Home/Glossary/DPA Agreement
Glossary · DPA Agreement

Data Processing Agreement (DPA): A Global Hiring Guide

A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor that sets out how personal data is handled, protected, and returned or deleted when the work is done. For companies hiring internationally, DPAs are not optional paperwork - they are a legal requirement in most markets and a direct part of how Employer of Record arrangements, cross-border payroll, and global HR platforms are governed. Getting them wrong exposes you to regulatory fines, data breach liability, and failed vendor relationships across multiple jurisdictions.

Nikolina RistoskaReviewed by Nikolina Ristoska · Head of Operations · Updated July 2026

What a DPA actually does

A DPA defines the relationship between two parties:

  • Data controller - the company that decides why and how personal data is processed (typically the employer or client).
  • Data processor - the third party that processes data on the controller's behalf (an EOR provider, payroll platform, ATS vendor, background check service, etc.).

The agreement sets the rules: what data is processed, for what purpose, with what security measures, for how long, and what happens when something goes wrong. It also covers whether the processor can appoint sub-processors, how data crosses borders, and what audit rights the controller holds.

Without a DPA, the controller retains all liability for whatever the processor does with the data, even if the processor causes the breach.

Why DPAs are a global hiring concern, not just a European one

The GDPR (EU, May 2018) made Article 28 DPAs well-known, but the requirement now appears in data protection law across dozens of countries. Any company building a distributed workforce will encounter multiple, sometimes conflicting, DPA obligations.

Region / Law DPA equivalent required? Key difference from GDPR
EU / EEA (GDPR) Yes - Article 28 mandates a written contract Strictest baseline; fines up to 4% of global annual revenue or €20 million
UK (UK GDPR) Yes - mirrored Article 28 requirement Post-Brexit transfers require UK-specific SCCs or addendums
Brazil (LGPD) Yes - contract between controller and operator required Terminology differs: "operator" instead of "processor"
India (DPDPA 2023) Yes - written contract with data fiduciary obligations Cross-border transfer rules still being finalized by regulation
Canada (PIPEDA / Bill C-27) De facto yes - accountability principle requires oversight of processors Less prescriptive on contract format
US (state-level: CCPA/CPRA, etc.) Yes for covered businesses - "service provider" contracts required No single federal law; requirements vary by state and sector
Australia (Privacy Act) Expected - APP 8 governs cross-border disclosure; contracts recommended Reform proposals would make written contracts mandatory

When you hire in five countries, you may need five DPAs that each satisfy a different legal framework, even with the same EOR provider.

DPAs and EOR arrangements

An Employer of Record sits in an unusual position in the data controller/processor picture. Depending on the jurisdiction and the contract structure, an EOR may act as:

  • A joint controller - because the EOR independently determines how it processes payroll, tax filings, and employment records under local law.
  • A data processor - for candidate data or HR system data the client company passes to it.
  • An independent controller - for data it collects from employees directly to meet its own legal obligations (e.g., tax registrations, social insurance).

This layered relationship means a single DPA may not be enough. A well-structured EOR engagement typically includes a DPA and a joint-controller agreement or a clear contractual delineation of each party's independent obligations under local law.

Before signing with any EOR, ask specifically: "Are you acting as a processor, a joint controller, or both? Which agreement governs each data type?" Providers that cannot answer clearly represent a compliance risk.

Cross-border data transfer mechanisms

A DPA governs how data is handled. A separate but related question is whether the transfer of personal data across borders is lawful in the first place. The two tools work together.

  • Standard Contractual Clauses (SCCs) - EU-approved contract modules for transfers from the EEA to countries without an adequacy decision. The 2021 SCCs replaced older versions and include a processor-to-processor module relevant to EOR sub-processor chains.
  • UK International Data Transfer Agreements (IDTAs) - UK equivalent of SCCs, required for UK-origin data.
  • Adequacy decisions - Where the EU or UK has decided a country provides equivalent protection (e.g., Japan, South Korea, New Zealand), transfers can proceed without SCCs, though a DPA is still required.
  • Binding Corporate Rules (BCRs) - Used within multinational groups; less common in EOR structures.

When your EOR processes payroll data for employees in Germany but routes it through servers in the United States, that transfer needs both a lawful transfer mechanism and a DPA. Check whether your EOR's standard DPA includes the current SCC modules as an annex.

What a DPA must contain

GDPR Article 28 is the most detailed public checklist for DPA content. Most other laws reference similar elements. A valid DPA should cover:

  1. Subject matter and duration - what processing is covered and when the agreement ends or is renewed.
  2. Nature and purpose of processing - what the processor does with the data and why.
  3. Types of personal data - for global hiring this typically includes name, national ID, bank details, tax numbers, salary, health data (where benefits are involved), immigration status.
  4. Categories of data subjects - employees, contractors, job applicants, dependants (relevant where family visas or benefits are involved).
  5. Processor obligations - process only on documented instructions; keep data confidential; implement appropriate security; assist with data subject rights requests; notify breaches; delete or return data at contract end.
  6. Sub-processor rules - prior written authorization required; same obligations imposed on sub-processors; controller notified of changes.
  7. Security measures - technical and organizational measures, typically set out in an annex (encryption standards, access controls, penetration testing cadence, etc.).
  8. Data transfer provisions - lawful mechanism for any transfer outside the originating jurisdiction.
  9. Audit rights - the controller's right to audit or receive third-party audit reports (ISO 27001, SOC 2, etc.).
  10. Breach notification timeline - GDPR requires notification to the controller without undue delay; many contracts specify 24 or 48 hours to allow the controller to meet its own 72-hour reporting obligation to regulators.

Sub-processors: the hidden risk in global HR stacks

Global EOR providers and HR platforms rarely run all their infrastructure themselves. A single EOR may use sub-processors for payroll calculation, cloud hosting, identity verification, background screening, and benefits administration. Each of those sub-processors handles your employees' personal data.

Under GDPR and similar laws, the controller (you) remains liable for sub-processor failures if you did not properly authorize the sub-processor chain in the DPA. Ask every EOR and HR platform for their current sub-processor list and a process for how they notify you of changes. If they cannot produce one, treat that as a due-diligence red flag.

When you need a DPA in global hiring

Any time a third party touches personal data belonging to your employees or candidates in another country, a DPA is likely required. Common triggers in international hiring include:

  • Engaging an Employer of Record to hire workers in a foreign market.
  • Using a global payroll platform that processes salary and tax data across borders.
  • Running background checks on candidates in countries with their own data protection regimes (Germany, France, and others place restrictions on the type and scope of checks permitted).
  • Using an applicant tracking system (ATS) hosted outside the candidate's country.
  • Administering employee benefits through a third-party broker or insurer in another jurisdiction.
  • Using workforce management or productivity monitoring tools where employees are based in the EU.
  • Transferring employee data to a parent company in another country (even within a corporate group, transfers require a lawful basis and usually a DPA or BCR).

What happens if no DPA is in place

Regulators have demonstrated they will act on missing or deficient DPAs, not just on data breaches. Documented consequences include:

  • Regulatory fines - GDPR fines for Article 28 violations have been issued by authorities in multiple EU member states. The maximum is €20 million or 4% of global annual turnover, whichever is higher. Brazil's LGPD and India's DPDPA carry their own penalty structures.
  • Supervisory orders - Regulators can order you to stop using a vendor entirely until a compliant DPA is in place. For a company relying on an EOR to employ workers in a given country, that is an operational emergency.
  • Unlimited controller liability - Without a DPA, there is no contractual allocation of fault. If the processor causes a breach, you carry the regulatory exposure because you failed to bind them to proper obligations.
  • Employee claims - In the EU and UK, data subjects (including your employees) can bring civil claims for material and non-material damage caused by data protection violations.
  • Lost vendor relationships - Enterprise clients and publicly listed companies increasingly require evidence of DPAs as part of vendor onboarding. Missing DPAs can cost you contracts.

Practical steps before signing with an EOR or HR vendor

  1. Ask for the vendor's standard DPA before contract discussions start. A reputable provider will have one ready.
  2. Map which countries' laws apply based on where your employees sit, where the vendor is headquartered, and where data is stored or processed.
  3. Check whether the DPA includes current SCC modules (2021 version for EU data) or equivalent transfer mechanisms for each relevant jurisdiction.
  4. Request the sub-processor list and confirm it is kept current with a notification process for additions.
  5. Verify breach notification timelines allow you enough time to meet your own reporting obligations (72 hours under GDPR).
  6. Confirm audit rights: at a minimum, the vendor should provide annual third-party audit reports such as ISO 27001 or SOC 2 Type II.
  7. Have local legal counsel review the DPA for any country where you have significant employee numbers or elevated regulatory risk.
  8. Record the signed DPA in your vendor register and set a review date tied to contract renewal or regulatory changes.
Agreement type What it covers Relationship to DPA
DPA (Data Processing Agreement) How personal data is processed by a third party on your behalf The core document
Joint Controller Agreement Shared responsibilities when two parties each determine processing purposes Used alongside or instead of a DPA where both parties are controllers
Standard Contractual Clauses (SCCs) Lawful mechanism for transferring personal data outside the EEA Often appended to or incorporated into a DPA
NDA / Confidentiality Agreement Restricts disclosure of business information Separate; does not satisfy data protection law requirements
Master Services Agreement (MSA) Commercial terms of the vendor relationship Does not replace a DPA; both are needed

A general service contract or NDA does not substitute for a DPA. Regulators and courts have been consistent on this point: data protection obligations must be addressed in a dedicated agreement that meets the substantive requirements of the applicable law.

Put this term to work

Reading up on EOR terminology usually means a hiring decision is close. These are the pages that help you make it.

About the author
Nikolina Ristoska
Head of Operations at EOR Overview

Building creative solutions and fostering global connections has been a rewarding part of my career. With a background in 2D/3D design and business development, I’ve been fortunate to work on projects that blend creativity and strategy, helping businesses grow and improve their operations in a connected world.

I’m also proud to contribute to Employ Borderless and EOR Overview, platforms designed to make international hiring less daunting. By sharing insights about remote hiring, EOR solutions, and global compliance, I aim to help businesses better understand the complexities of cross-border employment and make more informed decisions.
Over the years, my roles in client management, operations, and partnerships have taught me the importance of listening, problem-solving, and adapting to diverse needs. I’m passionate about simplifying processes and finding practical solutions that make a difference.

Key Skills and Expertise:

  • Business development and partnership building

  • Client management and operations

  • Creative strategy (2D/3D design, branding, and storytelling)

  • Cross-border collaboration and team leadership

  • Process optimization and efficiency

  • Global market strategy and analysis

  • Remote work infrastructure and best practices

View profile