What is a data processing agreement (DPA)?
The contract every European customer's lawyer asks for. Here is what it is and what your product has to back up.
In short
A data processing agreement (DPA) is the contract required by Article 28 of the GDPR between a controller, the business that decides why personal data is used, and a processor that handles the data for it. It sets out what is processed, why, how it is secured, which subprocessors are used and what happens at the end.
Also called: DPA, Data processing addendum, Article 28 agreement
Why it matters when your prototype goes to production
If your app stores personal details about people in Europe or the UK, you are a controller, and every supplier that touches that data, your host, database, email and analytics providers, is a processor that needs a DPA with you. When you sell to businesses, you become their processor, and they will send you theirs to sign.
Subprocessors
A subprocessor is a supplier your processor uses in turn. A DPA normally requires a published list of them and notice before it changes. For an app, that list is simply your infrastructure: where the database runs, who sends email, which AI models see user content.
What the product has to back up
- Deleting a person's data on request, everywhere it was copied.
- Knowing which suppliers receive which data.
- Security measures you can describe accurately in the contract.
Common questions
Is a DPA a legal requirement?
Under the GDPR, processing by a processor has to be governed by a contract or other legal act meeting Article 28. In practice that contract is the DPA.
Related terms
Read next
Sources
More on this: Production architecture & security · All glossary terms
Built something in Lovable you want people to rely on?
We are the engineers who take it the rest of the way — secured, tested, released and supported.