Regulatory & compliance⏱ ~1 minEU

DPA

The data processing agreement GDPR Article 28 requires between a controller and a processor - regulates what the vendor is allowed to do with personal data.

A DPA (Data Processing Agreement, in Norwegian databehandleravtale) is a legally binding agreement GDPRGeneral Data Protection Regulation - EU's data protection regulation, applicable in Norway via the EEA Agreement. Article 28 requires whenever a controller (e.g. a power company) lets a third party (the processor, e.g. a software vendor) process personal data on its behalf. The agreement specifies the purpose of the processing, which data is involved, how long it is retained, which security measures apply, and what happens to the data when the agreement ends. Without a signed DPA, the processing is in principle unlawful under GDPR, regardless of how strong the technical security measures are.

RegulationSecurity