Skip to main content
← Back to glossary
Compliance & consent

DPA — Data Processing Agreement

Was ist DPA?

Dieser Eintrag liegt derzeit nur auf Englisch vor.

A Data Processing Agreement (DPA) is the contract GDPR Article 28 requires when a controller hands personal data to a processor — on Devotel Orbit, that is you and us respectively. The DPA binds the processor to act only on the controller's documented instructions, under confidentiality, security-measure, and sub-processor guarantees down the chain, and to assist with data-subject requests and breach-notification duties. You preview and accept it from the Trust Center.

More detail

When GDPR places a DPA in scope — Article 28 kicks in the moment a controller engages a processor for record structured to the purposes the controller directs. If your contacts include people in the EU or EEA, or your organization is established there, your use of a communications platform is processor engagement: the DPA is the contract that makes Orbit's routing, storage, and retention of that personal data lawful in the first place, not an optional document.

What the DPA commits the platform to — on Devotel Orbit, the executed DPA governs contact records, message content, call recordings, and derived data: processing only on documented instructions, confidentiality undertakings from the people handling the data, technical and organizational security measures, the rule that sub-processors are engaged only under equivalent obligations and disclosed to you, assistance with data-subject access, portability, deletion, and objection requests, and deletion-or-return of the data at the end of the engagement unless retention law applies.

Trust Center execution — the DPA keeps its execution self-serve so a GDPR-relevant tenant never waits on a paperwork loop: an org owner or admin previews the template populated with the organization's controller details, accepts with a type-the-name attestation, and downloads the executed PDF from the same surface. Every acceptance writes an audit event with the signer details and the template version, and a subsequent controller-side change is handled the same way — re-accept against the current template.

Häufige Fragen

Do I need a DPA if I'm outside the EU or EEA?
You need one whenever you process the personal data of people located in the EU or EEA in the context of offering them goods, services, or monitoring their behavior — GDPR follows the data subject, not the controller's address. A non-EU company messaging EU contacts is a processor's controller under Article 28 just the same; a purely domestic operation with no EU data subjects is outside the scope.
How is the DPA different from the BAA?
They solve for different laws: the BAA is the HIPAA-specific contract for protected health information (US healthcare scope), while the DPA is the GDPR-specific contract for personal data generally. A healthcare tenant messaging EU patients can need both; a tenant with neither data class needs neither — the Trust Center evaluates the scopes independently and keeps the two execution flows separate.
How do I execute the DPA on Devotel Orbit?
From the Trust Center: an org owner or admin opens the Data Processing Agreement, reviews the current template (populated with your organization's controller details), completes the type-the-name acceptance, and the executed PDF becomes available for download. The acceptance and its signer details land in the audit trail, and a template-version change only ever asks for the same re-acceptance flow.

Build it on Orbit

Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.