Data Processing Agreement Template 2026 — GDPR Article 28 Must-Haves
TL;DR: A data processing agreement (DPA) is the contract GDPR — and similar privacy laws — require whenever one company processes personal data on behalf of another. Article 28 of the GDPR lists terms that are mandatory, not optional: documented instructions, confidentiality, security measures, sub-processor controls, assistance duties, deletion and audit rights. The template structure below walks through each required element, plus transfer clauses and a negotiation cheat sheet. It is general information, not legal advice.
What Is a Data Processing Agreement and Who Needs One?
A DPA is the agreement between a controller — the organization that decides why and how personal data is used — and a processor — the vendor that handles that data on the controller's instructions. Cloud hosting, payroll providers, CRM platforms, support desks and AI service providers all typically act as processors, which means every one of those relationships needs Article 28 language in place before processing starts, not after procurement remembers.
The same pattern appears beyond Europe: comparable "processor obligations" show up in other comprehensive privacy laws, so a well-drafted DPA usually travels further than its GDPR origin.
Why Does GDPR Article 28 Make These Terms Mandatory?
Article 28(3) requires that processing be governed by a binding contract setting out specific minimum content. The logic is accountability: the controller remains responsible for compliance even though the processor physically holds the data, so the law forces the controller to write its instructions down and to retain oversight rights over the vendor.
Missing or vague Article 28 content is not a cosmetic defect — regulators have treated inadequate processor arrangements as violations in their own right, and controllers without DPAs face awkward questions in any audit or breach investigation.
Which Clauses Must the Template Contain?
Subject matter, duration, nature and purpose
Describe what is processed, for how long, and why: "hosting of customer contact records for the term of the master services agreement, for the purpose of delivering the service." Annexes usually carry this detail; keep them specific enough that a stranger could tell what the vendor actually does with the data.
Categories of data and data subjects
List data types (contact details, employment records, identifiers) and whose data it is (customers, employees, end users). Precision here drives everything downstream — special categories such as health data trigger heavier expectations.
Documented instructions only
The processor acts only on the controller's documented instructions, including for transfers to third countries. Add a clause obliging the processor to flag instructions it believes infringe data protection law — the GDPR expects that notification duty.
Confidentiality commitments
Persons authorized to process must be under confidentiality obligations. Reference internal training and access-on-a-need-to-know basis rather than relying on the master agreement's generic NDA clause.
Security measures
Article 32 requires appropriate technical and organizational measures — encryption in transit and at rest, access control, pseudonymization where feasible, backup and recovery, vulnerability management. Attaching a security annex (or referencing a certified standard such as ISO 27001 or SOC 2 reports) is common practice, but remember certifications evidence, they do not replace, the obligation.
Sub-processors
Processors need prior specific or general written authorization to engage sub-processors, must impose the same data protection obligations down the chain, and remain liable for their sub-processors' failures. Provide for a list with change notice and a reasonable objection right.
Data subject rights assistance
The processor must assist the controller in responding to access, rectification, erasure and portability requests, taking into account the nature of the processing. Define response timeframes so the controller can meet statutory deadlines.
Breach notification
On becoming aware of a personal data breach, the processor must notify the controller without undue delay. Negotiate a concrete number (commonly 24 to 72 hours from awareness) and define what counts as "awareness" — this is one of the most contested clauses in real negotiations.
Deletion or return
At the end of the service, the processor must delete or return all personal data and delete existing copies unless storage is legally required. Specify the deletion deadline, the method (certified erasure standards help), and who certifies completion.
Audit and inspection rights
The controller may audit compliance directly or through an independent auditor. In practice most vendors offer certification reports as the first layer with on-site audits reserved for genuine cause — a workable compromise if the reporting is substantive.
How Do International Transfers Fit into the DPA?
If data leaves the European Economic Area, the DPA must address the transfer mechanism. The standard toolkit is the European Commission's Standard Contractual Clauses (SCCs), selected by module depending on the transfer direction (controller-to-processor being the usual case here), together with a transfer impact assessment where the destination country's surveillance laws raise questions. The UK adds its own IDTA or the UK addendum, and Switzerland requires minor modifications. Getting the modules wrong is a frequent, avoidable error — match each module to the actual role of each party.
| DPA element | Source | Common negotiation flashpoint | Fallback position |
|---|---|---|---|
| Breach notice window | Art 33 duty to assist | 24h vs 72h from awareness | "Without undue delay, target 48h" |
| Sub-processor approval | Art 28(2) | Specific vs general authorization | General + advance list + objection right |
| Audit scope | Art 28(3)(h) | On-site audits on demand | Certificates + audits with 30 days' notice and cause |
| Transfer mechanism | Chapter V | Which SCC modules apply | Module map per entity and role |
| Liability cap | Master agreement | Carve data claims out of the cap? | Super-cap sized to realistic exposure |
Controller or Processor: Why Does the Label Matter So Much?
Because obligations attach differently to each role. Controllers carry primary accountability for lawful basis, transparency and data subject rights; processors carry direct statutory duties too (security, breach notification to the controller, no sub-processing without authorization), but their main exposure flows through the contract. Mislabeling — calling an autonomous decision-maker a "mere processor" — unravels the whole structure when tested. When two organizations jointly decide purposes and means, joint-controller rules apply instead, requiring their own arrangement.
Vendors building AI features face an extra layer: model training on customer data changes the risk profile entirely, and should be addressed explicitly — permitted, prohibited, or permitted only with de-identification and opt-outs. Our overview of drafting an AI-ready privacy policy covers the public-facing side of those choices.
If you negotiate DPAs regularly, MeshLaw can draft and compare DPA redlines against your playbook — try it free →, keeping counsel in charge of judgment calls.
How Should You Run the Pre-Signature Checklist?
- Map the flow: what data goes where, who are recipients, does anything leave the EEA?
- Fix the roles: controller, processor or joint controllers — document the reasoning.
- Attach annexes: subject matter, categories, sub-processors, transfers, security measures.
- Check the chain: get the vendor's sub-processor list and spot-check their own downstream DPAs.
- Synchronize documents: make sure the master agreement's confidentiality, liability and survival clauses do not contradict the DPA.
- Calendar renewals: sub-processor lists change; set a review cadence instead of trusting notices to arrive.
For teams that also handle litigation or investigations data, the same discipline extends to evidence handling — see our guide to AI-assisted eDiscovery review. And when privacy diligence meets corporate transactions, our note on AI for M&A due diligence review shows how contract populations get screened at speed.
Frequently Asked Questions
Is a DPA required by law?
Under the GDPR, yes: processing by a processor must be governed by a contract containing the Article 28 elements. Comparable requirements exist in several other privacy regimes. Beyond legality, the DPA allocates risk in ways both sides need anyway.
Can we just accept the vendor's click-through DPA?
Sometimes, if its content genuinely covers the mandatory elements and your risk profile tolerates standard terms. Read the annexes regardless — that is where sub-processors, transfers and breach windows hide. High-volume or sensitive processing usually justifies negotiation.
Do we need a separate agreement or can it live in the MSA?
Either form satisfies the law as long as the substance is present and enforceable. Many vendors embed a DPA as an appendix or click-through incorporated into the master services agreement. What matters is completeness and a clear paper trail of acceptance.
Who signs on the controller side?
The legal entity acting as controller, ideally the same entity named in the master agreement. Group-wide signatures cause enforcement gaps when the contracting entity differs from the entity whose data flows. Check group structure before signing.
What happens if the processor breaches the DPA?
Contractual remedies apply — damages, indemnities, termination — and regulators can pursue either party, since processors now hold direct statutory duties too. Liability caps in the master agreement often limit practical recovery, which is why data-specific carve-outs are negotiated.
Are SCCs enough for international transfers?
They are the mechanism, not the whole answer. Exporters must also assess whether the destination country's laws undermine the protections and add supplementary measures where needed. Documentation of that assessment is itself expected.
Does the DPA cover marketing emails or analytics?
Only if those activities are within the documented instructions and the recipient is truly a processor. Advertising partners usually act as independent or joint controllers, needing different contracts entirely. Classify each relationship before choosing paper.
How long should we retain data after termination?
Default expectation is deletion or return promptly after the service ends, unless a legal retention duty applies. Set a concrete number of days, require certification of deletion, and address backups explicitly since purge cycles differ.
Can the processor use aggregated or anonymized data?
Only if the DPA permits it and the anonymization is genuine — properly anonymized data falls outside data protection law, but pseudonymized data does not. Vendors push broad usage rights; controllers should bound them tightly.
What about AI vendors specifically?
Treat them as processors unless they autonomously decide purposes, and pin down whether prompts or customer data train models. Prohibit or condition training explicitly, and ask where inference data is stored and transferred. Generic cloud boilerplate rarely answers these questions.
Do small businesses really need this?
The obligation scales with role, not headcount — any controller using a processor needs Article 28 terms. Smaller firms can lean on reputable vendors' standard DPAs rather than negotiating from scratch. Skipping it entirely is the one option that creates unmanaged risk.
How does the EU AI Act interact with our DPA?
They regulate different things — the AI Act targets AI systems' risks rather than personal data flows as such — but deployments using personal data will touch both. Our plain-language guide to the regulatory compliance monitoring routine maps the timeline; treat specialist advice as essential for specifics.
The Bottom Line
A DPA is not paperwork theater — it is the control system that lets you answer, with evidence, what a vendor does with personal data and who pays when something fails. Cover every Article 28 element, match transfer modules to reality, and re-check the annexes when sub-processors move. To accelerate drafting and review, try MeshLaw free → and keep human counsel focused on the clauses worth fighting.
Related guides
AI drafts, a lawyer reviews. Sign up free and see it on your own matter.
Get started free →