Skip to content
teamed.

Glossary

Data Processing Agreement

A Data Processing Agreement (DPA) is a binding contract between a data controller, such as an employer, and a data processor, such as an HR platform or EOR, that sets out how employee personal data may be processed in line with GDPR and similar privacy laws.

Reviewed by Teamed's in-house employment-law team·Last updated 28 July 2026

What is Data Processing Agreement?

A Data Processing Agreement (DPA) is a contract that governs how one organisation processes personal data on behalf of another. It sets the controller, who decides why and how data is used, on one side, and the processor, who acts on the controller's instructions, on the other, and it fixes the rules between them in writing.

In employment, an employer is usually the controller of its staff data, whilst a payroll provider, HR platform or Employer of Record acts as a processor. The DPA states the purpose and scope of processing, the security measures required, how long data is kept, what happens on termination, and the rules for any onward transfer to another country.

Under the GDPR, a DPA is not optional. Whenever a controller hands personal data to a processor, the law requires a binding agreement covering a defined set of terms. A well-drafted DPA protects the individuals whose data is processed and gives both parties a clear record of who is responsible for what.

What must a Data Processing Agreement include?

Under GDPR, it must set out the subject matter, duration, nature and purpose of the processing, the types of data and categories of people involved, and the controller's and processor's obligations. It must require the processor to act only on documented instructions, keep data confidential, apply proper security, and help the controller meet its own duties.

GDPR Article 28 lists these terms explicitly, which is why most DPAs follow a broadly similar structure across vendors.

Who is the controller and who is the processor?

The controller decides why and how personal data is processed; the processor carries out that processing on the controller's behalf. In a typical setup, the hiring company is the controller of its employee data, and its payroll provider, HR software or Employer of Record is the processor acting under instructions.

When do I need a DPA for HR or payroll data?

Whenever you let a third party process personal data about your workers on your behalf. That includes payroll bureaus, benefits administrators, HR software vendors and Employer of Record providers. If employee data leaves your systems and enters theirs, GDPR expects a Data Processing Agreement to be in place before the processing begins.

Key facts

GDPR Article 28
GDPR Article 28 requires a binding contract, such as a Data Processing Agreement, whenever a controller uses a processor, and it lists the specific terms that contract must contain.Source: GDPR, gdpr-info.eu· verified 2026-07-28

Frequently asked questions

  • Is a Data Processing Agreement legally required?
    Under the GDPR, yes, whenever a controller shares personal data with a processor. Article 28 makes a binding contract mandatory and sets out what it must contain. Other privacy regimes, including several outside Europe, impose similar requirements, so a DPA has become standard practice for HR and payroll vendors.
  • What is the difference between a DPA and standard contractual clauses?
    A DPA governs the controller and processor relationship in general. Standard contractual clauses are a specific mechanism for lawfully transferring personal data out of the EU to a country without an adequacy decision. A single arrangement often needs both: a DPA for the processing, and the clauses for any cross-border transfer.
  • Does my EOR need a DPA?
    Almost always. An Employer of Record processes a great deal of employee personal data, from payroll details to tax records, on your behalf. A DPA sets out how that data is handled, secured and returned or deleted, and it is a reasonable thing to expect any credible provider to sign.
  • What happens if there is no DPA in place?
    Processing personal data without a required DPA is itself a GDPR breach, separate from any data incident. It can expose both parties to enforcement action and leaves responsibilities undefined if something goes wrong. Putting the agreement in place before processing starts is far simpler than fixing it afterwards.

Related terms

Note

This is general information, not legal advice. Statutory rules vary by country and change over time.

Glossary

Have a global hiring question?

Ask a real person, or run the numbers yourself with the free calculators.

Talk to us about employee data protection

Last verified 2026-07-28