What is a Data Processing Agreement?

A data processing agreement, or DPA, is a legally binding contract between a data controller and a data processor that defines how personal data will be handled, protected, and used on the controller's behalf.

Under GDPR, any time an organization (the controller) hands personal data to a third party (a processor, like a cloud host, analytics vendor, or SaaS tool) to process on its behalf, a DPA is required by Article 28 - it isn't optional paperwork, it's a legal precondition for that processing to be lawful. The DPA specifies the scope and purpose of processing, security obligations, sub-processor rules, breach notification timelines, and what happens to the data when the relationship ends. DPAs are the mechanism that makes a vendor a tracked "subprocessor" in a company's own compliance register - every new vendor that touches personal data needs a signed DPA before that data flows to them, not after. This is also why international transfers matter alongside DPAs: if the processor is outside the EEA, the DPA needs to reference a valid transfer mechanism like Standard Contractual Clauses. A DPA doesn't replace security practices - it obligates them contractually, but the processor still has to actually implement encryption, access controls, and breach response to meet what the DPA requires.

In practice with Neotask

Every subprocessor Neotask sends personal data to - email providers, LLM vendors, cloud infrastructure - has a signed DPA tracked in the compliance DPA tracker before any tenant data is permitted to flow to it, and adding a new vendor requires that DPA to be in place in the same change that enables the integration.

Related terms

Start free

Plans

Free

$0/mo

Download without a card and start for free.

Individual

$50/mo

The full personal agent platform for one person.

Enterprise

$200/mo

Multiple workspaces and capacity for larger teams.

Continue