Back to Blog
Compliance November 2, 2026 9 min read

Reading a DPA Before You Sign It: The Eight Clauses That Actually Matter

A DPA is where the promises you made to your customers either hold up or quietly fall apart. Eight clauses do almost all of that work.

By Aparna Netheti

Reading a DPA Before You Sign It: The Eight Clauses That Actually Matter

A data processing agreement sets out what a vendor may do with personal information you are responsible for. Sign the wrong one and you have promised your customers protections your vendor is not obliged to deliver. That gap is invisible until an incident, a transfer question, or an access request makes it visible, and then it is your problem, not the vendor's.

Eight clauses carry almost all of the risk. Read those closely and skim the rest.

1. Scope and purpose limitation

Look for language restricting the vendor to processing only on your documented instructions and only for the purpose of providing the service. Then look for what has been carved out: analytics, benchmarking, service improvement, model training.

Those carve-outs are where the terms diverge from what your privacy policy told customers. A clause permitting use of "aggregated and anonymised data" for improvement is common and often acceptable, provided the anonymisation is real and defined. Ask what process produces it, because the word is used loosely.

2. Sub-processors

Three things: is there a list, is there notice before changes, and can you object.

A DPA with no list and no notice means your vendor can move your data to a new company at will, and you will find out during a security review. A workable clause names the sub-processors or points to a maintained page, commits to notice of a defined length before adding one, and gives you a right to object with a defined consequence, usually termination without penalty. This connects directly to your own disclosure obligations, since your customers will ask you the same questions you should be asking here.

3. Breach notification

The clause specifies a trigger and a clock. Read both carefully.

Trigger language matters more than the number of hours. "Without undue delay after confirming a breach" can mean weeks, because confirmation is a judgment the vendor makes. "Within 48 hours of becoming aware of a security incident affecting customer data" is a commitment you can act on. Push for awareness-based triggers.

Then check what the notice must contain. A notice saying only that something occurred is useless to you, because you have your own assessment to make. Ask for the categories of data, the number of affected records, the status of the investigation, and a named contact.

4. Deletion and return

Two failure modes. The first is a clause requiring deletion "in accordance with our standard retention practices", which is not a commitment. The second is a deletion promise that silently excludes backups.

What good looks like: deletion within a defined period after termination, an option to receive an export in a usable format first, backups covered with a stated overwrite cycle, and written confirmation on request. If backups are excluded, you need to know so you can describe your actual position honestly rather than repeating the vendor's marketing.

5. Location and transfers

The clause should state where processing occurs and where data rests, not merely that the vendor complies with applicable law.

For Canadian organizations this feeds directly into your transfer analysis, and Quebec's Law 25 makes it sharper by requiring assessment before information is communicated outside the province. A vendor unwilling to commit to locations in writing is a vendor whose location can change without you knowing. Record what you get in a cross-border transfer assessment attached to the vendor.

6. Audit and evidence

Full audit rights are rarely granted and rarely exercised. What you actually want is the practical version: a current third-party report, a completed security questionnaire on request, and the right to a reasonable audit if something goes wrong.

Watch for clauses limiting you to one audit every three years at your own cost with ninety days notice. That is a clause designed to be unusable. Negotiate the report and questionnaire instead, since those are the artefacts you will really use.

7. Liability

Read this against the value of the data, not the value of the contract.

A cap set at twelve months of fees is standard and is often wildly disproportionate to the harm a breach of that dataset would cause. You may not be able to move it, particularly with a large vendor. What you can do is know the number, decide consciously whether the exposure is acceptable, and record that decision as a risk acceptance rather than discovering it during an incident.

8. Changes to the terms

The clause that lets a vendor amend the DPA on notice, or by posting an updated version, quietly undoes everything above.

Look for a commitment that changes will not materially reduce protections, or a right to terminate if they do. Then diarise a review, because in practice nobody reads the update email. A vendor review triggered from your vendor inventory at renewal is the only reliable way to catch a term that changed eight months ago.

ClauseWeak versionStrong version
PurposeBroad improvement rightsDocumented instructions only, defined exceptions
Sub-processorsSilentListed, notice period, right to object
Breach noticeUndue delay after confirmationFixed hours from awareness, defined contents
DeletionStandard practicesDefined period, backups addressed, confirmation
LocationComplies with lawNamed regions for processing and storage
AuditOne audit per three yearsCurrent report plus questionnaire on request
LiabilityCapped at fees, unexaminedCapped, quantified, consciously accepted
AmendmentsEffective on postingNo material reduction, or termination right

This is general information, not legal advice. Have counsel review agreements that matter.

For the diligence that should happen before the DPA arrives, an AI procurement policy that does not block the business covers the questions to ask first.

Valdra keeps the DPA terms you actually agreed to against the vendor record, so the notice period, deletion commitment, and location you signed are visible when they matter.

Frequently asked questions

What is a data processing agreement?+

A contract setting out what a vendor may do with personal information you remain responsible for. It governs purpose limits, sub-processors, breach notification, deletion, data location, audit rights, liability, and how the terms themselves can change.

Which DPA clause causes the most problems?+

Breach notification, because the trigger matters more than the number of hours. Without undue delay after confirming a breach can mean weeks, since confirmation is the vendor's judgment. Push for a fixed period from becoming aware of an incident.

Should I worry about deletion clauses excluding backups?+

Yes. A deletion promise that silently excludes backups means data you told customers was deleted still exists. Look for a stated overwrite cycle covering backups, a defined deletion period after termination, and written confirmation on request.

Are full audit rights worth negotiating?+

Rarely. Clauses granting one audit every three years at your cost with ninety days notice are designed to be unusable. Negotiate for a current third-party report and a completed security questionnaire on request, which are the artefacts you will actually use.

What should I do about a low liability cap?+

You often cannot move it with a large vendor. Know the number, judge it against the harm a breach of that specific dataset would cause, and record the outcome as a conscious risk acceptance rather than discovering the cap during an incident.

data processing agreementDPA clausesvendor contract privacysub-processor clausebreach notification clauseDPA negotiation Canada

AI governance and privacy compliance, simplified.

Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.

Try Valdra

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.