# What is Data Processing Agreement? Also called DPA, Data Processing Addendum. A data processing agreement is a contract between a controller and a processor that governs how personal data may be handled on the controller's behalf. Article 28 of the General Data Protection Regulation requires such a contract and specifies terms it must contain, including the subject matter, duration, nature and purpose of processing, and the categories of data involved. The required terms follow a consistent pattern. The processor acts only on documented instructions, imposes confidentiality on personnel, implements appropriate security measures, engages subprocessors only with authorization and passes equivalent obligations down, assists the controller with data subject requests and breach notification, deletes or returns data at the end of the engagement, and makes information available for audits. International transfers are usually handled in the same document or an annex. Where personal data moves outside the European Economic Area to a country without an adequacy decision, standard contractual clauses are the common mechanism, generally accompanied by an assessment of the destination country's laws. The relevant clauses and the surrounding case law have changed more than once, so current versions matter. For AI services the clauses that deserve close reading concern training and retention. Whether submitted content may be used to train or improve models, how long prompts, completions, and traces are retained, whether human reviewers may access content, and which subprocessors including model providers are involved are all commercial and contractual questions rather than technical ones, and they vary considerably between vendors and even between tiers of the same vendor. Related instruments are frequently confused with a processing agreement. A data protection impact assessment is an internal risk analysis a controller performs for high-risk processing, not a contract. A joint controller arrangement applies where two parties jointly determine purposes. A processing agreement is specifically the controller to processor instrument, and using the wrong one leaves the required terms unaddressed. ## Key points - Required by GDPR Article 28 between controller and processor - Sets instructions, security, subprocessors, assistance, deletion, audit - Transfers outside the EEA usually rely on standard contractual clauses - For AI, read the training, retention, and human review clauses - Distinct from an impact assessment or a joint controller arrangement ## In practice A company adopting an AI writing tool reviews the processing agreement before rollout. It confirms that submitted content is excluded from model training, that prompts and outputs are retained for thirty days for abuse monitoring, that the subprocessor list names the model provider and the region it serves, and that transfers rely on standard contractual clauses. Two of those points required a signed amendment rather than the default terms. ## Related terms - [GDPR](/en/glossary/gdpr) - [Data Residency](/en/glossary/data-residency) - [SOC 2](/en/glossary/soc-2) - [Data Leakage Prevention](/en/glossary/data-leakage-prevention) - [AI Governance](/en/glossary/ai-governance) [Back to the AI Glossary](/en/glossary)