Data Processing Agreement

Data Processing Agreement

Data Processing Agreement

A data processing agreement sets the terms under which a service provider processes customer data: permitted purposes, security obligations, subprocessor disclosure and approval, data location, retention periods, deletion rights, and breach notification timelines.

For AI vendors it is also where no-training commitments and zero-retention terms belong.

Alternative Names:

DPA, Data Protection Agreement

Why it Matters?

The data processing agreement is the document that determines whether a firm can honestly represent to clients how their information is handled. Marketing pages and privacy policies can change unilaterally, while the agreement binds. The provisions most worth negotiating are subprocessor disclosure with a right to object, deletion on termination with a defined timeline, and breach notification measured in hours rather than days.

Frequently Confused with

Related terms

Frequently asked questions

What should a legal buyer negotiate in a DPA?

What should a legal buyer negotiate in a DPA?

Subprocessor disclosure with a right to object, deletion on termination with a defined timeline, breach notification within a short window, and for AI vendors an explicit no-training commitment.

Is a privacy policy an adequate substitute?

Is a privacy policy an adequate substitute?

No. Privacy policies can be changed unilaterally by the vendor. The data processing agreement is a negotiated contract that binds.