Skip to content
← Back to Glossary

What is Data Processing Agreement (DPA)?

Quick Answer

A legally binding contract between a business and its email service provider governing how personal data is processed.

A DPA is required under GDPR Article 28 whenever a business uses a third-party processor (like an ESP) to handle personal data of EU residents. It specifies the scope of processing, security measures, sub-processors used, data retention periods, and obligations in case of breach. Without a DPA, using an ESP for EU email lists is non-compliant. MisarMail provides a signed DPA to all paid plan customers on request.

Related Terms

Master email marketing with MisarMail.com — AI-powered campaigns, automation, and deliverability tools.

Start Free Trial →