Data Processing Agreement (DPA)
As of 2026-07-24T14:00:00Z
What is Data Processing Agreement (DPA)?
A DPA is a legal precondition, not an option — operating without one in 2026 exposes both parties to fines up to 4% of global turnover or €20M.
A Data Processing Agreement is the contract that turns an SAP analytics engagement from a data-protection risk into a documented, defensible arrangement. Under GDPR Article 28, any consultant who accesses or processes personal data on a client's behalf — and personal data in SAP analytics work is far broader than most consultants assume, covering employee master data, customer records, sales pipeline entries, support tickets, essentially any field that could identify a natural person — is legally a processor, and a processor working without a signed DPA is operating outside the law. The exposure is not theoretical: administrative fines under GDPR reach four percent of global annual turnover or twenty million euros, whichever is higher, and that ceiling applies to the controller, which is precisely why controllers now refuse to onboard a consultant who cannot produce a DPA before data access begins.
Article 28 specifies eight mandatory contents, and a genuinely useful DPA addresses all of them rather than using boilerplate that nods at each without substance: subject matter and duration of processing; nature and purpose of processing; the categories of personal data and data subjects involved; the controller's obligations and rights; the processor's obligations, covering security measures, confidentiality, sub-processor controls, assistance with data-subject rights requests, breach notification, and end-of-processing data handling; audit rights for the controller; sub-processor authorisation terms; and the jurisdictional mechanism governing any international transfer of the data.
When a full DPA is required versus when a lighter clause suffices
Why it matters
- Article 28 mandates eight specific contents in every DPA, from processing scope to sub-processor authorisation and international-transfer compliance.
- Breach-notification timing is engineered backward from GDPR's 72-hour authority-notification rule — B2B contracts typically require the processor to notify within 24-48h.
- Sub-processor scope is a live dispute point — Tier-1 firms typically count junior consultants as sub-processors, solo consultants often don't but should clarify.
Key points
- GDPR Art. 28 mandates DPA for all controller-processor relationships touching EU personal data.
- Eight mandatory contents: subject/duration · nature/purpose · data types · controller obligations · processor obligations · audit rights · sub-processor auth · transfer compliance.
- Five most-disputed clauses: sub-processor scope · audit rights · breach notification · Schrems-II · cessation.
- Schrems-II requires SCCs 2021 + TIA + supplementary technical measures for non-EEE transfers.
- Breach notification chain: processor → controller 24-48h, enables controller's 72h Art. 33 obligation.
- Audit rights typical: 3-5 day notice on-site / 24h remote; full refusal fails procurement.
- FR clients > €100k expect bilingual FR/EN + CNIL-aligned vocabulary (responsable / sous-traitant).
- Own reusable template (€500-1k lawyer cost) saves 4-6 weeks per engagement vs custom.
- Data Processing Agreement (DPA) is mastered only when it changes a named buyer decision.
- Start with the semantic contract and control model before demonstrating the tool.
Terms used on this page
- Data Processing Agreement (DPA)
- Contract governing how a processor handles personal data on behalf of a controller. Mandated by GDPR Art. 28.
- Controller / Responsable du traitement
- Entity determining purposes and means of personal-data processing. Usually the client.
- Processor / Sous-traitant
- Entity processing data on behalf of the controller. Usually the consultant.
- Sub-processor
- Entity engaged by the processor to perform processing activities. Requires controller authorisation.
- Schrems-II
- 2020 CJEU ruling invalidating EU-US Privacy Shield; requires case-by-case TIA + SCCs for non-EEE transfers.
- SCCs (Standard Contractual Clauses)
- EU Commission-approved contractual mechanism for personal-data transfers outside EEA. 2021 version current.
- TIA (Transfer Impact Assessment)
- Schrems-II-mandated case-by-case assessment of whether the transfer destination provides essentially equivalent EU-level data protection.
- TOMs (Technical and Organisational Measures)
- GDPR Art. 32 security measures annex; typically aligned with ISO 27001:2022.
Sources
- GDPR Article 28 (eur-lex)
- CNIL — Commission Nationale Informatique et Libertés
- EU Commission Standard Contractual Clauses 2021
- EDPB Schrems-II supplementary measures guidance
- Eursap freelance contracting patterns + DPA templates
- SAP News Center — Accelerate the Autonomous Enterprise with SAP Business Data Cloud
- SAP News Center — SAP Unveils the Autonomous Enterprise
- SAP News Center — The Future of the Enterprise Is Autonomous
- SAP Datasphere — Help Portal
- SAP Datasphere — official product page
- SAP Analytics Cloud — Help Portal
- SAP Analytics Cloud — official product page
- SAP BW/4HANA — Help Portal
- SAP S/4HANA — Help Portal
- SAP News Center
- SAP Community
- SAP — industries overview
- EFRAG — CSRD/ESRS standards
- Gartner — research & analyst site
- BARC — BI & Analytics research
- TDWI — data & analytics research
- DSAG — German-speaking SAP user group
- ASUG — Americas' SAP User Group
- Databricks — official site
- EU AI Act Service Desk — implementation timeline
Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.