Data Processing Agreement
aka DPA, Article 28 contract, Data Processing Addendum
Mandatory contract under GDPR Article 28 between a data controller and a data processor. Sets out subject matter, duration, processing purposes, and required security measures.
Last reviewed April 2026
Definition
A Data Processing Agreement (DPA) is the contract required under Article 28 of the GDPR between a data controller (the Irish SME) and any processor that handles personal data on the controller's behalf (most SaaS providers). The contract must cover the subject matter and duration of processing, the nature and purpose of processing, the categories of personal data and data subjects, the controller's obligations and rights, and a defined list of processor obligations: confidentiality, security measures (Article 32), use of sub-processors only with prior authorisation, assistance with data subject rights, breach notification, return or deletion of data on termination, and audit rights. A processor that engages a sub-processor (e.g. AWS, GCP, Azure, Twilio) must impose the same data protection obligations on it via a back-to-back contract. Under Irish and EU practice, the DPA is usually signed by accepting the SaaS provider's standard terms or by countersigning a downloadable PDF. A DPA is separate from the main service contract but typically cross-references it. Without an Article 28 DPA in place, the use of any third-party processor for personal data is a GDPR breach by the controller.
Why it matters for software choice
If a vendor cannot produce a current GDPR-compliant DPA on request, the Irish SME using them is technically in breach of GDPR Article 28. Software that publishes a click-through DPA on its website, names sub-processors transparently, and notifies of sub-processor changes is materially easier to defend in a DPC inquiry.
Authority sources
- GDPR Article 28: Processor (gdpr-info.eu)
- DPC: Contracts (www.dataprotection.ie)
Software categories this affects
Vendors covered by this term
HiBob
Modern HR platform designed for mid-size companies with strong culture and engagement tools
BambooHR
Intuitive HR platform for Irish SMEs who need hiring, onboarding, and people management
Mailchimp
The world's most widely used email marketing platform, with a generous free tier for small lists
HubSpot CRM
Free CRM with marketing automation, widely adopted by Irish tech and services firms
Salesforce
Enterprise CRM with EU data centres and a strong Irish partner ecosystem
Klaviyo
Ecommerce-focused email and SMS marketing with deep Shopify and WooCommerce integration
Related terms
Data Protection Commission
Ireland's national data protection authority. Lead supervisory authority for many large US tech companies headquartered in Dublin under the GDPR's one-stop-shop mechanism.
Standard Contractual Clauses
Pre-approved contractual templates issued by the European Commission for transferring personal data outside the EEA. The default fallback when no adequacy decision applies.
Data Residency (EU vs US)
Where customer personal data is stored and processed. Storing inside the EU/EEA simplifies GDPR compliance; processing in the US triggers transfer-mechanism obligations under Schrems II.