Data Processing Agreement (DPA)

A legally binding contract between a data controller and data processor that outlines how personal data will be processed, protected, and handled in compliance with privacy regulations.

Also known as: DPA

Why data processing agreement (DPA) matters

Under GDPR, you must have a DPA with every vendor that processes personal data on your behalf - including your analytics platform. The DPA defines each party's responsibilities, data security measures, and what happens during a data breach.

Without proper DPAs, you risk regulatory fines even if no actual data breach occurs. Most analytics vendors provide standard DPAs, but you should review them to ensure they meet your specific requirements.

The newsletter

Join our KISS newsletter

One short read a week on what actually moves revenue, in a free email. Read by 10,000+ operators and founders.

No spam. Unsubscribe in one click.

Common Mistakes

  • -Using analytics tools without a signed DPA - this is a GDPR violation
  • -Not reviewing the DPA terms to ensure they align with your privacy policy
  • -Assuming a vendor's standard DPA covers all your specific data processing activities

Pro Tips

  • +Maintain a register of all DPAs and review them annually
  • +Ensure DPAs cover data breach notification timelines (72 hours under GDPR)
  • +Check that sub-processor lists in DPAs are kept current as vendors change their infrastructure

Related Terms

KISSmetrics

Build your business intelligence layer for free.

Record the response as a property on the person and every report splits by it, so you can see what promoters do differently rather than watching a number move.