Lawyer

Expert in international corporate, IT, and crypto law. Has extensive experience in business setup and support in the USA, EU, LATAM, and the Middle East. Specializes in corporate structuring, compliance, KYC/AML, IP, GDPR, as well as regulation of crypto and fintech projects.

Contact now
Data Processing Agreement (DPA) for GDPR

Data Processing Agreement (DPA) for GDPR

DPA (Data Processing Agreement) is not a “legal accessory” to a contract with a contractor. It is a document that makes the processing of personal data manageable: who has entrusted what to whom, what data is processed, how it is protected, to whom it is transferred, how it is returned/deleted and who is responsible if something goes wrong.

GDPR requires that there is a contract (or other legal act) between the controller and the processor with clearly defined processing conditions and control of the chain of subcontractors. This is not “good practice”, it is basic compliance hygiene.

DPA in simple words: who with whom and about what?

There are two key roles in the GDPR:

  • Controller (owner/the one who determines the purposes and means)   — decides “why”   and   “how”   the data is processed.
  • Processor (processor)   — processes data on behalf of the controller and only according to documented instructions.

A DPA is needed when you, as a controller, engage a contractor who has access to personal data: CRM, call center, email marketing, accounting, HR services, hosting, analytics, support service, dev team, etc.

Data Processing Agreement (DPA) для GDPR

When is a DPA almost always needed (and when is it not)?

A DPA is almost always needed if:

  • the contractor has access to your customer/user base;
  • the contractor hosts services/backend/logs;
  • the contractor provides support and sees profiles/history of requests;
  • the contractor provides mailings/targeting/behavioral analytics;
  • the contractor processes employee data (HR, payroll, recruiting).

A DPA may not be needed if:

  • the contractor is a separate controller, because it determines the purposes/means of processing itself;
  • you have a controller-to-controller model (there is a different logic of obligations and responsibilities).

The most common problem is incorrect qualification of roles. One paragraph “processor/controller” in the contract does not cure the actual reality.

Get legal advice

Mandatory conditions of DPA: what should be inside (checklist)?

Minimum “must-have” set (in essence, the requirements of Art. 28 GDPR):

  1. Subject matter and boundaries of processing: what is processed, for which services, in which systems.
  2. Duration, nature and purposes of processing.
  3. Data categories and categories of subjects.
  4. Documented instructions of the controller (how are they issued, who approves).
  5. Technical and organizational security measures (TOMs) (logic of Art. 32 GDPR).
  6. Subprocessors: procedure for involvement, register, notification of changes, objection mechanism, “flow-down” obligations.
  7. Controller assistance: requests from subjects (DSR), DPIA, interaction with the regulator, incidents/leaks.
  8. Return/deletion of data after completion of services (including backup policy).
  9. Audits/inspections and provision of information to demonstrate compliance.
  10. Processor personnel confidentiality (NDA, role-based access, training).

Cheat sheet: DPA structure “without hysteria”

DPA block What do we record? Why do you need it?
Description of processing subject/objectives/duration/systems removes “fuzziness” and disputes about boundaries
Data and subjects data types, categories of persons correct TOMs, DPIA, transfers
Instructions how they are issued, who approves, SLA proof of “documented instructions”
Security (TOMs) encryption, access, logging, reserves, SDLC reduces the risk of incidents and claims
Subprocessors list + update + right to object supply chain control
DSR/breaches/DPIA terms, channels, responsible so that you don’t “burn” in the regulator’s deadlines
Audit format (SOC2/ISO/online), frequency, NDA balance of control and realism
Termination delete/return, backups, confirmation “clean exit” without tails

Subprocessors: where do companies lose the most?

Almost every processor has a chain of subprocessors (cloud, logging, support, analytics). Practical minimum that should be in a DPA:

  • Subprocessor List;
  • Change Notice procedure;
  • Objection workflow and what to do next;
  • Flow-down: the same security/privacy requirements “down the chain”.

In short: if you don’t control the subprocessors, you don’t control the risk.

And what if there are international transfers? (SCC and “single architecture”)

If the data goes outside the EEA/UK (or there are non-EEA in the chain), a single DPA may not be enough – a transfer mechanism (often an SCC) and an agreed set of applications/measures are needed.

A healthy approach: do not produce documents “for the sake of checking off”, but assemble one logical structure: main agreement + DPA/Annex + transfer conditions (if necessary).

Typical mistakes (and why they are more expensive than a lawyer)

  • “Universal DPA on 2 pages” without a description of the actual processing.
  • TOMs as marketing (“we are very safe”), without specifics.
  • No mechanics of subprocessors and change notifications.
  • Audit: either “forbidden” or “come every week” (both options are bad).
  • Termination without delete/return and without logic for backups.
  • No SLA for DSR/incidents — and then it’s your fault, because the deadlines are yours.
Find out the cost of legal support

How do we usually do a DPA “turnkey” (process)?

  • Qualify roles: controller/processor/joint controllers.
  • Describe processing (Annex): systems, flows, data categories, accesses.
  • Fix TOMs for service and risk profile, not “copy-paste”.
  • Subprocessors: registry + governance + flow-down.
  • Transfers: SCC/additional measures — if necessary.
  • Negotiate with vendor: bring DPA to a realistic but protective standard.

5 “yes/no” questions for self-check

  1. Does the contract with the contractor describe the subject/purposes/term of processing and data types?
  2. Is there a TOMs/Annex that corresponds to your service, not a template?
  3. Is there a registry of subprocessors and a notification/objection procedure?
  4. Are the deadlines and procedure for DSR/incidents/DPIA prescribed?
  5. Is there an “exit plan”: delete/return + backups + confirmation?

If the answer to at least two questions is “no” — your DPA is probably decorative.

What can we do for the client (briefly, in essence)?

  • Preparation of DPA (Article 28) with annexes for a specific service.
  • Redline of the vendor’s DPA + risk matrix (what is critical, what is traded).
  • Governance of subprocessors and the transfer part (if non-EEA).
  • Due diligence package: description of TOMs, responses to partners/clients, audit logic.

DPA is like an umbrella: when you have it, rain seems like a small thing; when you don’t have it, suddenly the regulator appears and it turns out that you got wet, and the contractor is somehow to blame.

Calculate the cost of services

1 question

Do you need a consultation on GDPR?

Yes
No

2 question

Are you interested in developing a Data Processing Agreement for your company?

Yes
No

3 question

Do you need full fintech compliance for your business?

Yes
No

You may also need:

20%
discount
If we do not
call back
during the day
Consultation
Law company
Leave a request for legal assistance right now:
9+ years on the market
70+ professional practitioners
Fixed price
Online / offline consultation

Fintech

A ready-made company with a cryptocurrency license AML check Audit of a Crypto Exchange or Crypto Trader Audit of smart contracts AUTHORISED PAYMENT INSTITUTION IN UK BANK REGISTRATION IN CYPRUS Bookmaker’s license BUSINESS REGISTRATION IN COSTA RICA Buy a company with a crypto license Buy a ready-made brokerage company with a license in Ukraine Buy a ready-made company in Estonia Buy a ready-made company in Hong Kong with an account Buy a ready-made company in Poland Buy a ready-made company in the UAE (Dubai) Buy a ready-made company with a brokerage account in Ukraine Buy a ready-made company with turnover in Ukraine Buying a ready company with MetaTrader 4 Buying a ready-made company in Singapore Buying a ready-made company with an EMI license Canada MSB FINTRAC Registered for Sale 2026 Cancellation of gaming licenses Choosing Between MetaTrader 4 (MT4) or MetaTrader 5 (MT5) CLEAN COMPANY WITH METATRADER 4 PLATFORM COMPANY REGISTRATION IN ESTONIA COMPANY REGISTRATION IN HONG KONG Company registration in Latvia Company registration in Malta Company Registration in the UK Comparison of MetaTrader 4 and MetaTrader 5 Connecting the MetaTrader Platform Connecting to MetaTrader 5: A Guide for Brokerage Companies CREATION OF A HOLDING COMPANY IN CYPRUS Cryptocurrency and token accounting in Ukraine Cryptocurrency investment agreement CRYPTOCURRENCY SETTLEMENTS IN UKRAINE CYPRUS INVESTMENT FIRM STP BROKER FOR SALE Cyprus STP Broker for sale Data Processing Agreement (DPA) for GDPR DEVELOPMENT OF AN AML POLICY DRAWING UP A GIG CONTRACT Extension of gambling licenses in Ukraine FOREX jurisdiction Gambling license in Malta Gambling license in Ukraine Gambling table license GDPR compliance for business GETTING AN AEMI LICENSE IN THE UK How much does a MT4 license cost? HOW TO CONNECTI THE METATRADER PLATFORM How to to get MT4/MT5 Whitelabel licence How to unblock a money account at stock exchanges and other financial institutions? ICO SUPPORT Implementation of Travel Rule systems in Europe International M&A Services Internet casino license Internet poker license Investing in cryptocurrency – Legal support KYC verification Lawyers in the field of blockchain technology Legal Comparison of EMI/AEMI Electronic Money Licenses and PI Payment Institution Licenses Legal Opinion Letter Legal support for checking the security of a cryptocurrency wallet Legal support for crypto wallet unfreezing Legal support for the purchase of a ready-made company with a Forex license LEGAL SUPPORT FOR UNLOCKING CRYPTO ASSETS LEGAL SUPPORT WEB 3.0 SERVICES Legal verification of the crypto wallet Legal verification of the transaction for AML/CTF License for gambling equipment License for gaming machine halls LICENSE FOR PAYMENT SYSTEM IN CYPRUS License to trade cryptocurrencies Licensing of cryptocurrency activities in France Licensing of virtual currency service providers in Spain LLC registration in Bulgaria MSB Registration in Canada OBTAINING A BETTING LICENSE OBTAINING A CASINO LICENSE Obtaining a casino license in Ukraine OBTAINING A CRYPTO LICENCE IN HONG KONG Obtaining a crypto license in Bulgaria OBTAINING A CRYPTO LICENSE IN CURAÇAO OBTAINING A CRYPTO LICENSE IN ESTONIA Obtaining a Crypto License in Georgia OBTAINING A CRYPTO LICENSE IN GIBRALTAR OBTAINING A CRYPTO LICENSE IN ITALY OBTAINING A CRYPTO LICENSE IN KAZAKHSTAN OBTAINING A CRYPTO LICENSE IN KYRGYZSTAN OBTAINING A CRYPTO LICENSE IN LITHUANIA OBTAINING A CRYPTO LICENSE IN POLAND OBTAINING A CRYPTO LICENSE IN SINGAPORE OBTAINING A CRYPTO LICENSE IN SLOVAKIA OBTAINING A CRYPTO LICENSE IN SWITZERLAND OBTAINING A CRYPTO LICENSE IN THE CZECH REPUBLIC OBTAINING A CRYPTO LICENSE IN THE UAE Obtaining a Curacao gambling license Obtaining a forex license OBTAINING A GAMBLING LICENSE IN ANJOAN Obtaining a gambling license in the UK OBTAINING A LOTTERY LICENSE IN CURACAO Obtaining a MiCA license for CASP in the EU Obtaining a payment license in Belize Obtaining a PI Payment Licence Obtaining a PSP Licence for a Payment Service OBTAINING A VANUATU FOREX LICENSE Obtaining an AEMI license in Lithuania Obtaining an AEMI license in the Netherlands Obtaining an API (Application Programming Interface) Payment License OBTAINING AN EMI LICENSE IN KAZAKHSTAN Obtaining an EMI license in Malta Obtaining an EMI Payment Licence OBTAINING AN EMI PAYMENT LICENSE IN LITHUANIA Obtaining an MSO Licence in Hong Kong Obtaining an SPI in Poland Obtaining CASP in Austria OBTAINING CRYPTO LICENSES IN THE EU OBTAINING FOREX LICENSES OBTAINING LOTTERY LICENSE OBTAINING POKER LICENSES OBTAINING SVF LICENSE IN SINGAPORE OPENING A BANK ACCOUNT FOR A GAMBLING BUSINESS Opening a bank account in Turkey for a legal entity Opening a brokerage account in Exante Opening a business in Slovakia Opening a crypto company (CASP) in Poland Opening a crypto-friendly account Opening Accounts for High-Risk Businesses Opening an account in payment systems Opening an account in Payoneer for entities Opening an account in the payment system Opening of a sole proprietorship in Germany Opening of an individual enterprise in the Czech Republic Optimization of the tax burden in the UK Purchase a Ready-made Company with MT4 Purchasing a Ready-Made Company with MT5 READY-MADE COMPANIES WITH BROKERAGE LICENSE Ready-Made Pawnshop with a License and 6 Branches for Sale Real estate tokenization RECEIVING CRYPTO LICENSES IN EL SALVADOR Register a company in England Register a company in Hong Kong Register a company in the USA REGISTERING A BANK ACCOUNT IN HONG KONG REGISTERING A CRYPTO COMPANY IN COSTA RICA Registration of a company (LLC) in Austria Registration of a company (LLC) in Cyprus Registration of a Crypto Company in Georgia in a Free Industrial Zone Registration of an association providing p2p services in Poland Registration of an entrepreneur in the Netherlands Registration of an IE in Great Britain Registration of an individual entrepreneur for IT in Europe Registration of an individual entrepreneur in Austria Registration of an individual entrepreneur in Latvia REGISTRATION OF AN INDIVIDUAL ENTREPRENEUR IN SPAIN Registration of an LLC (BV) in the Netherlands Registration of an offshore company Registration of individual entrepreneurs (analogue) in Bulgaria Registration of LLC in Great Britain REGISTRATION OF THE COMPANY (LLC) IN THE CZECH REPUBLIC Registration of tokenization of real estate and other assets in Ukraine and abroad Relocation of business to Europe Relocation of business to the territory of the European Union SCC GDPR Self-Employed Person (SEP) in Malta Services of MLRO – specialist Smart contracts: The future of agreements based on blockchain technologies and their legal support SPI license in the Czech Republic Tax consultation in Europe Tax system for Ukrainians in Italy Tax system in Cyprus Tax system in Malta Taxation for Ukrainians in the Czech Republic Taxation of Ukrainians in Britain Taxation of Ukrainians in Estonia Taxation of Ukrainians in Germany TAXATION SYSTEM FOR UKRAINIANS IN SPAIN Termination of the GIG-contract The opening of the GmbH in Germany The system of taxation of Ukrainians in Austria The system of taxation of Ukrainians in Slovakia The taxation system for Ukrainians in Canada The taxation system for Ukrainians in Ireland The taxation system in Austria TOKENIZATION Unlocking crypto wallets on exchanges and other financial institutions