Compliance and GDPR
Data processing agreement
A data processing agreement, or DPA, is a contract that sets out how a service provider may handle personal data on behalf of the customer that controls it.
Why it matters
When you use a tool that touches your contact data, the GDPR expects a DPA between you and that provider. It defines what the provider may do with the data, how it is protected, and what happens if something goes wrong. Without one, using a data or outreach tool on EU personal data leaves a gap in your compliance.
How it works in practice
A DPA sets out the scope and purpose of processing, the provider’s security duties, rules for using sub-processors, support for data-subject rights, and what happens to the data when the contract ends. The customer acts as the controller deciding why and how data is used, and the provider acts as the processor acting on the customer’s instructions. It is signed before the data is handled.
Common mistakes
A common mistake is using a provider that touches personal data without a DPA in place. Another is signing one without checking who the sub-processors are or where data is stored. A third is treating the DPA as filed and forgotten rather than something to revisit when the setup changes.
How hubsell approaches it
hubsell offers a data processing agreement so your use of the platform on EU contact data is covered, with EU data handling behind it.