Reading a DPA
What is a data processing agreement (DPA)?
A data processing agreement (DPA) is the contract between a company and a vendor that handles personal data on the company’s behalf. It says what the vendor may do with the data, how it keeps it safe, and what happens when the vendor brings in another company to help. The law is quoted below from the official text, and every vendor clause from an agreement we read on the date shown.
Controller and processor
The GDPR, the EU data protection law, names the two sides. Your company is usually the controller. The vendor is the processor.
‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data
GDPR Article 4(7) — official text · read September 30, 2026
‘processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller
GDPR Article 4(8) — official text · read September 30, 2026
California uses different words for a similar role: a business, and its service provider. The service provider’s status depends on a written contract.
“Service provider” means a person that processes personal information on behalf of a business and that receives from or on behalf of the business consumer’s personal information for a business purpose pursuant to a written contract, provided that the contract prohibits the person from: (A) Selling or sharing the personal information.
California Civil Code §1798.140(ag)(1) — official text · read September 30, 2026
The law requires the contract
Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller.
GDPR Article 28(3) — official text · read September 30, 2026
A business that collects a consumer’s personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that: (1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.
California Civil Code §1798.100(d) — official text · read September 30, 2026
What a DPA must contain under the GDPR
Article 28(3) goes on to list what the contract must stipulate. The processor:
- (a)processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject;
- (b)ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- (c)takes all measures required pursuant to Article 32;
- (d)respects the conditions referred to in paragraphs 2 and 4 for engaging another processor;
- (e)taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in Chapter III;
- (f)assists the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 taking into account the nature of processing and the information available to the processor;
- (g)at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;
- (h)makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
GDPR Article 28(3)(a)–(h), quoted from the official text, read September 30, 2026. Point (a) is shortened at a semicolon; the full text continues with an exception for notifying the controller of a legal requirement.
The clause that changes after you sign
Point (d) refers back to paragraph 2, which governs the vendor bringing in another company, a sub-processor. It is the part of a DPA that moves: the vendor adds a name to a published list, and the clause decides what you can do about it.
The processor shall not engage another processor without prior specific or general written authorisation of the controller. In the case of general written authorisation, the processor shall inform the controller of any intended changes concerning the addition or replacement of other processors, thereby giving the controller the opportunity to object to such changes.
GDPR Article 28(2) — official text · read September 30, 2026
Vendors write the notice and the objection period into their own DPAs. This is one of them:
Customer may object to the use of such additional Sub-processor within 30 days of receiving notice of the change by following the instructions set forth in the Sub-Processor List or by contacting privacy@openai.com.
OpenAI — https://openai.com/policies/data-processing-addendum/ · read September 30, 2026 · snapshot 16626fe4e570
Some state what happens if you say nothing:
If Subscriber does not provide written objection within such five (5) calendar day period, the Subprocessor shall be deemed approved by Subscriber.
HiddenLayer — https://hiddenlayer.com/dpa · read September 7, 2026 · snapshot bd14b81487fd
We quote the objection period from 70AI vendors’ agreements; 25 of them state 30 days. Every window we hold is listed with its clause, and what a sub-processor is has its own page.
Where AI vendors publish their DPAs
We read 97 DPA pages and 100 sub-processor lists for 186 AI vendors, and keep a dated, hashed copy of each reading. Where each vendor publishes lists the addresses, and says plainly which vendors publish nothing we can read.
Common questions
- What is a DPA?
- A data processing agreement is the contract between a company that decides why and how personal data is processed (the controller, in GDPR terms) and a vendor that processes it on the company's behalf (the processor). GDPR Article 28(3) requires processing by a processor to be governed by such a contract.
- Is a DPA required?
- Under the GDPR, Article 28(3) says processing by a processor "shall be governed by a contract or other legal act". Under California law, Civil Code §1798.100(d) requires a business that discloses personal information to a service provider or contractor to enter into an agreement with it.
- What must a DPA contain?
- GDPR Article 28(3) lists what the contract must set out and stipulate, including that the processor acts only on documented instructions, keeps the data confidential, respects the conditions for engaging another processor, and deletes or returns the data at the end of the service.
- What does a DPA say about sub-processors?
- Article 28(2) lets a processor engage another processor only with the controller's specific or general written authorization, and under general authorization the processor must inform the controller of changes, giving it the opportunity to object. A vendor's DPA sets out how that notice is given and how long the customer has to object.
- Can a vendor change its DPA?
- Vendors publish their DPAs and sub-processor lists as web pages and can edit them. Xither keeps a dated, hashed copy of each reading of these pages for the AI vendors it watches, and records when one changes.
What this page is not
It is not legal advice. It quotes the law and published agreements on the dates shown; a negotiated contract may say something else, and it governs.
Xither Staff Writer · reviewed September 30, 2026. Vendor clauses and counts are generated from the record when the page is served.