How data processing agreement works
A DPA typically specifies the categories of personal data involved, the purpose and duration of processing, the safeguards the processor must apply, and whether the processor may engage sub-processors, along with notification requirements if a breach occurs. It also usually addresses cross-border transfers, specifying what safeguard applies if data leaves the country.
Businesses working with an outsourced service provider that will handle customer, employee or financial data typically request a DPA before sharing any of that data, not after the relationship has started. A well-written DPA gives both parties clarity on obligations and is often requested during a vendor's security or procurement review. A DPA is distinct from a general service agreement or terms of use, since it specifically addresses the processor's obligations around personal data rather than the commercial terms of the relationship, and regulators expect to see both documents in place for a compliant vendor relationship handling personal data.
Example
A UK accounting firm wants to bring on an outsourced bookkeeping provider that will access client financial and payroll data. Before onboarding starts, the firm requests a DPA specifying what data will be processed, where it will be stored, what safeguard applies to any cross-border transfer, and what happens to the data if the engagement ends. The signed DPA is kept alongside the firm's other vendor due diligence records, ready to produce if a client or regulator asks how the firm's outsourced providers are held to data protection standards.
Data processing agreement in QuickBooks Online vs Xero
Not software-specific: a DPA is a legal document rather than a software feature, though major platforms like Xero, QuickBooks Online and Google Workspace publish their own standard DPAs for customers who need one as part of their own compliance documentation with sub-processors.
Related terms
How LedgerBPO handles data processing agreement
We provide a data processing agreement on request, documenting how client data is collected, stored, safeguarded and handled at the end of an engagement, including any cross-border processing between our offices. This gives clients and their auditors clear documentation to support their own data protection compliance obligations.