Sell · Data Processing Agreement
Do you need a DPA for this customer?
Start with the actual data flow and legal roles, not a template. Solvd is designed to connect supported DPA terms to the product, MSA, subprocessors, security commitments and jurisdictions that make the agreement necessary.
Privacy-law page. Controller/processor and business/service-provider roles, international transfers, regulated data and state-law requirements are fact-specific and require legal review when consequential.
Direct answer
A DPA is about the processing relationship—not just the presence of personal data.
The agreement should reflect who determines the purposes and means of processing, who processes on whose behalf, what data and people are involved, which laws and customer requirements apply, and what operational commitments the product can actually meet. Under GDPR Article 28, qualifying controller/processor relationships require a binding processing contract; California has separate service-provider/contractor contract requirements when the CCPA applies.
What to check
Map the data relationship before drafting the data terms.
- Customer / startup legal roles
- Data categories and data subjects
- Purpose, duration and instructions
- Security and confidentiality commitments
- Subprocessors and processing locations
- Deletion/return, assistance, audit and transfer terms
Company-context proof
The DPA cannot promise a data architecture the product does not have.
- Customer MSA promises EU-region hostingExisting promise
- DPA annex lists U.S.-only processing locationNew document
- Hosting / transfer terms conflictResolve before sign
The DPA should describe the data relationship the product actually has. Cross-check it against the MSA, security materials, subprocessors and product architecture before signing.
Contract stack
Read privacy terms with the commercial agreement.
SaaS agreement
Product and subscription terms that may contain data/security promises.
MSA
Master obligations, precedence and risk allocation that interact with the DPA.
Security + subprocessors
Operational facts the DPA should not contradict or overpromise.
Before / Next
Start from the data flow. End with obligations the company can perform.
Founder questions
Do not let “we handle personal data” collapse every privacy role into one answer.
When does a startup need a DPA?
It depends on the data, legal roles, jurisdictions and customer relationship. Under GDPR Article 28, processing by a processor on behalf of a controller must be governed by a qualifying contract. California’s CCPA regulations also impose contract requirements on service providers and contractors when those roles apply.
What should a DPA cover?
For a controller/processor relationship, common topics include processing subject matter and duration, purpose, data categories and data subjects, documented instructions, confidentiality, security, subprocessors, assistance with rights/compliance, deletion/return and audit or information rights. Other laws and customer requirements can add terms.
Is a DPA the same as a privacy policy?
No. A privacy policy is an external notice about an organization’s privacy practices. A DPA is a contract governing a data-processing relationship between parties.
Is a DPA the same as Standard Contractual Clauses?
No. A DPA addresses the processing relationship. EU Standard Contractual Clauses can be used for certain cross-border transfer mechanisms and can sit alongside or within broader data-processing terms.
Does every SaaS customer need a DPA?
No universal rule says every SaaS sale requires a separate DPA. The need depends on whether personal data is processed, each party’s legal role, applicable law, the master contract and the customer’s requirements.
Know → Do