Data processing agreement
A data processing agreement is a GDPR-required contract governing how a processor handles personal data on behalf of a controller.

What is a data processing agreement?
A data processing agreement (DPA) is a legally binding contract between a controller and a processor that handles personal data on the controller’s behalf. It is directly required by GDPR Article 28 and must set out the purpose of the processing, its duration, the types of personal data involved, and the processor’s obligations around security, sub-processors, and helping fulfil data subject rights. The agreement is not itself a legal basis for processing — you still need a lawful basis (such as consent) under Article 6.
Why does a data processing agreement matter?
In an online store you continuously share customer data — names, addresses, emails, order history — with vendors who process it for you. Without a DPA in place, you lack proof that the processing is lawful, and as the controller you remain liable if a vendor leaks data. The agreement defines responsibility, gives you the right to audit the processor, and obliges them to delete or return data when the relationship ends.
Common use cases
- Shopify as the platform. Shopify processes your customers’ data and is therefore a processor for you as the controller.
- Third-party apps. Email marketing, reviews, analytics, and fulfilment apps that access customer data each require a DPA.
- Agencies and freelancers. Any external party that gains access to your store’s personal data must be covered.
- Switching vendors. The agreement ensures data is deleted or migrated correctly on termination.
Shopify perspective
Shopify incorporates its Data Processing Addendum directly into its commercial terms, so you are covered when you accept them — there is no separate agreement to sign with Shopify itself. The responsibility, however, falls on you to ensure a DPA is in place for every App Store app you install. Keep a register of your sub-processors, and scrutinise apps tied to cookie consent and GDPR in particular before they touch customer data.