Skip to content
Glossary

What is a data processing agreement (DPA)?

The contract every European customer's lawyer asks for. Here is what it is and what your product has to back up.

Plutonapps Engineering1 min read

In short

A data processing agreement (DPA) is the contract required by Article 28 of the GDPR between a controller, the business that decides why personal data is used, and a processor that handles the data for it. It sets out what is processed, why, how it is secured, which subprocessors are used and what happens at the end.

Also called: DPA, Data processing addendum, Article 28 agreement

Why it matters when your prototype goes to production

If your app stores personal details about people in Europe or the UK, you are a controller, and every supplier that touches that data, your host, database, email and analytics providers, is a processor that needs a DPA with you. When you sell to businesses, you become their processor, and they will send you theirs to sign.

Subprocessors

A subprocessor is a supplier your processor uses in turn. A DPA normally requires a published list of them and notice before it changes. For an app, that list is simply your infrastructure: where the database runs, who sends email, which AI models see user content.

What the product has to back up

  • Deleting a person's data on request, everywhere it was copied.
  • Knowing which suppliers receive which data.
  • Security measures you can describe accurately in the contract.

Common questions

Is a DPA a legal requirement?

Under the GDPR, processing by a processor has to be governed by a contract or other legal act meeting Article 28. In practice that contract is the DPA.

More on this: Production architecture & security · All glossary terms

Built something in Lovable you want people to rely on?

We are the engineers who take it the rest of the way — secured, tested, released and supported.