A data processing agreement (or data processing addendum or DPA) is a legally binding document that describes an arrangement between two organisations where one instructs the other to perform information operations on their behalf. An example of this is a controller giving instructions to a processor. A few more commonplace examples:

  • payroll — an employer instructing an outsourced service provider (like payroll administrator) to pay their employees on their behalf each month;
  • telecoms — an organisation instructing a telecommunications service provider to route calls, messages or data traffic through their network; or
  • pension funds — a pension fund instructing an administration company to administer member payments and beneficiary payouts on their behalf.

These relationships almost always entail a third party processing people’s personal data. For this reason, data protection laws generally have strict rules governing data processing agreements.

The most common form of these agreements would be found between a controller and a processor. There are less common examples, however, for instance, with sub-processing agreements where a processor appoints a sub-processor to do the work. Data protection laws also generally prescribe minimum requirements for inclusions in DPA’s which protect data subjects through a system of checks and balances between the controller and the processor (or processor and sub-processor). These rules are in place to make sure the controller meets its processing obligations even when getting help from a third-party processor.

If you are unsure about whether you need a data processing agreement or not, read on — because you probably do, and there could be dire consequences for not having one. They are required by law. It is part of managing data processing relationships.

Why is a data processing agreement important?

They are important because data protection laws generally require an agreement whenever:

  • a controller instructs a processor, or
  • a processor instructs a sub-processor;

to carry out a task involving personal data on their behalf. There are severe consequences for the instructing controller or processor if they fail to have one in place. We’ve written all about how they are required by law.

It is also important to understand data processing agreements (DPAs), whether you are the controller, processor or sub-processor, regardless of whether your organisation is the instructing organisation or not. DPAs affect your organisation no matter where it is in the data processing chain.

It just makes sense to have some paperwork in place to make sure that everyone is doing things properly. Especially where you’re sharing personal data that your data subjects have entrusted you with, with another party.

How we can help

So, whether you’re a controller, processor or sub-processor, we can help.

  • Know more about data processing agreements and get generic templates by joining a data protection programme.
  • Manage your data processing relationships with a bespoke data processing agreement template specifically for your organisation by asking Michalsons to draft one for you.
  • Conclude a data processing agreement with a counterparty by asking us to review it and help you negotiate it.
  • Gain insight into how you’re currently managing your data processing relationships by doing a complimentary online data processing relationship assessment.
  • Read more about contracts in a data protection context by reading the ICO guidance.

How do you benefit from a data processing agreement?

There are a number of benefits to having a DPA in place.

  • satisfy a legal requirement — data protection law generally requires a controller to have a DPA in place whenever they use a processor (and the same of a processor whenever they use a sub-processor);
  • avoid regulatory fines — you could receive fines from regulatory authorities if you don’t have one where you should;
  • protects all parties — it makes sure that each organisation in the processing chain operates in compliance with relevant data protection laws and holds up their end of the bargain to protect the interests of all parties;
  • minimal requirements — data protection laws generally prescribe minimal requirements for inclusion in DPA’s which protect data subjects through a system of checks and balances between the controller and the processor (or processor and sub-processor);
  • other people’s data processing agreements — others may present you with DPA’s that could be adequate, but you should make sure that they protect your organisation and are not simply for their benefit;
  • information security — you may not be doing enough to secure the personal data that you process or others process on your behalf, without the necessary undertakings to stick to certain information security requirements; and
  • incident response — you may struggle to respond to data breaches, leaks and other incidents quickly, comprehensively and effectively without the necessary paperwork to get help from your processors or sub-processors.

Not sure whether you are a controller or processor?

A controller often draws up a data processing agreement to make sure that a processor handles the controller’s data properly. This does not always have to be the case and there are benefits to a processor, or even a sub-processor, drawing up a DPA themselves. If you’re unsure whether you’re a controller or processor, please refer to our article on data protection responsibilities in your relationships.