DPA
Data Processing Agreement — a contract between a company and a SaaS vendor that governs how the vendor handles personal data. Legally required under GDPR.
A DPA is a formal contract between a company (the "data controller") and a SaaS vendor (the "data processor") that specifies how the vendor is allowed to handle personal data belonging to the company's users or employees. Under GDPR (EU) and equivalent laws (CCPA, LGPD), this contract is legally required whenever a vendor processes personal data on your behalf.
A standard DPA covers: - **Scope**: what data is processed, why, by whom. - **Subprocessors**: which other companies the vendor uses (cloud, monitoring) and how customers are notified of changes. - **Data location**: which countries/regions data is stored in — critical for GDPR requiring EU data to stay in EU or adequately-protected regions. - **Security requirements**: encryption at rest and in transit, access controls, breach notification (72 hours under GDPR). - **Deletion**: how and when data is deleted at contract end. - **Audit rights**: whether and how the customer can audit vendor compliance.
Most SaaS vendors publish a standard DPA (as a downloadable PDF or click-through) customers can accept without negotiation. Enterprise customers with legal teams often negotiate custom DPAs with specific carve-outs.
If a vendor refuses to sign a DPA, or theirs is missing standard clauses, that's a red flag — either they don't understand compliance, or they don't want to commit to what a DPA requires.