal data it processes on behalf of an organisation. Unlike most of the terms in this cluster, it is a contractual instrument from data protection law: it is mandatory under Article 28 of the GDPR and, because the GDPR is a regulation, that duty applies directly and identically in every Member State. You remain the controller and stay responsible for the data; the provider acts only on your instructions. Without a valid agreement, passing the data to that provider is unlawful – however securely it works in technical terms.

What the agreement has to cover

For example: An organisation introduces a cloud-based applicant management tool. Because the vendor stores the names, CVs and contact details of applicants, it processes personal data on behalf of the organisation. Before the software goes live, the two sides sign a data processing agreement that records the storage locations (EU hosting), the technical and organisational measures and a deletion period once the recruitment procedure is closed. Only then is the tool compliant with data protection law.

The agreement and supply chain security

The data processing agreement is a classic tool for managing service providers. It complements what NIS2 requires under the heading of Supply chain security, by writing security requirements for partners down in a binding and enforceable form. A single contract thereby turns into a concrete lever for steering the Third-party risk of one particular service provider.

Thinking GDPR and NIS2 together

The agreement comes from data protection law, while NIS2, which has applied since 18 October 2024, requires you to manage the whole Supply chain. The two reach you in different ways – the GDPR is a regulation and applies directly in every Member State, NIS2 is a directive that has to be transposed into national law first – but they interlock in practice: if you must sign an agreement anyway, you can anchor the reporting duties and security requirements that also cover the NIS2 expectations of service providers in the same document. Contracts are an effective lever for steering third-party risks on a firm legal footing.

Further reading: GDPR (EU) 2016/679, Article 28 (EUR-Lex)

Frequently asked questions

When do you need a data processing agreement?

You need a data processing agreement (DPA) whenever an external service provider processes personal data on behalf of your organisation and on its instructions – a cloud, IT or payroll provider, for example. You remain the controller and stay responsible for the data, while the provider acts only on your instructions. Without a valid DPA, passing the data to that provider is unlawful, however securely it works in technical terms.

What is the legal basis for a DPA?

The DPA rests on Article 28 of the GDPR. That provision lays down in binding terms what such a contract has to cover: among other things the subject matter, duration and purpose of the processing, the technical and organisational measures (TOMs), the duties in the event of a data breach and on deletion, rules on the use of sub-processors, and rights of inspection and audit. The GDPR is a regulation, so Article 28 applies directly and in the same wording in every Member State – no national transposing act stands in between.

What has the DPA to do with NIS2?

The DPA is a contractual lever for writing security requirements and reporting duties towards service providers down in a binding and enforceable way. It comes from data protection law, while NIS2, which has applied since 18 October 2024, requires you to manage the whole supply chain. The two instruments differ in how they reach you: the GDPR is a regulation and binds you directly, whereas NIS2 is a directive that binds you through the transposing law of your Member State. They interlock in practice: if you have to sign a DPA anyway, you can anchor the NIS2 security requirements in the same document and steer the third-party risk of that provider on a firm legal footing.

Data protection & supply chain

Secure providers by contract and in writing

Compliance Compass keeps contracts, technical and organisational measures and provider risks in view – GDPR and NIS2 from one place.