Free GDPR Data Processing Agreement (DPA) Template

A data processing agreement is the contract a controller must have with every processor handling personal data on its behalf. This free DPA template implements Article 28 of the GDPR in full, including Standard Contractual Clauses for international transfers.

What is a data processing agreement?

A DPA is a contract between a data controller and a data processor, made mandatory by Article 28(3) GDPR, setting out the subject matter, duration, nature and purpose of processing, the types of personal data, and the processor's obligations.

Controller, processor, or joint controller?

You are a controller when you decide the purposes and means of processing, a processor when you handle another party's personal data on their instructions, and a joint controller when two parties genuinely decide the purposes together (which needs an Article 26 arrangement instead).

Sub-processors and flow-down obligations

A processor needs authorisation to engage sub-processors, must flow down the same obligations by contract, publish a sub-processor list, give notice of changes, and remain liable to the controller. Include hosting, CDN, email, analytics, and AI vendors.

International transfers after Schrems II

Transfers outside the EEA or UK need a valid mechanism: EU–US Data Privacy Framework certification or the 2021 Standard Contractual Clauses with the UK Addendum, supported by a transfer impact assessment.

Breach notification timelines

Controllers must notify their supervisory authority within 72 hours of awareness; processors must notify the controller without undue delay, usually fixed at 24, 48, or 72 hours in the DPA.

Frequently asked questions

Is a data processing agreement legally required?

Yes. Article 28(3) GDPR requires a written contract, including in electronic form, between every controller and processor. Operating without one is a breach in itself.

Who signs the DPA — controller or processor?

Both. Vendors usually offer their standard DPA and enterprise customers often insist on their own; either way all Article 28 obligations must be present.

What is the difference between a DPA and an NDA?

An NDA protects confidential business information for the disclosing party; a DPA is statutory, governs personal data specifically, and exists to protect the individuals whose data is processed. Most vendor relationships need both.

Do I need a DPA with US vendors?

Yes, if they process EU or UK personal data on your behalf, together with a valid transfer mechanism such as the Data Privacy Framework or the Standard Contractual Clauses.

Does a DPA cover AI vendors and model training?

Only if you write it in: prohibit training on your personal data, cap prompt retention, and list AI sub-processors. DPAs drafted before 2023 rarely address this.

Get started on econtracts.ai →