Data Processing Agreement (DPA)
A Data Processing Agreement (DPA) is a contract that sets the instructions, safeguards, and responsibilities for a processor handling personal data on a controller's behalf.
DPAs are commonly used to document controller-processor relationships under data protection laws such as the GDPR. The controller decides the purposes and essential means of processing; the processor acts on documented instructions. Labels alone do not settle the roles, and the same organization can be a controller for one activity and a processor for another.
A DPA typically describes the subject, duration, purpose, data types, and groups of people involved. It also addresses confidentiality, security, subprocessors, assistance with individual rights and incidents, deletion or return at the end of service, and information needed to demonstrate compliance. International data transfers may require additional terms or arrangements.
What to review for AI phone calls
The agreement should match the real data flow. An AI phone workflow can create audio, transcripts, summaries, extracted fields, phone-number metadata, tool requests, and webhook events. If the DPA describes only “contact information” while the configured agent collects health, financial, or other sensitive details, the paperwork and the implementation may be misaligned.
Teams should identify every processor and subprocessor that can receive personal data, including services added through integrations. They should also verify permitted purposes, access boundaries, security responsibilities, storage locations, retention periods, deletion behavior, incident-notification procedures, and support for individual requests. Adding a new destination or changing what the agent asks can require a fresh review.
What a DPA does not do
A DPA does not itself create a lawful basis to collect data, replace a privacy notice, or make an excessive call script necessary. It is also different from a Business Associate Agreement: a BAA addresses defined HIPAA relationships involving PHI, while a DPA addresses controller-processor handling of personal data under the applicable privacy framework. Some organizations may need both for the same service.
The contract is useful only when operating controls reflect it. Prompts, permissions, integrations, retention settings, and deletion procedures should implement the documented instructions. Legal, privacy, and security teams should review the actual calling program and the executed agreement together.