What Is a Data Processing Agreement?
TL;DR
A data processing agreement, or DPA, is the contract GDPR Article 28 requires between a controller who decides why personal data is processed and a processor who handles it on instruction. It must set out the subject matter, duration, nature and purpose of the processing, and impose eight specific obligations on the processor.
What must a DPA contain?
Article 28(3) lists eight obligations the contract has to place on the processor. Four govern how the data is handled: process only on documented instructions from the controller, keep personnel with access under a duty of confidentiality, apply the security measures required by Article 32, and respect the conditions on engaging another processor. The other four are what the processor owes the controller: assistance with data subject rights requests, assistance with the obligations in Articles 32 to 36 covering security, breach notification and impact assessments, deletion or return of the data when the service ends, and the information needed to demonstrate compliance, including allowing audits.
Those eight are the floor rather than the whole document. A workable DPA also names the categories of data and of data subjects, sets out how international transfers are handled, and attaches the current list of sub-processors. What a definition cannot tell you is whether your specific arrangement is controller to processor at all, and that is a legal question rather than a drafting one.
Who signs which side of a DPA?
The controller is whoever decides the purposes and means of the processing. In an outreach programme that is the sender: you choose who to contact, what to say and why. The sending platform executes those decisions, so it acts as processor, which is why a vendor presents a DPA rather than negotiating one from scratch each time.
The line moves when a vendor starts making its own decisions. A platform that sources contacts and decides who should be approached is determining a purpose of its own for that activity, and joint controller or separate controller language appears precisely there. Reading which role a contract assigns for which activity is more informative than the title on the document.
Frequently asked questions
No. A privacy policy is a notice addressed to individuals about how their data is handled. A DPA is a contract between two organisations that allocates responsibility for the processing. Different audience, different legal function, and publishing one does nothing about the requirement for the other.