A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor, required under Article 28 of the GDPR, that sets out how the processor may handle personal data on the controller's behalf. For email marketing, your provider is the processor and you are the controller, so a signed DPA is a baseline requirement of GDPR compliance.
What a DPA must contain
Under the GDPR, a DPA specifies the subject matter and duration of processing, the types of personal data and categories of data subjects, the processor's security measures, the use of sub-processors, support for data-subject rights, breach-notification timelines, and what happens to the data when the contract ends. A good DPA is downloadable without a sales call.
Why the DPA matters
Without a DPA you cannot demonstrate GDPR-compliant processing, so it is one of the first documents to check when choosing a provider. Review it alongside where the provider hosts data and whether it relies on Standard Contractual Clauses or benefits from an EU adequacy decision. Mailpro provides a clear DPA and hosts data in Switzerland. Learn more about GDPR and data residency, or read our guide to the best GDPR-compliant email marketing software.
Mailpro and GDPR
A clear DPA, no sales call required
Mailpro gives you a straightforward Data Processing Agreement and hosts your data in Switzerland, so GDPR compliance starts on solid ground.