Skip to content
GO BACK

Data processing agreement (DPA)

Last updated: 14/08/2026 Reviewed by: Access Financial Team

Data processing agreement (DPA)

is the mandatory contract (GDPR Article 28) between a controller and any processor handling personal data on its behalf — payroll bureaus, EORs, benefits platforms. It fixes instructions, security, sub-processing, breach notification, audit rights and end-of-service deletion.

Reading a vendor DPA quickly

  • Instructions and scope: processing only per documented instructions; purposes listed match the service.
  • Sub-processors: current list, notification of changes and objection mechanics — payroll chains always have sub-processors.
  • Transfers: mechanisms named (adequacy, SCCs) with country visibility.
  • Security and breach: concrete measures and notification clocks that let you meet your own 72-hour duty.
  • Exit: return or deletion with certification — the clause everyone needs and nobody tests until offboarding a vendor.

FAQ

Do we need a DPA with an EOR?

Yes for the processing the EOR performs on your instructions — and note the nuance: for its own employer obligations (payroll filings, social insurance) the EOR acts as controller in its own right. Good EOR contracts split the roles explicitly; missing DPAs are a standard vendor-audit finding.

Who signs DPAs in a group?

Each controller engaging the processor — practically solved by a group master DPA with accession for affiliates. The map of who controls which employees’ data (home employer vs host vs shared) should exist before the signature block is built.