Data processing agreement (DPA)
A data processing agreement (DPA), also called a data processing addendum or processor agreement, is the contract or other legal act required by Art. 28(3) GDPR whenever a controller entrusts processing of personal data to a processor. It must be in writing, including electronic form, and is binding on the processor. The same term is used, confusingly, for the data protection authority; context usually makes the meaning clear.
Art. 28(3) prescribes the minimum content. The DPA must set out the subject matter and duration of processing, its nature and purpose, the type of personal data and categories of data subjects, and the obligations and rights of the controller. It must stipulate that the processor: processes only on documented instructions, including for international transfers, and informs the controller if an instruction infringes the law; ensures that persons authorised to process the data are bound by confidentiality; takes all Art. 32 security measures; engages sub-processors only under the conditions of Art. 28(2) and (4); assists the controller in responding to data subject requests; assists with security, breach notification, DPIAs and prior consultation; deletes or returns all data at the end of the services, unless Union or Member State law requires storage; and makes available all information necessary to demonstrate compliance, allowing and contributing to audits and inspections. The European Commission adopted standard contractual clauses for controller-processor relationships (Decision 2021/915) that may be used verbatim, and Modules 2 and 3 of the transfer SCCs also satisfy Art. 28.
In life sciences, DPAs are concluded with CROs, EDC, eCOA and IRT vendors, central laboratories, safety database and medical information providers, cloud hosts and consultants. Sector-specific points include: retention instructions that reflect the 25-year CTR archiving rule and prevent premature deletion; treatment of unblinded data; interaction with GCP audit rights; breach notification within 24 to 48 hours; and clear allocation of roles where the vendor also processes data for its own purposes. iliomad reviews and negotiates DPAs against an Art. 28 checklist; see contractual review services.
