Seegnals

Definition

Data processing agreement (DPA)

The GDPR-required contract between a data controller and its processor, setting out what the processor may do with the data.

A data processing agreement is the contract Article 28 of the GDPR requires whenever a controller has personal data processed by another organisation. It binds the processor to act only on the controller’s documented instructions, to keep the data confidential and secure, to help the controller with data-subject requests and breaches, to use sub-processors only with permission, and to delete or return the data at the end of the service. It also states where the data is processed and on what terms it may leave the EEA.

It matters for outbound because a prospect list is personal data, and the tool you upload it to is a processor. Without a DPA, the processing has no proper contractual basis, and that is a gap an auditor, a client or a supervisory authority will notice. In practice the DPA is also the document that answers the questions a careful buyer asks about their tooling: which sub-processors touch the data, in which countries, and what happens when the contract ends. Signing one is not a formality to be skipped because the vendor is small.

Seegnals provides a DPA on request. The customer is the data controller, the application is hosted in Germany and the database in Ireland, and there is no transfer outside the EEA for core processing.