A Data Processing Agreement is a legally significant document in United States, governed by the principles of applicable law within the common law legal system. This document establishes the rights, obligations, and responsibilities of the parties involved, ensuring legal compliance with the laws of United States. Under United States law, this type of document is regulated by Uniform Commercial Code (UCC) and Restatement (Second) of Contracts, which sets out the fundamental requirements for validity and enforceability.
The legal framework in United States imposes specific requirements on legal obligations and party rights. Parties entering into this arrangement must ensure compliance with mandatory provisions that cannot be waived by agreement. The document must clearly define compliance requirements, enforcement mechanisms, and dispute resolution in accordance with United States law. Failure to address these elements may render certain provisions unenforceable or expose the parties to legal liability.
In United States, electronic signatures are generally recognized under E-SIGN Act (15 U.S.C. 7001) and UETA. However, certain types of documents may require wet-ink signatures or additional formalities depending on the subject matter and jurisdiction. Notarization requirements vary by state; some documents require notarization for recording or enforcement. Parties should verify the specific requirements applicable to their situation to ensure the document meets all formal validity requirements under United States law.
Dispute resolution for matters arising from this document in United States may be pursued through federal and state courts, with arbitration under the Federal Arbitration Act (9 U.S.C. 1-16). The choice of dispute resolution mechanism should be clearly stated in the document to avoid uncertainty. Litigation in state and federal courts follows the procedural rules established by United States law, while alternative dispute resolution methods may offer faster and more cost-effective outcomes. The statute of limitations for related claims in United States is varies by state, typically 3-6 years for written contracts.
Consumer protection and privacy considerations are increasingly relevant in United States. Federal Trade Commission Act and state consumer protection statutes may apply to transactions involving consumers, imposing additional disclosure and fairness requirements. Data protection obligations under state privacy laws, CCPA (California), and sector-specific federal regulations must be considered when the document involves the collection or processing of personal information. Non-compliance with these regulations may result in significant penalties and reputational harm.
This template has been specifically drafted to comply with the legal requirements of United States. It incorporates the mandatory clauses and provisions required by local law, including all necessary legal references and formalities. The document addresses the specific regulatory framework applicable in United States, taking into account recent legislative changes and judicial interpretations that may affect the enforceability of its provisions.
While this template provides a solid legal foundation based on United States law, parties should consult with a qualified legal professional in United States to ensure the document meets their specific needs and complies with all applicable local requirements. Legal advice is particularly important for complex transactions, cross-border arrangements, or situations involving significant financial obligations or regulatory implications.
What Is a Data Processing Agreement?
A Data Processing Agreement (DPA) is a legally binding contract between a data controller (the organization that determines the purposes and means of processing personal data) and a data processor (a third party that processes personal data on behalf of the controller). The DPA establishes the processor's obligations regarding data security, confidentiality, breach notification, data subject rights, sub-processing, international data transfers, and the return or destruction of data upon termination.
DPAs are mandated by several privacy regulations. The EU General Data Protection Regulation (GDPR) Article 28 requires controllers to have a written contract with any processor that handles personal data on their behalf. The California Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), require businesses to enter into agreements with service providers that include specific contractual provisions about data use and protection under California Civil Code Section 1798.100 et seq. The Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), and other state privacy laws enacted since 2021 contain similar requirements.
The DPA is distinct from a privacy policy (which discloses data practices to consumers) and a data collection consent form (which obtains individual consent). Instead, it governs the business-to-business relationship regarding data handling. Without a DPA in place, both the controller and processor face regulatory enforcement, fines (up to 4% of annual global turnover under GDPR or $7,500 per intentional violation under CCPA), and civil liability for data breaches.
When Do You Need a Data Processing Agreement?
A Data Processing Agreement is required in the following situations: when a business uses a third-party cloud service provider (AWS, Google Cloud, Azure) to store or process customer personal data; when a company outsources payroll processing, HR functions, or benefits administration to a service provider; when a business uses a CRM platform, email marketing service, or analytics tool that processes customer data; when a healthcare organization shares protected health information (PHI) with a business associate, which also requires a HIPAA Business Associate Agreement; and when a company uses a third-party customer support, call center, or chat service that accesses personal data.
Additional scenarios include engaging IT consultants or managed service providers who access company systems containing personal data, using third-party payment processors that handle financial data, working with marketing agencies that manage customer databases, and contracting with data analytics firms that process behavioral or demographic data.
Operating without a DPA exposes both parties to significant legal risk. Under GDPR, the absence of a DPA is itself a violation of Article 28, independent of any actual data breach. Regulatory authorities have issued fines specifically for the failure to have adequate data processing agreements in place. In the United States, the FTC has taken enforcement action against companies that failed to contractually require adequate data protection from their service providers.
What to Include in Your Data Processing Agreement
A compliant Data Processing Agreement must include the following elements:
Subject matter and duration -- a description of the processing activities, the categories of personal data being processed, the categories of data subjects, and the duration of the processing.
Nature and purpose of processing -- the specific purpose for which the processor handles personal data (e.g., cloud storage, analytics, payment processing), and a restriction that the processor may not process the data for any other purpose.
Processor obligations -- the processor's duty to process data only on documented instructions from the controller, to maintain confidentiality, to implement appropriate technical and organizational security measures (as specified in GDPR Article 32), and to assist the controller in responding to data subject rights requests.
Sub-processing restrictions -- whether the processor may engage sub-processors, the requirement for prior written consent from the controller, the obligation to impose the same data protection requirements on sub-processors, and liability for sub-processor actions.
Security measures -- specific technical and organizational measures the processor must implement, including encryption, pseudonymization, access controls, regular security testing, and incident response procedures.
Breach notification -- the timeline and procedure for notifying the controller of a data breach (72 hours under GDPR Article 33), the information that must be included in the notification, and the processor's obligation to assist with breach investigation and remediation.
Data subject rights assistance -- the processor's obligation to assist the controller in fulfilling data subject requests for access, rectification, erasure, data portability, and restriction of processing.
International data transfers -- if data will be transferred outside the EEA (for GDPR) or outside the jurisdiction of origin, the legal mechanism for the transfer (Standard Contractual Clauses, adequacy decisions, binding corporate rules, or the EU-U.S. Data Privacy Framework).
Audit rights -- the controller's right to audit the processor's data protection practices, including on-site inspections and review of security certifications (SOC 2, ISO 27001).
Data return and deletion -- the processor's obligation to return or delete all personal data upon termination of the agreement, and certification of deletion upon request.
Liability and indemnification -- allocation of liability between controller and processor for data breaches, regulatory fines, and data subject claims.
Frequently Asked Questions
Related Documents
You may also find these documents useful:
Terms of Service
Running a website, app, or online platform? Your Terms of Service is the rulebook for everyone who uses it. It sets the ground rules — acceptable use, account responsibilities, payment terms, intellectual property rights, limitation of liability, and how you handle disputes. Without clear terms, you're leaving yourself open to abuse and lawsuits. Every serious online business needs one, and ours covers the essentials for modern platforms. Our free template is easy to customize. Fill in your details, preview, and download as PDF or Word — no account needed.
Privacy Policy
Running a website or app that collects any user data — even just an email for a newsletter? You legally need a Privacy Policy. It's not optional; regulations like GDPR and CCPA require you to tell users what data you collect, why you collect it, and how you protect it. Without one, you risk fines and lost trust. Our free template helps you cover data collection practices, cookie usage, third-party sharing, user rights, and contact information. Fill in the details, preview your policy, and download it as PDF or Word — no account needed.