DEFINITION
Data Processing Agreement (DPA)
A GDPR-mandated contract between a controller and a processor that governs how personal data is handled on the controller's behalf.
In depth
A Data Processing Agreement (DPA) is required under Article 28 of the GDPR whenever a controller (the entity that decides why and how personal data is processed) engages a processor (an entity that processes data on the controller's behalf). The DPA must specify the subject-matter, duration, nature, purpose, and types of personal data, plus security obligations, sub-processor rules, breach-notification timelines, and the controller's audit rights. Using an AI service that processes EU personal data without a DPA in place is itself a GDPR violation, separate from any underlying lawful-basis issue.
Examples
- An EU-based law firm signing a DPA with an enterprise AI vendor before piloting it for document review.
- A SaaS company including its AI sub-processor in the chain of DPAs disclosed to customers.
- A controller refusing to use an AI tool whose terms do not meet Article 28 minimums.
How Locke handles data processing agreement (dpa)
Sonomos does not act as a processor of customer data, because no customer data ever reaches Sonomos systems. There is no DPA to negotiate, no sub-processor to disclose, and no GDPR transfer mechanism to invoke.
See the productRelated terms
- GDPR
The EU General Data Protection Regulation — the world's most comprehensive data-protection law, governing how organisations handle personal data of EU residents.
- Business Associate Agreement (BAA)
A HIPAA-mandated contract between a covered entity and a vendor that handles PHI on its behalf, defining each party's privacy and security obligations.
- Personally Identifiable Information (PII)
Any information that can identify a specific person, either directly (name, SSN) or in combination with other data (zip code + birthdate).