What is Data Processing Agreement (DPA)?

A Data Processing Agreement (DPA) is a legal contract that sets out how a service provider (the processor) may handle personal data on behalf of an organisation (the controller). It defines responsibilities, security measures, subcontractor rules and what happens if something goes wrong.

A DPA explains, in plain legal terms, who is responsible for personal data collected and processed when you use a service. For survey and form tools like Hearo, that includes names, contact details, language preferences and any free-text answers that could identify a person. A DPA typically covers: the roles of controller and processor; the purposes and types of data processed; required technical and organisational security measures; rules on subprocessors; data retention and deletion; incident and breach reporting; audit rights; and how international transfers are handled. A DPA is a contract between organisations β€” it sits alongside (but does not replace) your privacy notice to participants or any required consent forms.

Usage example

Sam runs parent surveys for a school. Before uploading contact lists and pupil information, the school signs a DPA with Hearo that specifies what student and parent data Hearo will process, how long it will be kept, which subprocessors may access it, and how fast Hearo must notify the school if there is a data breach.

Practical application

DPAs matter because they reduce legal and operational risk when you collect personal data. They make clear who must: protect the data, delete it when asked, respond to subject access requests, and notify partners about breaches. For organisations running multilingual surveys, a DPA ensures that translation, storage and review of responses (including free-text answers in many languages) meet required security and privacy standards. Before sharing personal data, check the DPA for retention limits, subprocessors, breach notification timelines and any controls for international data transfers.

FAQ

Do I need a DPA to use Hearo?

If you are collecting personal data (names, contact details, identifiable free-text answers) you should have a DPA with any third-party service that processes that data. Hearo provides a standard DPA for customers that sets out how we handle survey data and supports common legal requirements.

What if my survey collects sensitive or special-category data?

Sensitive personal data (health, ethnicity, immigration status, etc.) usually requires extra safeguards and a clear legal basis under applicable law. Your DPA should specify additional protections and any restrictions on processing; you should also check whether local law requires explicit consent or other steps before collecting those answers.

Does a DPA cover international transfers of data?

Yes. A DPA should explain where data is stored and the mechanisms used for transfers (for example, EU Standard Contractual Clauses, approved frameworks or encryption and tenancy controls). If your project has strict data residency requirements, confirm those controls in the DPA before collecting data.

What happens if there is a data breach?

The DPA sets out responsibilities and timelines: the processor must notify the controller without undue delay (often within a specified number of hours), assist with containment and investigation, and cooperate on notifications to authorities or affected individuals. It also clarifies who pays for remediation and liability limits.