Privacy
Data processing agreement
Also called DPA, SCCs companion.
Data processing agreement is the contract between a controller and a processor that sets how personal data may be handled. GDPR Article 28 requires one.
How it is measured
A valid one states the subject, duration, nature, and purpose of processing, the data types, and the duties of each party. It requires processing only on instructions, confidentiality, security, subprocessor controls, help with requests, and deletion or return at the end.
Check by reading for each required element. A one-page "terms of service" paragraph about privacy rarely covers them all.
Worked example
A boutique agency hires an email platform. The vendor's DPA lists 11 subprocessors and gives 30 days' notice of changes. The agency finds it has no right to object, so it asks for one.
Without the DPA, a regulator would see a gap in the file for the entire contract period.
How it differs
A data processing agreement is the contract. A data controller is the party that signs it as the one giving instructions. The agreement excludes the decision about purposes; the controller's role excludes the proof in writing.
Common errors
Signing without reading subprocessors. Skipping the DPA for small vendors. Forgetting transfer terms. Leaving no deletion step. Assuming standard terms cover it.
In practice
List your vendors that handle personal data and mark which have a signed DPA. Request the missing ones. Calendar a review each year.