Glossary

DPA (Data Processing Agreement)

A data processing agreement (DPA) is a contract under Art. 28 GDPR between a controller and a processor that handles personal data on the controller's behalf. It defines the subject, duration, nature, and purpose of processing as well as technical and organizational measures. SMEs need one whenever external providers such as cloud or AI services process personal data for them.

Last updated: 2026-08-03

The GDPR distinguishes between the controller, who decides on the purposes and means of processing, and the processor, who handles data only on the controller's instructions. Art. 28 GDPR prescribes what a DPA must cover at minimum: processing on documented instructions, confidentiality obligations, technical and organizational measures, the handling of sub-processors, support with data subject rights and breach notifications, and deletion or return of data when the contract ends. Without this contract, both sides are in breach of the GDPR – even if the processing itself is flawless.

In day-to-day business, this affects more tools than many expect: cloud storage, newsletter services, payroll, ticketing systems, and AI applications that process emails or documents containing customer data. Before adopting a new tool, SMEs should therefore check whether the provider offers a DPA, which sub-processors it uses, and where the data is processed. A trustworthy provider answers these questions openly, without making you dig for them.

Chifty provides a DPA under Art. 28 GDPR for business use – you receive it on request or when signing the contract. The full sub-processor list with purpose and location per provider is part of the agreement and also publicly available on the security page. With Google Cloud Vertex AI and OpenAI, it is contractually agreed that requests are not retained after processing.

On top of that comes a principle that goes beyond the contract text: the AI must not bypass permissions. Answers draw only on sources the asking person is authorized to see, with citations shown – the permission filter is applied inside the search itself, before a result exists.

Frequently asked questions

What is a DPA?
A DPA (data processing agreement) is a contract under Art. 28 GDPR. It is required whenever a service provider processes personal data on a company's behalf, and it defines how that data is protected – from documented instructions and technical measures to deletion when the contract ends.
Why does an SME need a DPA?
As soon as an external service – cloud storage, a newsletter tool, or an AI application – processes personal data, the GDPR requires a DPA. Without one, both the company and the provider are in breach of the regulation, even if everything runs correctly on a technical level. The DPA is the contractual foundation of any work with data processors.
How do I get Chifty's DPA?
You receive the DPA under Art. 28 GDPR on request or when signing the contract. The sub-processor list with purpose and location per provider is also publicly available on Chifty's security page.