Data Processing Agreements: What In-House Teams Should Negotiate

by | Oct 7, 2026 | Insights

unnamed file 2

Most data processing agreements arrive as a vendor’s standard addendum, and many get signed without a single redline. That works until the vendor suffers a breach, adds a subprocessor in a country you never approved, or starts using your customers’ data to improve its own AI model.

A data processing agreement (DPA) is the contract that governs how a vendor handles personal data on your behalf. The template is usually fine on the legally required terms. The money and the risk sit in the handful of clauses the template leaves vague, and those are the ones worth your negotiating time.

What a Data Processing Agreement Has to Cover

Under the GDPR, Article 28 requires a written contract whenever a processor handles personal data for a controller. It sets out the mandatory content: the processor acts only on your documented instructions, keeps the data confidential, applies appropriate security measures, uses subprocessors only under set conditions, helps you respond to data subject requests, deletes or returns the data at the end, and gives you the information needed to show compliance.

US law has moved in the same direction. The CCPA, as amended by the CPRA, requires specific contract terms with service providers and contractors, and most of the newer state privacy laws, including those in Virginia and Colorado, require a controller-processor contract with similar content. If you sell into Europe and the US, one well-built DPA can cover both, provided it addresses each regime’s requirements rather than only the GDPR’s.

Get the Roles Right Before You Redline

Before negotiating a single clause, confirm who is the controller and who is the processor. A payroll provider processing your employee data on your instructions is a processor. A vendor that also uses the data for its own purposes, such as benchmarking or product development, may be acting as an independent controller for that use, and a standard DPA will not cover it.

Getting this wrong changes the whole negotiation. If the vendor wants rights to use your data beyond delivering the service, that belongs in a separate, explicit clause you can accept, limit or refuse, not buried in a definition section.

Six Clauses Worth Your Negotiating Time

Subprocessors come first. Most vendors want a general authorization to appoint subprocessors, which is acceptable if you get advance notice of changes, a real right to object, and a commitment that every subprocessor signs terms at least as protective as yours. The GDPR already makes the processor liable to you for its subprocessors’ failures, so confirm the DPA does not quietly narrow that.

Breach notification is second. The GDPR gives you 72 hours to notify the supervisory authority once you become aware of a breach, while the processor only has to tell you “without undue delay.” Ask for a fixed window, commonly 24 to 48 hours, plus a minimum list of information the first notice must contain, so your clock does not run out while you wait for the vendor’s facts.

International transfers are third. If data leaves the EU or UK, the DPA should name the mechanism, whether that is the EU Standard Contractual Clauses, the UK transfer addendum, or the recipient’s certification under the EU-US Data Privacy Framework. Ask what happens if that mechanism is invalidated, as the EU courts did with both Safe Harbor and Privacy Shield.

Audit rights are fourth. Vendors will offer SOC 2 Type II or ISO 27001 reports in place of on-site audits, which is a reasonable default. Keep a right to a direct audit after a breach or at a regulator’s request.

Liability is fifth, and it is where many DPAs fail the buyer. If the DPA is silent, the main agreement’s liability cap usually applies, and that cap may equal a few months of fees. Negotiate a separate, higher cap for data protection breaches and make sure regulatory fines and notification costs fall inside it.

AI and secondary use is sixth. Add an express restriction on using your data, including derived or aggregated data, to train or improve the vendor’s models unless you opt in. This clause did not appear in most templates a few years ago, and it now matters on almost every SaaS deal.

When to Bring in Outside Privacy Counsel

Most in-house teams can handle a steady flow of DPAs with a clause playbook and a fallback position for each point above. The pressure comes in spikes: a vendor consolidation project, a product launch into a new market, or an acquisition where you inherit hundreds of vendor contracts with no consistent privacy terms.

Those spikes are where a dedicated privacy counsel or a short-term contract review team pays for itself. The same applies when AI tools enter the picture, since DPAs increasingly overlap with obligations under the EU AI Act, which we cover in our EU AI Act guide for general counsels.

LawFlex provides on-demand privacy lawyers and fractional DPO support across GDPR, CCPA and state privacy regimes, with vetted matches typically within 24 hours and no long-term contract. You keep the negotiating strategy in-house and add capacity only for the weeks you need it.

FAQ

Is a data processing agreement legally required?

Under the GDPR, yes: Article 28 requires a binding contract between a controller and any processor handling personal data on its behalf. The CCPA and most newer US state privacy laws also require specific contract terms with service providers and processors.

Who drafts the data processing agreement, the controller or the processor?

Either side can. Large vendors usually insist on their own DPA, while large customers often require vendors to sign theirs. If you are the smaller party, negotiate the clauses that carry risk rather than trying to replace the whole template.

What is the difference between a DPA and Standard Contractual Clauses?

A DPA governs how a processor handles personal data. Standard Contractual Clauses are a specific transfer mechanism approved by the European Commission for moving personal data outside the EU, and they are often attached to the DPA as an annex.

How quickly must a processor report a data breach?

The GDPR requires the processor to notify the controller without undue delay. Because the controller then has 72 hours to notify the regulator, many in-house teams negotiate a fixed notification window of 24 to 48 hours in the DPA.

Related Posts