Definition
A Data Processing Agreement (DPA) is a legal contract between a data controller (the organisation that determines the purpose of data processing) and a data processor (the organisation that processes data on behalf of the controller). Under GDPR, a DPA is required whenever a controller engages a processor to handle personal data.
For email marketing, the DPA is the contract between your organisation (the controller) and your email service provider (the processor). Without a signed DPA, your ESP may not be GDPR-compliant for processing subscriber data.
What a DPA Must Include (GDPR Article 28)
| Requirement | Email Marketing Application |
|---|---|
| Subject matter and duration of processing | Email marketing services, duration of contract |
| Nature and purpose of processing | Sending emails, tracking engagement, managing lists |
| Type of personal data | Email addresses, names, engagement data, preferences |
| Categories of data subjects | Email subscribers, customers, leads |
| Obligations of the controller | Your responsibilities under GDPR |
| Confidentiality obligations | Processor must ensure data confidentiality |
| Security measures | Technical and organisational measures |
| Sub-processor authorisation | Whether the ESP can engage sub-processors |
| Data breach notification | Processor must notify controller of breaches |
| Deletion or return of data | What happens to data when contract ends |
DPAs for Email Service Providers
Most major ESPs provide standard DPAs:
| ESP | DPA Availability | Sub-processors |
|---|---|---|
| Mailchimp | Available in account settings | AWS, Google Cloud, others |
| Klaviyo | Available in account settings | AWS, Snowflake, others |
| HubSpot | Available in account settings | AWS, Google Cloud |
| SendGrid | Available on request | Twilio infrastructure |
| MailerLite | Available in account settings | DigitalOcean, others |
When You Need a DPA with Your ESP
- Your ESP is a data processor: Any organisation that processes subscriber data on your behalf.
- Your subscribers are in the EU/UK: GDPR applies regardless of your organisations location.
- You process personal data: Email addresses and engagement data are personal data.
- You use third-party integrations: Each integration that processes data may need its own DPA.
DPA Best Practices
- Review before signing: Do not accept a DPA without reviewing the processor's security measures and sub-processor list.
- Maintain a DPA register: Track all processors and their DPA status.
- Review sub-processors: Monitor changes to the processors sub-processor list and object to changes you do not approve.
- Check termination clauses: Understand what happens to your data when the contract ends.
- Update annually: Review DPAs annually or when significant changes occur in either organisation.
Related Glossary Terms
A/B Testing
A/B testing in email marketing is the practice of sending two variations of an email to a small sample of your list to determine which version performs better before sending the winner to the remaining subscribers.
Abandoned Cart Email
An abandoned cart email is an automated message sent to customers who added items to their online shopping cart but left without completing the purchase. It is one of the highest-converting email types in ecommerce.
AIDA Model for Email
The AIDA model (Attention, Interest, Desire, Action) is a classic copywriting framework used to structure email campaigns that guide subscribers from awareness to conversion.
AMP for Email
AMP for Email is a Google-developed framework that allows email messages to include interactive elements like forms, carousels, accordions, and live content. It turns static emails into dynamic, interactive experiences directly inside the inbox.
Anchoring Effect in Email Marketing
The anchoring effect is a cognitive bias where the first piece of information presented (the anchor) influences subsequent decisions, used in email to frame pricing and value perception.
Announcement Email
An announcement email is a dedicated campaign that communicates a specific update, milestone, or change to subscribers, from product launches and feature releases to company news and events.
Frequently Asked Questions
You need a DPA with any tool that processes personal data — your ESP, analytics platform, CRM, email testing tools, and any other service that handles subscriber data. Tools that only process anonymised data may not require a DPA.
Reputable ESPs provide DPAs as standard. If an ESP does not offer a DPA, they are unlikely to be GDPR-compliant. Using an ESP without a DPA puts your organisation at regulatory risk.
Most ESPs require their own DPA template to ensure it covers their specific processing activities. Review the ESPs DPA and request amendments if it does not meet your requirements.
DPAs are typically signed as a separate document but referenced in the main service agreement. Some ESPs include DPA terms within their standard terms of service. Ensure the DPA is explicitly agreed.
Before migrating data to a new ESP, ensure a DPA is in place covering the transition period. When cancelling the old ESP, confirm the DPA requires deletion of your data after the contract ends.