Skip to content
Data Processing Agreement

Data Processing Agreement: Who Controls the Data and What the Processor Must Do

A DPA is the contract governing how a supplier handles personal data on your behalf. This entry explains the roles, the terms such agreements normally contain, and the clauses worth reading closely.

Free Forever • No Credit Card Required

Data processing agreement structure showing controller and processor roles, sub-processors and transfer mechanisms

Quick answer

Is HelloGrowthCRM right for Data Processing Agreement?

Yes. HelloGrowthCRM gives Data Processing Agreement a single system to capture every lead, automate follow-up across phone, WhatsApp, and email, prioritise leads with AI scoring, and forecast revenue — with calling and messaging built in instead of sold as add-ons. It's built for the problems these teams actually hit — like the supplier is treated as a processor for everything, when in fact it acts as a controller for some of the data, so the agreement does not describe the actual arrangement — rather than generic sales busywork.
  • Plain definition: a data processing agreement is the contract that governs how one organisation handles personal data on behalf of another, and it exists because the law requires the arrangement to be written down
  • The core distinction is between the controller, which decides why and how personal data is processed, and the processor, which processes it on the controller's instructions
  • Most business software vendors act as processors for their customers' data while being controllers of their own account and billing data, so both roles can exist in one relationship

See pricingBook a demo

01

Why the document exists

When one organisation handles personal data on behalf of another, data protection law in most jurisdictions requires the arrangement to be governed by a written contract with specified content. That contract is the data processing agreement. It is not a formality invented by lawyers: it is the mechanism by which obligations towards individuals follow their data into a supplier's systems.

For a buyer of business software, this is now a routine part of procurement. Almost any system holding customer records, employee details or contact information involves a processing relationship, and a supplier without a standard agreement to offer is unusual.

02

Controller, processor, and why the roles are not always obvious

The controller decides why and how personal data is processed. The processor does it on the controller's instructions. In a straightforward software purchase, the customer is the controller of the records it uploads and the vendor is the processor.

The complication is that most relationships involve more than one data set. A vendor is typically a processor for the customer data you upload and a controller for the account, billing and usage data it collects about your organisation, because it decides those purposes itself. A well-drafted agreement acknowledges both roles rather than describing the whole relationship in one direction. Where a supplier begins determining purposes for data you provided, for example by using it for its own analysis, it may become a controller for that activity whatever the contract calls it.

03

What the agreement normally contains

ProvisionWhat it should specifyWhy it matters
Scope of processingSubject, duration, nature, purpose, data typesDefines the boundary of permitted use
InstructionsProcessing only on documented instructionsPrevents unilateral repurposing
SecurityAppropriate technical and organisational measuresThe substantive protection obligation
Sub-processorsAuthorisation, notice and objection rightsRisk follows the data downstream
AssistanceSupport for rights requests and breach dutiesThe controller carries these obligations
Breach notificationTrigger, period and information providedControllers face short statutory deadlines
TransfersLocations and the mechanism usedCross-border movement needs a lawful basis
Deletion or returnFormat, period, confirmation, backupsDetermines whether exit is clean
04

The clauses worth reading closely

Sub-processors

Data entrusted to one supplier is frequently handled by several. Hosting, messaging, analytics and support tooling all touch it. The reasonable arrangement is a maintained list, advance notice of additions and a right to object. A clause allowing unlimited additions with no notice removes any ability to assess who holds your data, which is the specific thing a security review is for.

Breach notification

Controllers usually face a short statutory deadline to notify a regulator after becoming aware of a breach. A processor commitment to notify without undue delay, with no period stated, can leave the controller unable to meet that deadline through no fault of its own. Ask for a defined maximum period and a list of the information that will accompany the notification.

Deletion and exit

Deletion or return at the end of the contract is a required term everywhere, and the difference between a real commitment and a nominal one lies in the detail. Which format is data returned in, and can it be loaded into another system. Within what period does deletion occur, and is confirmation provided. How long do residual copies persist in backups before their retention cycle expires. A supplier that answers the last question honestly is being accurate; one that claims instant and total deletion including backups is usually not.

05

International transfers

Moving personal data across borders generally requires a lawful basis. Under the European framework, the common routes are an adequacy decision covering the destination country and standard contractual clauses agreed between the parties, sometimes with an assessment of the destination's legal environment. The practical questions for a buyer are simpler: where is the data stored, where is it processed, which functions move it elsewhere, and can a region be chosen.

Requirements differ by jurisdiction, and a business operating in several should not assume one approach satisfies all of them. India's framework, which uses data fiduciary and data processor in place of controller and processor, likewise requires a contract to be in place before a processor handles data on a fiduciary's behalf. Nothing on this page is legal advice, and data protection is an area where the general shape is easy to describe and the specific application is not.

06

Related terms

A security review assesses whether a supplier's practices are adequate, while the data processing agreement is the contractual expression of what it must do. A master service agreement is the framework the processing agreement usually attaches to. A sub-processor list is the operational document that supports the sub-processor clause. Standard contractual clauses are one of the transfer mechanisms rather than a substitute for the agreement itself.

Challenges we solve

The problems holding this industry back — and the fix

Every team in this space loses revenue to the same recurring gaps. Here is what they cost you and how HelloGrowthCRM closes each one.

  • The supplier is treated as a processor for everything, when in fact it acts as a controller for some of the data, so the agreement does not describe the actual arrangement.

    Map the roles per data set rather than per relationship. A vendor is usually a processor for the customer records you upload and a controller for the account and billing information it collects about you, and the agreement should say so.Roles mapped per data set

  • The sub-processor clause allows new third parties to be added with no notice, so data reaches organisations the customer has never assessed.

    Require a maintained sub-processor list, advance notice of additions and a stated right to object. This is standard practice among established vendors and a reasonable request of any supplier holding customer data.Sub-processor notice and objection

  • Breach notification says the processor will notify without undue delay, with no period stated, so the controller cannot meet its own regulatory deadlines.

    Ask for a defined maximum period and a list of the information that will be provided. The controller usually carries a short statutory deadline of its own, and a processor commitment that is vaguer than that deadline leaves the controller unable to comply.Defined breach notification terms

  • Deletion at the end of the contract is promised without a format, a timescale or any statement about backups, so the obligation cannot be verified.

    Specify the format for returned data, the period for deletion, whether confirmation is provided, and how long residual copies persist in backups before expiring. An unverifiable deletion commitment is a statement of intent rather than a control.Verifiable deletion terms

What you get

Why teams choose HelloGrowthCRM

AI-powered CRM with the features you need to close more deals.

  • Plain definition: a data processing agreement is the contract that governs how one organisation handles personal data on behalf of another, and it exists because the law requires the arrangement to be written down
  • The core distinction is between the controller, which decides why and how personal data is processed, and the processor, which processes it on the controller's instructions
  • Most business software vendors act as processors for their customers' data while being controllers of their own account and billing data, so both roles can exist in one relationship
  • Under the European framework, a written contract between controller and processor is mandatory and must cover a specified list of matters rather than being left to general drafting
  • Those required matters include the subject and duration of the processing, its nature and purpose, the types of personal data involved and the categories of individuals affected
  • The processor must act only on documented instructions, keep personnel under confidentiality obligations, and implement appropriate technical and organisational security measures
  • Sub-processor terms govern whether the processor may engage others, how the controller is informed, and what right the controller has to object to a new one
  • The processor must assist the controller with individual rights requests, with breach notification and, where applicable, with impact assessments, since the controller carries those obligations
  • Breach notification terms should state the trigger, the notification period and what information will be provided, and vague wording here is a common weakness
  • Deletion or return of data at the end of the contract is a required term, and the practical questions are the format, the period and how long backups retain copies afterwards
  • International transfers need a lawful basis, and the usual mechanisms are an adequacy decision covering the destination or approved standard contractual clauses between the parties
  • India's data protection framework uses the terms data fiduciary and data processor, and requires processing by a processor to take place under a valid contract, so a written agreement is expected there too

HelloGrowthCRM by the numbers

$12
per user/month list price — $10/user/mo on annual billing, ₹899/user/mo in India
$0
free forever starter plan — no credit card required
14-day
trial included on paid plans
259+
live integrations, from WhatsApp to Tally and QuickBooks
500+
teams worldwide run their pipeline on HelloGrowthCRM

Frequently Asked Questions

Common questions about using HelloGrowthCRM in your industry.

Ready to grow?

Join small businesses that close more deals with HelloGrowthCRM.

Free Forever • No Credit Card Required

Take the next step

Free Forever • No Credit Card Required

Prefer email? Write to sales@hellogrowthcrm.com