Data processing agreement (DPA)
is the mandatory contract (GDPR Article 28) between a controller and any processor handling personal data on its behalf — payroll bureaus, EORs, benefits platforms. It fixes instructions, security, sub-processing, breach notification, audit rights and end-of-service deletion.
Reading a vendor DPA quickly
- Instructions and scope: processing only per documented instructions; purposes listed match the service.
- Sub-processors: current list, notification of changes and objection mechanics — payroll chains always have sub-processors.
- Transfers: mechanisms named (adequacy, SCCs) with country visibility.
- Security and breach: concrete measures and notification clocks that let you meet your own 72-hour duty.
- Exit: return or deletion with certification — the clause everyone needs and nobody tests until offboarding a vendor.
FAQ
Do we need a DPA with an EOR?
Yes for the processing the EOR performs on your instructions — and note the nuance: for its own employer obligations (payroll filings, social insurance) the EOR acts as controller in its own right. Good EOR contracts split the roles explicitly; missing DPAs are a standard vendor-audit finding.
Who signs DPAs in a group?
Each controller engaging the processor — practically solved by a group master DPA with accession for affiliates. The map of who controls which employees’ data (home employer vs host vs shared) should exist before the signature block is built.