GDPR Data Processing Agreements (DPA) Explained for Marketers

Reading time: 1 minutes | Compliance Guide | Updated: 9/3/2026

Every real vendor relationship needs a proper GDPR data processing agreement in place here's what to check before you sign one.

Every marketing tool that processes personal data on your behalf your email platform, your CRM, your ad platforms, your analytics tools — needs a Data Processing Agreement in place. Most vendors already have one ready to go, but "a DPA exists" and "the DPA actually covers what you need" are different things. This guide is about the second part.

1. Controller vs. processor why this matters

Under GDPR, the controller decides why and how personal data is processed for most marketing activities, that's your business. A processor processes data on the controller's behalf and instructions your email service provider, ad platform, or analytics tool, in most configurations. Article 28 requires a written contract (the DPA) whenever a controller uses a processor, setting out exactly what the processor can and can't do with the data.

Some vendors act as controllers for parts of their own service (for example, an ad platform using your data for its own product improvement) — in that case a DPA alone isn't the right document; check whether the vendor's terms describe a joint-controller or independent-controller relationship for that specific use, which carries different obligations than a straightforward processor relationship.

2. What Article 28 requires a DPA to actually contain

A compliant DPA needs to specify, at minimum:

  • The subject matter, duration, nature, and purpose of the processing, and the categories of data and data subjects involved.
  • That the processor only processes data on documented instructions from the controller.
  • Confidentiality commitments for anyone with access to the data.
  • Security measures appropriate to the risk (referencing Article 32).
  • Terms for engaging sub-processors, including a requirement to flow down the same obligations.
  • Assistance obligations helping the controller respond to data subject rights requests and data breaches.
  • Deletion or return of data at the end of the engagement.
  • The processor's cooperation with audits and provision of information demonstrating compliance.

A one-paragraph "we comply with GDPR" clause buried in a vendor's general terms of service is not a DPA, even if the vendor calls it one.

3. Check the sub-processor list, not just the headline vendor

Most marketing tools rely on their own sub-processors cloud hosting, customer support tooling, analytics-on-analytics. A proper DPA discloses these (often via a linked, maintained sub-processor list) and requires the vendor to notify you of changes, ideally with a chance to object. If a vendor's DPA doesn't mention sub-processors at all, that's a gap worth asking about directly.

4. Cross-border transfer terms belong in or alongside the DPA

If the vendor processes data outside the EEA (most US-headquartered marketing tools do), the DPA or an attached transfer addendum needs to specify the transfer mechanism: Standard Contractual Clauses, an adequacy decision, or EU-US Data Privacy Framework certification for participating US companies. See the Cross-Border Data Transfers guide in this hub for what each of these actually means in practice.

5. Standard vendor DPAs vs. negotiated terms

For most SaaS marketing tools at typical SME scale, the vendor's standard, non-negotiable DPA (often auto-accepted alongside the terms of service, or available as a self-serve document in account settings) is the realistic path large platforms like Google, Meta, and major email providers won't individually negotiate terms for a small account. What you can and should do: actually read it, confirm it covers the six Article 28 requirements above, and keep a record of which version you agreed to and when.

6. Building an internal DPA inventory

A simple, practical control most marketing teams are missing: a single list of every tool that processes personal data, whether a signed/accepted DPA is on file, the date, and the sub-processor/transfer notes. This becomes the answer to "can you demonstrate your vendor compliance" during an audit or a data subject access request that touches third-party tools see the Data Subject Access Requests guide for how vendor data fits into fulfilling a request.

Checklist before adding a new marketing tool

  • Confirm whether the vendor is a processor, a joint controller, or an independent controller for your specific use case.
  • Locate and read the actual DPA not just the marketing page that says "GDPR compliant."
  • Confirm it covers all six Article 28 elements listed above.
  • Check the sub-processor list and transfer mechanism for non-EEA processing.
  • Log it in your internal DPA inventory with the date accepted.
This guide is general information, not legal advice. For high-risk vendor relationships or non-standard data flows, have a qualified data protection professional review the actual DPA text before signing.

See how Adverizeo handles GDPR compliance for vendor data, or view pricing.

Loading full guide...