Governance & Compliance
DPA (Data Processing Agreement)
A DPA is the contract governing how a vendor processes personal data on your behalf — purposes, security, subprocessors, breach duties. No DPA, no regulated data.
A data processing agreement binds a processor to handle personal data only on the customer's instructions, with defined security measures, subprocessor rules, breach notification, and deletion duties. GDPR requires one whenever a processor is used; Canadian and US frameworks expect equivalent contractual safeguards.
For AI tools, the DPA is a tier marker: enterprise plans come with one, consumer accounts don't. An employee using a personal AI account processes company personal data with no DPA in place — one of the cleanest ways to explain shadow-AI risk to a regulator-minded audience.
Where this shows up
Related terms
See it in your own organization.
Sanitized AI inventories the AI tools in use and redacts sensitive data from prompts before it leaves.