A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor, required under Article 28 of the GDPR, that sets out how the processor may handle personal data on the controller's behalf. For email marketing, your provider is the processor and you are the controller, so a signed DPA is a baseline requirement of GDPR compliance.

What a DPA must contain

Under the GDPR, a DPA specifies the subject matter and duration of processing, the types of personal data and categories of data subjects, the processor's security measures, the use of sub-processors, support for data-subject rights, breach-notification timelines, and what happens to the data when the contract ends. A good DPA is downloadable without a sales call.

Why the DPA matters

Without a DPA you cannot demonstrate GDPR-compliant processing, so it is one of the first documents to check when choosing a provider. Review it alongside where the provider hosts data and whether it relies on Standard Contractual Clauses or benefits from an EU adequacy decision. Mailpro provides a clear DPA and hosts data in Switzerland. Learn more about GDPR and data residency, or read our guide to the best GDPR-compliant email marketing software.

Mailpro and GDPR

A clear DPA, no sales call required

Mailpro gives you a straightforward Data Processing Agreement and hosts your data in Switzerland, so GDPR compliance starts on solid ground.

Start free with Mailpro See Mailpro pricing

Previous Article

   

Next Article

You might also be interested in:

Data residency refers to the physical country or jurisdiction where data is stored. In simple terms, it answers the question: where does your data live? When a business stores contact lists, form responses, email content, custo...
A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor, required under Article 28 of the GDPR, that sets out how the processor may handle personal data on the controller'...
A data controller and a data processor are two roles defined by data-protection laws such as the GDPR. The controller decides why and how personal data is processed; the processor handles that data only on the controller's instruc...