Governance & Compliance · Data artifact
Data Processing Agreement
Data artifactGovernance & ComplianceSafety, Security & Governancearc:DataProcessingAgreement
A controller-processor contract specifying which personal data a vendor may process, how long it may retain it, whether subprocessors are permitted and deletion procedures at termination.
Responsibility. Binds third-party processors to the controller's data-protection terms.
Also known as: DPA (contract), Processor agreement
Relationships
constrains control
Design guidance
- MUST state that the vendor processes as processor on the controller's behalf, the controller retaining ultimate GDPR responsibility.
- SHOULD document Standard Contractual Clauses and supplementary measures for international transfers (Ref9.05).
Classification
- Quality attributes
- Transparency and accountability (NIST AI RMF: accountable and transparent)
- Risks mitigated
- Processors reusing data for their own purposes
- Frameworks & regulations
- GDPR Art. 28
Sources
- Ch9.7: T. Nguyen, "GDPR and Data Protection Regulations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.7. ISBN: 9798244538229.
- Ref9.05: "Privacy and Data Protection for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/05-Privacy-Data-Protection.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note