A data processing agreement, or DPA, is a legally binding contract between a data controller and a data processor that defines how personal data will be handled, protected, and used on the controller's behalf.
Under GDPR, any time an organization (the controller) hands personal data to a third party (a processor, like a cloud host, analytics vendor, or SaaS tool) to process on its behalf, a DPA is required by Article 28 - it isn't optional paperwork, it's a legal precondition for that processing to be lawful. The DPA specifies the scope and purpose of processing, security obligations, sub-processor rules, breach notification timelines, and what happens to the data when the relationship ends.
DPAs are the mechanism that makes a vendor a tracked "subprocessor" in a company's own compliance register - every new vendor that touches personal data needs a signed DPA before that data flows to them, not after. This is also why international transfers matter alongside DPAs: if the processor is outside the EEA, the DPA needs to reference a valid transfer mechanism like Standard Contractual Clauses.
A DPA doesn't replace security practices - it obligates them contractually, but the processor still has to actually implement encryption, access controls, and breach response to meet what the DPA requires.
Every subprocessor Neotask sends personal data to - email providers, LLM vendors, cloud infrastructure - has a signed DPA tracked in the compliance DPA tracker before any tenant data is permitted to flow to it, and adding a new vendor requires that DPA to be in place in the same change that enables the integration.
$0/mo
Download without a card and start for free.
$50/mo
The full personal agent platform for one person.
$100/mo
One company workspace with room to add your team.
$200/mo
Multiple workspaces and capacity for larger teams.
Explore: Integrations · Skills · Solutions · Use cases · Examples · Comparisons · Templates · Blog · Docs