Glossary
DPA (Data Processing Agreement)
A data processing agreement (DPA) is a contract under Art. 28 GDPR between a controller and a processor that handles personal data on the controller's behalf. It defines the subject, duration, nature, and purpose of processing as well as technical and organizational measures. SMEs need one whenever external providers such as cloud or AI services process personal data for them.
Last updated: 2026-08-03
The GDPR distinguishes between the controller, who decides on the purposes and means of processing, and the processor, who handles data only on the controller's instructions. Art. 28 GDPR prescribes what a DPA must cover at minimum: processing on documented instructions, confidentiality obligations, technical and organizational measures, the handling of sub-processors, support with data subject rights and breach notifications, and deletion or return of data when the contract ends. Without this contract, both sides are in breach of the GDPR – even if the processing itself is flawless.
In day-to-day business, this affects more tools than many expect: cloud storage, newsletter services, payroll, ticketing systems, and AI applications that process emails or documents containing customer data. Before adopting a new tool, SMEs should therefore check whether the provider offers a DPA, which sub-processors it uses, and where the data is processed. A trustworthy provider answers these questions openly, without making you dig for them.
Chifty provides a DPA under Art. 28 GDPR for business use – you receive it on request or when signing the contract. The full sub-processor list with purpose and location per provider is part of the agreement and also publicly available on the security page. With Google Cloud Vertex AI and OpenAI, it is contractually agreed that requests are not retained after processing.
On top of that comes a principle that goes beyond the contract text: the AI must not bypass permissions. Answers draw only on sources the asking person is authorized to see, with citations shown – the permission filter is applied inside the search itself, before a result exists.