What It Does
A data protection clause, frequently a standalone data processing agreement (DPA), governs how one party processes personal data on another's behalf. It assigns the controller and processor roles, limits the processor to the controller's documented instructions, and requires confidentiality, security measures, sub-processor controls, breach notification, and assistance with data-subject requests. For transfers out of the EEA or UK, it incorporates the Standard Contractual Clauses. GDPR Article 28 makes most of these terms mandatory whenever a processor handles personal data, so the DPA is less negotiable on substance and more about scope, liability, and the sub-processor and audit mechanics.
Assigns controller and processor roles and limits processing to documented instructions
Requires confidentiality, security measures, and assistance with data-subject requests
Controls the use of sub-processors and the right to object to new ones
Sets breach-notification duties and timing
Governs international transfers, incorporating the Standard Contractual Clauses
As US state privacy laws proliferate, DPAs increasingly map a single set of obligations to both GDPR processor duties and CCPA service-provider terms.
When You'll See It
The data protection clause appears in SaaS and cloud agreements, service agreements and SLAs, vendor and outsourcing contracts, marketing and analytics deals, research collaborations, and transition services agreements. It is usually a standalone DPA attached to the main contract, with the Standard Contractual Clauses as an addendum for cross-border transfers. It is most heavily negotiated in enterprise SaaS, where sub-processor lists, audit rights, and breach-liability caps are the live issues.
It matters most wherever a vendor touches personal data the customer is responsible for, such as a cloud platform, a payroll provider, or an analytics tool. The more personal data a vendor processes, the more the DPA carries the privacy-compliance load.
Examples
Relativity ODA LLC / KLDiscovery Ontrack, LLC
Data Processing Agreement
Controller-processor: documented instructions
Mutual
2023
"The processor shall process personal data only on documented instructions from the controller, unless required to do so by Union or Member State law to which the processor is subject. In this case, the processor shall inform the controller of that legal requirement[...]"
Relativity ODA LLC / KLDiscovery Ontrack, LLC
Data Processing Agreement
Sub-processor authorization
Mutual
2023
"The processor has the controller's general authorisation for the engagement of sub-processors from an agreed list. The processor shall specifically inform in writing the controller of any intended changes of that list through the addition or replacement of sub-processors at least 30[...]"
Alliance Data Systems Corporation / Loyalty Ventures Inc.
Transition Services Agreement
Documented instructions + EEA transfer
Mutual
2021
"[the processor shall process the personal data] for the sole purpose of providing the Services and only on documented instructions from the controller, including with regard to transfers of personal data outside the European Economic Area or to an international organization[...]"
Amgen Inc. / RBNC Therapeutics, Inc.
Research Collaboration and License Agreement
Personal Information + third-country transfer
Mutual
2021
"[the Processing Party shall:] (i) process the Personal Information only on documented instructions from the controller and in accordance with applicable Law, including with regard to transfers of Personal Information to a third country or an international organization[...]"
Negotiate
Customer, you want protection
Bind the processor to your documented instructions and bar any other use of the data.
Require advance notice and a right to object before any new sub-processor is added.
Set a short, fixed breach-notification window, measured in hours where you can get it.
Keep meaningful audit rights and require deletion or return of data on termination.
Incorporate the current Standard Contractual Clauses for any transfer outside the EEA or UK.
Get an indemnity for losses caused by the processor's breach of the DPA or of privacy law, sitting outside (or carved out of) the general liability cap.
Vendor, you want workable terms
Limit instructions to the documented scope and charge for work beyond it.
Use a general sub-processor authorization with a notice-and-object process, not per-vendor consent.
Tie breach notification to "without undue delay" after confirmation, not on mere suspicion.
Scope audits to once a year on notice, or to a third-party report.
Cap data-protection liability and align it with the agreement's overall liability terms.
Most of a DPA is fixed by law. Spend your time on sub-processors, breach timing, and who pays when data leaks.
Red Flags
A processor permitted to use the data for its own purposes, beyond the controller's instructions.
Sub-processors allowed with no notice or right to object, so your data moves to unknown vendors.
A vague breach-notification trigger or a long window that delays your own regulatory deadlines.
No transfer mechanism for data leaving the EEA or UK, leaving cross-border processing non-compliant.
A data-protection liability carve-out or cap that leaves the controller exposed for the processor's breach.
FAQs
This content is for informational purposes only and does not constitute legal advice.



