DPA

Data processing agreement

A DPA is the contract framing the processing of personal data entrusted by a controller to a processor: it sets out what the processor is allowed to do, and nothing else.

What Article 28 requires it to contain

The GDPR does not leave the content to the parties. The contract must state the subject matter and duration of the processing, its nature and purpose, the type of data and the categories of data subjects, the obligation to act only on documented instructions, confidentiality, security measures, what happens to the data when the contract ends, and the regime for sub-processors.

Who is who

On a website, the publisher is the controller: they decide to measure their audience, and why. The measurement tool is the processor: it processes on the publisher’s behalf. Reversing those roles is the most reliable warning sign — a tool that reserves the right to exploit your data for its own purposes is no longer a processor, and your DPA no longer covers what it does.

Sub-processors

A serious DPA names its sub-processors — hosting provider, email service, payment provider — and where they are. That is what lets you know where your data actually sits, and check that none of it leaves the European Union without your knowing.