Data Management Policies open on a desktop.

What is a Data Processing Agreement (DPA)?

Learn how a DPA helps protect and build trust by defining data handling responsibilities and ensuring compliance with privacy regulations.

Einstein standing in front of screen that reads Navigate Compliance with Salesforce Trusted Services.

Stay ahead of AI regulations and maintain customer trust with the Regulations Whitepaper.

Salesforce mascot Astro standing on a tree log while presenting a slide.

Stay up to date on all things security and privacy.

Sign up for our monthly newsletter to get the latest research, industry insights, and product news delivered straight to your inbox.

Astro standing in front of screen that reads Secure Your AI Enterprise.

Hear from 4,000 IT professionals on improving data quality and building secure AI capabilities.

Data Processing Agreement FAQ

A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor. It outlines the obligations and responsibilities of each party regarding the processing of personal data, ensuring that the processor handles data in compliance with data protection laws like GDPR.

A data controller is an organization that determines the purpose and means of processing personal data. A data processor is a third party that processes that data on behalf of the controller. For example, a company is a controller, and its cloud service provider is a processor.

The purpose of a DPA is to ensure that a data processor handles personal data in a way that is compliant with data protection laws. It legally obligates the processor to follow the controller’s instructions and to implement appropriate security measures to protect the data.

A DPA is important for data controllers because it helps them fulfill their legal obligations under regulations like GDPR. It holds the data processor accountable for protecting personal data, providing the controller with legal protection and ensuring that they are taking appropriate measures to secure the data.

A DPA protects a company from liability by defining the legal roles and responsibilities of both the controller and the processor. This clarifies that the processor must comply with the controller’s instructions and data protection laws, which can help a company mitigate legal and financial risks in the event of a data breach.

A DPA typically includes key elements such as the duration and nature of the processing, the type of personal data involved, and the obligations of both the controller and the processor. It also outlines security measures the processor must take and the procedures for handling data breaches.