Data Processing Agreement (DPA)
As of 2026-10-05
What is Data Processing Agreement (DPA)?
A DPA is a legal precondition, not an option — operating without one in 2026 exposes both parties to fines up to 4% of global turnover or €20M.
What it is
A Data Processing Agreement is the contract that turns an SAP analytics engagement from a data-protection risk into a documented, defensible arrangement. Under GDPR Article 28, any consultant who accesses or processes personal data on a client's behalf — and personal data in SAP analytics work is far broader than most consultants assume, covering employee master data, customer records, sales pipeline entries, support tickets, essentially any field that could identify a natural person — is legally a processor, and a processor working without a signed DPA is operating outside the law. The exposure is not theoretical: administrative fines under GDPR reach four percent of global annual turnover or twenty million euros, whichever is higher, for breaches of the core principles and the international-transfer rules, and two percent or ten million euros for breaches of the controller and processor obligations of Articles 25-39, including Article 28 itself (Article 83(4)-(5)); both tiers can be imposed on controllers and processors, which is precisely why controllers now refuse to onboard a consultant who cannot produce a DPA before data access begins.
Why it matters
- Article 28 mandates eight specific contents in every DPA, from processing scope to sub-processor authorisation and international-transfer compliance.
- Breach-notification timing is engineered backward from GDPR's 72-hour authority-notification rule — B2B contracts typically require the processor to notify within 24-48h.
- Sub-processor scope is a live dispute point — Tier-1 firms typically count junior consultants as sub-processors, solo consultants often don't but should clarify.
Key points
- GDPR Art. 28 mandates DPA for all controller-processor relationships touching EU personal data.
- Eight mandatory contents: subject/duration · nature/purpose · data types · controller obligations · processor obligations · audit rights · sub-processor auth · transfer compliance.
- Five most-disputed clauses: sub-processor scope · audit rights · breach notification · Schrems-II · cessation.
- Schrems-II requires SCCs 2021 + TIA + supplementary technical measures for non-EEE transfers.
- Breach notification chain: processor → controller 24-48h, enables controller's 72h Art. 33 obligation.
- Audit rights typical: 3-5 day notice on-site / 24h remote; full refusal fails procurement.
- FR clients > €100k expect bilingual FR/EN + CNIL-aligned vocabulary (responsable / sous-traitant).
- Own reusable template (€500-1k lawyer cost) saves 4-6 weeks per engagement vs custom.
Terms used on this page
- Data Processing Agreement (DPA)
- Contract governing how a processor handles personal data on behalf of a controller. Mandated by GDPR Art. 28.
- Controller / Responsable du traitement
- Entity determining purposes and means of personal-data processing. Usually the client.
- Processor / Sous-traitant
- Entity processing data on behalf of the controller. Usually the consultant.
- Sub-processor
- Entity engaged by the processor to perform processing activities. Requires controller authorisation.
- Schrems-II
- 2020 CJEU ruling invalidating EU-US Privacy Shield; requires case-by-case TIA + SCCs for non-EEE transfers.
- SCCs (Standard Contractual Clauses)
- EU Commission-approved contractual mechanism for personal-data transfers outside EEA. 2021 version current.
- TIA (Transfer Impact Assessment)
- Schrems-II-mandated case-by-case assessment of whether the transfer destination provides essentially equivalent EU-level data protection.
- TOMs (Technical and Organisational Measures)
- GDPR Art. 32 security measures annex; typically aligned with ISO 27001:2022.
Sources
- GDPR Article 28 (eur-lex)
- EUR-Lex — Regulation (EU) 2016/679 (GDPR), Article 28 processor requirements
- SAP Help Portal — generative AI hub orchestration service (data masking, content filtering, grounding pipeline)
- AWS — AWS and SAP expand collaboration for SAP Business AI Platform, new regions (2026-09-18)
- EDPB — Guidelines 07/2020 on the concepts of controller and processor in the GDPR (what makes a consultant a processor; Art. 28 contract content)
- European Commission — Implementing Decision (EU) 2021/915 on standard contractual clauses between controllers and processors (ready-made Art. 28 DPA text)
- European Commission — Standard Contractual Clauses (SCC) hub (controller-processor and transfer SCCs)
- EDPB — Opinion 22/2024 on certain obligations following from reliance on processor(s) and sub-processor(s) (sub-processor chain duties)
- GDPR Article 28 — Processor (text of the eight mandatory contract elements; unofficial reproduction of the Regulation)
- GDPR Article 83 — Administrative fines (two-tier ceilings: 2 %/EUR 10m for Art. 28, 4 %/EUR 20m for principles and transfers; unofficial reproduction)
- GDPR Article 33 — Notification of a personal data breach (72-hour rule and processor duty to notify the controller)
- ICO — Contracts and liabilities between controllers and processors (UK GDPR guidance on required contract terms)
- European Commission — Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy Framework adequacy (transfers to certified US importers)
- CNIL — RGPD chapitre IV: responsable de traitement et sous-traitant (French regulator reading of processor obligations)
Full card available to members. What the full card adds: the full decision framework · the SAP vs Snowflake / Databricks / Fabric comparison · the common pitfalls and their fix · the cheat sheet · the architecture schemas · the code blocks · the facts worth quoting.