A data processing agreement sets the terms under which a service provider processes customer data: permitted purposes, security obligations, subprocessor disclosure and approval, data location, retention periods, deletion rights, and breach notification timelines.
For AI vendors it is also where no-training commitments and zero-retention terms belong.
Alternative Names:
DPA, Data Protection Agreement
Why it Matters?
The data processing agreement is the document that determines whether a firm can honestly represent to clients how their information is handled. Marketing pages and privacy policies can change unilaterally, while the agreement binds. The provisions most worth negotiating are subprocessor disclosure with a right to object, deletion on termination with a defined timeline, and breach notification measured in hours rather than days.
Frequently Confused with
Related terms
Frequently asked questions
What should a legal buyer negotiate in a DPA?
Is a privacy policy an adequate substitute?





