Skip to content
Find my data room
Data room terms / Security and compliance

Data processing agreement (DPA)

The short version

The contract annex in which the room vendor promises how it will treat personal information on your behalf: safeguards, who else it may use, cross-border moves and deletion at the end.

How it plays out on a deal

For a data room, the seller is usually the controller and the room provider a processor. The DPA covers security measures, sub-processors, breach notification, transfers abroad and deletion at the end of the contract.

Most established vendors publish a standard DPA. Buyers in regulated sectors sometimes need changes, such as shorter breach notification times or a fixed sub-processor list, so it helps to ask early whether the vendor negotiates its DPA and on which plans.

What to check in a review or demo

  1. 1Whether a standard DPA is published and signed as part of the order.
  2. 2The breach notification period and the sub-processor list.
  3. 3How data is deleted at the end of the contract and whether deletion is confirmed in writing.

Read alongside

Where this comes up on Data Room Review