Glossary

DEFINITION

Data Processing Agreement (DPA)

A GDPR-mandated contract between a controller and a processor that governs how personal data is handled on the controller's behalf.

In depth

A Data Processing Agreement (DPA) is required under Article 28 of the GDPR whenever a controller (the entity that decides why and how personal data is processed) engages a processor (an entity that processes data on the controller's behalf). The DPA must specify the subject-matter, duration, nature, purpose, and types of personal data, plus security obligations, sub-processor rules, breach-notification timelines, and the controller's audit rights. Using an AI service that processes EU personal data without a DPA in place is itself a GDPR violation, separate from any underlying lawful-basis issue.

Examples

  • An EU-based law firm signing a DPA with an enterprise AI vendor before piloting it for document review.
  • A SaaS company including its AI sub-processor in the chain of DPAs disclosed to customers.
  • A controller refusing to use an AI tool whose terms do not meet Article 28 minimums.

How Locke handles data processing agreement (dpa)

Sonomos does not act as a processor of customer data, because no customer data ever reaches Sonomos systems. There is no DPA to negotiate, no sub-processor to disclose, and no GDPR transfer mechanism to invoke.

See the product