What a DPA actually does
A DPA defines the relationship between two parties:
- Data controller - the company that decides why and how personal data is processed (typically the employer or client).
- Data processor - the third party that processes data on the controller's behalf (an EOR provider, payroll platform, ATS vendor, background check service, etc.).
The agreement sets the rules: what data is processed, for what purpose, with what security measures, for how long, and what happens when something goes wrong. It also covers whether the processor can appoint sub-processors, how data crosses borders, and what audit rights the controller holds.
Without a DPA, the controller retains all liability for whatever the processor does with the data, even if the processor causes the breach.
Why DPAs are a global hiring concern, not just a European one
The GDPR (EU, May 2018) made Article 28 DPAs well-known, but the requirement now appears in data protection law across dozens of countries. Any company building a distributed workforce will encounter multiple, sometimes conflicting, DPA obligations.
| Region / Law | DPA equivalent required? | Key difference from GDPR |
|---|---|---|
| EU / EEA (GDPR) | Yes - Article 28 mandates a written contract | Strictest baseline; fines up to 4% of global annual revenue or €20 million |
| UK (UK GDPR) | Yes - mirrored Article 28 requirement | Post-Brexit transfers require UK-specific SCCs or addendums |
| Brazil (LGPD) | Yes - contract between controller and operator required | Terminology differs: "operator" instead of "processor" |
| India (DPDPA 2023) | Yes - written contract with data fiduciary obligations | Cross-border transfer rules still being finalized by regulation |
| Canada (PIPEDA / Bill C-27) | De facto yes - accountability principle requires oversight of processors | Less prescriptive on contract format |
| US (state-level: CCPA/CPRA, etc.) | Yes for covered businesses - "service provider" contracts required | No single federal law; requirements vary by state and sector |
| Australia (Privacy Act) | Expected - APP 8 governs cross-border disclosure; contracts recommended | Reform proposals would make written contracts mandatory |
When you hire in five countries, you may need five DPAs that each satisfy a different legal framework, even with the same EOR provider.
DPAs and EOR arrangements
An Employer of Record sits in an unusual position in the data controller/processor picture. Depending on the jurisdiction and the contract structure, an EOR may act as:
- A joint controller - because the EOR independently determines how it processes payroll, tax filings, and employment records under local law.
- A data processor - for candidate data or HR system data the client company passes to it.
- An independent controller - for data it collects from employees directly to meet its own legal obligations (e.g., tax registrations, social insurance).
This layered relationship means a single DPA may not be enough. A well-structured EOR engagement typically includes a DPA and a joint-controller agreement or a clear contractual delineation of each party's independent obligations under local law.
Before signing with any EOR, ask specifically: "Are you acting as a processor, a joint controller, or both? Which agreement governs each data type?" Providers that cannot answer clearly represent a compliance risk.
Cross-border data transfer mechanisms
A DPA governs how data is handled. A separate but related question is whether the transfer of personal data across borders is lawful in the first place. The two tools work together.
- Standard Contractual Clauses (SCCs) - EU-approved contract modules for transfers from the EEA to countries without an adequacy decision. The 2021 SCCs replaced older versions and include a processor-to-processor module relevant to EOR sub-processor chains.
- UK International Data Transfer Agreements (IDTAs) - UK equivalent of SCCs, required for UK-origin data.
- Adequacy decisions - Where the EU or UK has decided a country provides equivalent protection (e.g., Japan, South Korea, New Zealand), transfers can proceed without SCCs, though a DPA is still required.
- Binding Corporate Rules (BCRs) - Used within multinational groups; less common in EOR structures.
When your EOR processes payroll data for employees in Germany but routes it through servers in the United States, that transfer needs both a lawful transfer mechanism and a DPA. Check whether your EOR's standard DPA includes the current SCC modules as an annex.
What a DPA must contain
GDPR Article 28 is the most detailed public checklist for DPA content. Most other laws reference similar elements. A valid DPA should cover:
- Subject matter and duration - what processing is covered and when the agreement ends or is renewed.
- Nature and purpose of processing - what the processor does with the data and why.
- Types of personal data - for global hiring this typically includes name, national ID, bank details, tax numbers, salary, health data (where benefits are involved), immigration status.
- Categories of data subjects - employees, contractors, job applicants, dependants (relevant where family visas or benefits are involved).
- Processor obligations - process only on documented instructions; keep data confidential; implement appropriate security; assist with data subject rights requests; notify breaches; delete or return data at contract end.
- Sub-processor rules - prior written authorization required; same obligations imposed on sub-processors; controller notified of changes.
- Security measures - technical and organizational measures, typically set out in an annex (encryption standards, access controls, penetration testing cadence, etc.).
- Data transfer provisions - lawful mechanism for any transfer outside the originating jurisdiction.
- Audit rights - the controller's right to audit or receive third-party audit reports (ISO 27001, SOC 2, etc.).
- Breach notification timeline - GDPR requires notification to the controller without undue delay; many contracts specify 24 or 48 hours to allow the controller to meet its own 72-hour reporting obligation to regulators.
Sub-processors: the hidden risk in global HR stacks
Global EOR providers and HR platforms rarely run all their infrastructure themselves. A single EOR may use sub-processors for payroll calculation, cloud hosting, identity verification, background screening, and benefits administration. Each of those sub-processors handles your employees' personal data.
Under GDPR and similar laws, the controller (you) remains liable for sub-processor failures if you did not properly authorize the sub-processor chain in the DPA. Ask every EOR and HR platform for their current sub-processor list and a process for how they notify you of changes. If they cannot produce one, treat that as a due-diligence red flag.
When you need a DPA in global hiring
Any time a third party touches personal data belonging to your employees or candidates in another country, a DPA is likely required. Common triggers in international hiring include:
- Engaging an Employer of Record to hire workers in a foreign market.
- Using a global payroll platform that processes salary and tax data across borders.
- Running background checks on candidates in countries with their own data protection regimes (Germany, France, and others place restrictions on the type and scope of checks permitted).
- Using an applicant tracking system (ATS) hosted outside the candidate's country.
- Administering employee benefits through a third-party broker or insurer in another jurisdiction.
- Using workforce management or productivity monitoring tools where employees are based in the EU.
- Transferring employee data to a parent company in another country (even within a corporate group, transfers require a lawful basis and usually a DPA or BCR).
What happens if no DPA is in place
Regulators have demonstrated they will act on missing or deficient DPAs, not just on data breaches. Documented consequences include:
- Regulatory fines - GDPR fines for Article 28 violations have been issued by authorities in multiple EU member states. The maximum is €20 million or 4% of global annual turnover, whichever is higher. Brazil's LGPD and India's DPDPA carry their own penalty structures.
- Supervisory orders - Regulators can order you to stop using a vendor entirely until a compliant DPA is in place. For a company relying on an EOR to employ workers in a given country, that is an operational emergency.
- Unlimited controller liability - Without a DPA, there is no contractual allocation of fault. If the processor causes a breach, you carry the regulatory exposure because you failed to bind them to proper obligations.
- Employee claims - In the EU and UK, data subjects (including your employees) can bring civil claims for material and non-material damage caused by data protection violations.
- Lost vendor relationships - Enterprise clients and publicly listed companies increasingly require evidence of DPAs as part of vendor onboarding. Missing DPAs can cost you contracts.
Practical steps before signing with an EOR or HR vendor
- Ask for the vendor's standard DPA before contract discussions start. A reputable provider will have one ready.
- Map which countries' laws apply based on where your employees sit, where the vendor is headquartered, and where data is stored or processed.
- Check whether the DPA includes current SCC modules (2021 version for EU data) or equivalent transfer mechanisms for each relevant jurisdiction.
- Request the sub-processor list and confirm it is kept current with a notification process for additions.
- Verify breach notification timelines allow you enough time to meet your own reporting obligations (72 hours under GDPR).
- Confirm audit rights: at a minimum, the vendor should provide annual third-party audit reports such as ISO 27001 or SOC 2 Type II.
- Have local legal counsel review the DPA for any country where you have significant employee numbers or elevated regulatory risk.
- Record the signed DPA in your vendor register and set a review date tied to contract renewal or regulatory changes.
DPA vs. related agreements
| Agreement type | What it covers | Relationship to DPA |
|---|---|---|
| DPA (Data Processing Agreement) | How personal data is processed by a third party on your behalf | The core document |
| Joint Controller Agreement | Shared responsibilities when two parties each determine processing purposes | Used alongside or instead of a DPA where both parties are controllers |
| Standard Contractual Clauses (SCCs) | Lawful mechanism for transferring personal data outside the EEA | Often appended to or incorporated into a DPA |
| NDA / Confidentiality Agreement | Restricts disclosure of business information | Separate; does not satisfy data protection law requirements |
| Master Services Agreement (MSA) | Commercial terms of the vendor relationship | Does not replace a DPA; both are needed |
A general service contract or NDA does not substitute for a DPA. Regulators and courts have been consistent on this point: data protection obligations must be addressed in a dedicated agreement that meets the substantive requirements of the applicable law.