The Data Processing Agreement (DPA) is a contract between a data controller and a data processor. It legally regulates the processing of personal data carried out on behalf of the data controller, in accordance with Article 28 of the General Data Protection Regulation (GDPR).
This document defines:
the nature and purpose of the processing,
the types of data processed,
the obligations and rights of the data controller,
the guarantees provided by the data processor regarding security and confidentiality,
the conditions for further subcontracting, assistance, breach notification, and data return or deletion.