Data processing agreement (DPA)

Data protection glossary · 1 minute read

The data processing agreement is the contract between a controller and its processor that is required under Art. 28 GDPR.

Mandatory content

The agreement must set out the subject matter and duration of the processing, its nature and purpose, the type of personal data and the categories of data subjects. It must also set out the obligations and rights of the controller, in particular:

  • processing only on documented instructions
  • confidentiality obligations for the persons involved
  • technical and organisational measures under Art. 32 GDPR
  • rules for sub-processors
  • assistance with data subject rights and data breaches
  • erasure or return of the data when the contract ends
  • rights to evidence and audits

Form and templates

The DPA must be concluded in writing, which includes electronic form. With Implementing Decision (EU) 2021/915, the European Commission has published standard contractual clauses for processing on behalf of a controller, which may be used but are not mandatory.

If a required DPA is missing, both parties are in breach of the GDPR. This can result in a fine.

Art. 28(3) GDPR
Sets out the minimum content of the agreement.
Art. 28(9) GDPR
Written form, which can also be met electronically.
Art. 28(7) GDPR
Basis for standard contractual clauses adopted by the European Commission.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.