Why does my company need a Data Processing Addendum (DPA)?

By Will Elton, Last updated: 2023-01-11 (originally published on 2021-03-01)

To begin, a Data Processing Addendum (DPA) is a contract between data controllers and data processors. The main purpose of a Data Processing Addendum (DPA) is to protect the user’s data in compliance with the GDPR or any other Privacy Laws.

For example, you have a business that operates through a website and collects the information of the visitors visiting your website. But, at some point, your business has to work with some other third-party processor to handle some of the data. Therefore, at that time a “Data Processing Addendum” will help your business legally if said third-party misuses your user’s data. 

Importantly, one of the key changes introduced by the GDPR is that a clear framework of responsibility is established for data protection. Essentially, a data controller may only appoint processors that provide a “sufficient guarantee” to meet the requirements of the GDPR. A data processor may only act on “documented instructions” of the controller. And, must comply with a number of requirements to ensure that the controller will fulfil its obligations under the GDPR. 

Do I need a Data Processing Addendum (DPA)?

If you’re running a business that works with user’s data, then you need a Data Processing Addendum. Having a Data Processing Addendum will help your business in a legal dispute if a third-party try to misuse your user’s data. It offers protection for your company for any third party act that is not in compliance with GDPR or other privacy laws.

Essentially, without a DPA your business might be at risk if a third-party provider tries to manipulate your user’s data. This is the case because the wrong-doings of that third-party would otherwise fall on your company’s head. Additionally, there are not only legal ramifications but also the damage to the reputation of your company that may result in a decrease in revenue. 

What is GDPR & PDPA?

In a nutshell, every country has their own set of data protection and privacy laws. For instance, the European Union has established the General Data Protection Regulation (GDPR) act.  In Singapore, they have PDPA, which stands for Personal Data Protection Act 2010. This regulates the processing of all personal data that has been collected while making any commercial transaction.

The General Data Protection Regulation (“GDPR”) is a new privacy law in the European Union (“EU”) that came into force on 25 May 2018. The GDPR regulates the protection of personal data, which includes any information that can be used to identify a person, such as a name, identification number, location data, or online identifier, and a wide range of other types of information. The GDPR applies to all businesses in the EU, including the UK.

However, if you are a business outside the EU that collects personal data from individuals in the EU, and you make decisions about how and why personal data is used, you will be considered a “controller” under the GDPR. And, will be subject to its rules regarding the data of those individuals. If you process the personal data of individuals in the EU on behalf of a controller, you will be considered a “processor” and will also need to comply with the GDPR.

Conclusion on DPA

The Data Processing Addendum supplements any service agreement (or terms of service) already in place. Importantly, the Data Processing Addendum is not just a document that is nice to have. It is mandatory The GDPR, for instance, requires that processing of personal data by a service provider on behalf of a data controller must be governed by a binding contract. It sets out details of the personal data by the processor on behalf of the controller and each party’s responsibilities in such processing.

You Might Also Like

Along with this document, make sure you see these other templates in our library:

The Zegal Template Library

Zegal’s template library represents a complete and curated list of essential and premium business templates that can be used directly, for everyday business needs. Importantly, whether you’re a startup or a larger enterprise, you will find that our Zegal automation solution allows anyone to create a legal agreement, any time, anywhere. All without a need for an expensive lawyer. Why do we do this? Well, we think that running your business day-to-day is important, and having these templates at your fingertips allows you to not miss a beat!

Lawyers draft and curate all of our legal templates for ease of understanding using plain English. Just fill out our guided questionnaires, and we will create the contract for you. Using our patent-pending expert rules engine, we automate the creation of complex legal contracts.

Try it for free today!

Tags: GDPR | privacy

Like what you just read?

Subscribe to our newsletter and be the first to hear of the latest Zegal happenings, tips and insights!