Data processing agreement (DPA)
Data processing agreement (DPA) is the contract required whenever a vendor processes personal data on your behalf — registration platforms, event apps, matchmaking tools, email systems. It defines what the vendor may do with the data, how they secure it, and what happens on breach, audit, or contract end.
Every event runs on a chain of vendors handling attendee data, and the DPA is what makes each link legally accountable. As organizer you're typically the "controller" — you decide why data is collected — while your registration platform, app provider, and matchmaking vendor are "processors" acting on your instructions. The DPA pins down that relationship: permitted uses, security measures, sub-processors (your vendor's vendors, where surprises usually hide), breach notification timelines, and data return or deletion when the contract ends. Commercially, DPAs matter twice: they're legally required under GDPR and similar laws, and they're where you discover what a vendor actually does with your attendee data — including, increasingly, whether they train AI models on it. That clause deserves close reading; "improving our services" can mean your audience data sharpening a product your competitor events also buy. The common mistake is signing the vendor's standard DPA unread during a rushed procurement, then learning about sub-processors in unexpected jurisdictions after a breach. One honest nuance: a signed DPA shifts accountability but not reputation. If your app vendor leaks attendee data, the regulator may pursue them — your exhibitors and attendees will remember you. Contracts allocate liability; they don't distribute blame.
Direct answer
Data processing agreement (DPA) is the contract required whenever a vendor processes personal data on your behalf — registration platforms, event apps, matchmaking tools, email systems. It defines what the vendor may do with the data, how they secure it, and what happens on breach, audit, or contract end.
More terms
No related terms yet.