Data Processing Addendum
A Data Processing Addendum is a legal contract that sets out the rights and obligations of two parties when one handles personal data on behalf of the other. It typically applies when a service provider processes personal data to deliver its products or services to a customer. The document is intended to govern how that data is handled in line with applicable privacy and data protection laws.
A Data Processing Addendum (DPA) is a legally binding contract, often incorporated into or appended to a broader service agreement, that defines the obligations of the parties involved in the processing of personal data, commonly framed around a controller instructing a processor to carry out processing on its behalf. It typically describes the parties' respective responsibilities under applicable privacy, data security, and data protection laws, and generally applies when a provider processes customer personal data in its capacity as a processor in connection with the provision of its products, services, or related support. The specific scope, required terms, and applicable legal obligations vary by jurisdiction and by the underlying data protection regime; the evidence provided here does not detail the mandated contents of a DPA under any particular law, so this definition should not be treated as an exhaustive statement of statutory requirements.
Why it matters
A Data Processing Addendum is a foundational instrument for allocating data protection responsibilities between organizations that share personal data in a service relationship. In the context of cookie consent and tracking technologies, many organizations rely on third-party vendors, analytics providers, tag managers, consent management platforms, and advertising partners, that process personal data collected through cookies, pixels, SDKs, and similar technologies. A DPA is the mechanism through which the customer, often acting as a controller, sets out the terms under which such a provider handles that data, commonly in its capacity as a processor.
Without a DPA in place, an organization may struggle to demonstrate that its vendor relationships are governed in line with applicable privacy and data protection laws. Because a DPA describes the parties' respective obligations, it supports accountability and helps clarify who is responsible for what when personal data is processed on one party's behalf. It is important to note, however, that the specific contents and mandated terms of a DPA vary by jurisdiction and by the underlying data protection regime; the presence of a DPA supports compliance but does not by itself guarantee it, and it does not replace the legal judgment needed to assess whether a given processing arrangement is lawful.
Who it's relevant to
Inside DPA
Common questions
Answers to the questions practitioners most commonly ask about DPA.

