Data Processing Agreements for Vendors That Handle Customer Data
When you give a vendor access to customer data, your services agreement rarely limits how the vendor may use that data. A data processing agreement, often called a DPA, defines the permitted processing, security duties, assistance obligations, and end of service procedures.
Payment processors, email platforms, analytics providers, cloud hosts, payroll vendors, customer support tools, and advertising platforms often receive personal data while providing their services. Your DPA should govern that access before the first transfer. With vague terms, the vendor determines how it may use the data.
When the Law Requires a DPA
When your business determines why and how personal data is processed, the Texas Data Privacy and Security Act treats it as a controller. A processor handles personal data on the controller's behalf. Texas Business and Commerce Code § 541.104 requires a binding contract between them.
Your Texas contract must state the processing instructions, nature and purpose, data type, duration, and each party's rights and obligations. It must also address confidentiality, deletion or return, compliance information, assessments, and subcontractors.
Texas expanded the processor's statutory duties on January 1, 2026. House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, amended § 541.104. When applicable, processors must now assist with security requirements for personal data collected, stored, or processed by an artificial intelligence system. They must also help the controller satisfy notice requirements for a breach involving the processor's system under Chapter 521.
California law defines the parties under different labels and requires more detailed terms. For a business covered by the CCPA, Civil Code § 1798.100(d) requires a contract whenever you sell or share personal information with a third party or disclose it to a service provider or contractor for a business purpose. California regulation § 7051 governs service provider and contractor contracts. Section 7053 covers agreements with third parties that receive personal information through a sale or share.
Virginia, Colorado, and Connecticut also require contracts between controllers and processors. If a vendor receives personal data from your business and processes it for your benefit, you should confirm the applicable contract rules before any transfer begins.
Processing Instructions and Purpose Limits
Your DPA must state the instructions that govern the vendor's work. Texas requires processing instructions. California requires specific business purposes rather than a generic reference to the entire agreement.
If you allow the vendor to process data only to provide services under a master agreement, the vendor controls how it uses the data. Your DPA should list each permitted activity, such as hosting, payment processing, fraud detection, customer support, analytics, advertising measurement, or report generation, then tie every one to the specific work the vendor agreed to perform.
Because risk varies by data type, you should list the categories the vendor receives. Names, email addresses, payment information, device identifiers, browsing activity, account credentials, health information, biometric data, children's data, and precise geolocation present different levels of risk. Sensitive data may trigger consent, assessment, security, and retention duties.
Your processing instructions should state how long the vendor may retain the data, when active processing ends, and how it handles archived copies and backups. With a retention schedule, both sides have an objective end point.
Confidentiality and Security
The vendor must bind each person who processes personal data to a duty of confidentiality. It must impose that duty on employees, contractors, and subcontractors with access to the data.
Your security terms should match the volume, sensitivity, and use of the information. When a vendor promises only reasonable security, you receive a legal standard with few concrete controls. In a dedicated clause, you should name the controls or evidence, such as a SOC 2 Type II report, ISO 27001 certification, the NIST Cybersecurity Framework, CIS Controls, penetration testing, encryption, access controls, or incident response testing.
You should also assign responsibility for security measures by stating each side's duties. If you control user permissions while the vendor controls encryption, system logging, and infrastructure, your agreement must state that allocation.
Subcontractors
Vendors often rely on cloud hosts, support providers, analytics tools, and other subcontractors. Your DPA should govern the full processing chain.
Texas requires a written subcontractor agreement that imposes the processor's obligations for the personal data. California requires a compliant subcontractor contract. Virginia, Colorado, and Connecticut impose similar flow down duties.
Before the vendor proceeds, you should decide whether it needs advance approval or may act after notice and a chance to object. Your DPA should state how the vendor delivers that communication, how long you have to respond, and what happens when the parties can't resolve the dispute. The vendor should remain responsible for its subcontractors' performance.
Breach Notice and Response
Your DPA should include a separate incident notice provision. Under Texas Business and Commerce Code § 521.053(c), a custodian that maintains sensitive personal information must notify the owner or license holder immediately after discovering a breach when an unauthorized person acquired, or is reasonably believed to have acquired, the information.
Texas notice to affected individuals is generally due within 60 days after the business determines that a breach occurred. Notice to the Texas Attorney General is due within 30 days when the breach affects at least 250 Texas residents. Colorado, Florida, and New York can require individual notice within 30 days.
For vendors that handle sensitive personal information, a 48 to 72 hour notice period after discovery can leave the customer time to investigate and meet applicable deadlines. The clause can require the vendor to preserve evidence, identify affected systems, describe known data categories, provide continuing updates, cooperate with forensic review, and support consumer and regulator notices. It can also state when the clock begins and identify the people who receive notice.
Consumer Rights Assistance
A vendor may hold the information you need to answer a request for access, deletion, correction, or portability. Texas requires processors to assist with consumer requests through appropriate technical and organizational measures when reasonably practicable.
California requires service providers and contractors to help the business comply with consumer requests or to act once the business notifies them. You should translate those duties into a working procedure by setting response times, accepted intake formats, verification responsibilities, confirmation requirements, and rules for submissions that reach the vendor first.
California Audit and Assessment Assistance
California's current regulations require more than a general promise of cooperation. A service provider or contractor must assist a covered business with its cybersecurity audit, risk assessment, and automated decisionmaking obligations when it holds relevant information. The vendor must provide the underlying facts within its possession, custody, or control.
Under Section 7051, you have the right to take reasonable steps to verify compliant processing. The regulation states that reasonable measures may include manual reviews, automated scans, assessments, audits, and technical or operational testing at least once every 12 months.
Under your contract, you should exercise the stated verification authority. Under § 7051(c), a business that never enforces its contract or conducts audits or tests may lose the defense that it lacked reason to believe the vendor intended to violate the CCPA. For many software vendors, annual review of an independent assessment report may fit the risk. Vendors with sensitive data or essential functions may justify stronger inspection, testing, and remediation provisions.
Return and Deletion
At your direction, the processor must return or delete personal data when the services end unless the law requires retention. Your DPA should cover production systems, archives, backups, logs, exports, derived files, and subcontractor copies.
Immediate deletion from backups may conflict with the vendor's ordinary rotation. If so, you should require the vendor to isolate the retained copy from active processing, limit access, preserve confidentiality, and delete it under a defined schedule.
You should also obtain written evidence. A deletion certificate must identify any data retained under a legal obligation and attest that the vendor completed the required deletion.
California Use Restrictions
California § 7051 requires the contract to prohibit the vendor from selling or sharing personal information received under the agreement. It must also prohibit retention, use, or disclosure for purposes beyond the stated business purposes, for another commercial purpose, or outside the direct business relationship, unless the CCPA permits the activity.
These restrictions apply to analytics, advertising, model training, product development, and benchmarking clauses. A vendor that uses identifiable customer data to improve its services may act beyond the permitted purpose.
The vendor must provide the same level of privacy protection required by the CCPA, notify the business when it can no longer comply, support consumer requests, and allow the business to stop and remediate unauthorized use. California also requires a contractor to certify that it understands the statutory restrictions and will comply with them.
Aggregated and Deidentified Data
Standard DPAs often reserve broad rights to use aggregated or deidentified data for analytics, benchmarking, research, or product improvement. You should review those rights separately.
California defines deidentified information through functional safeguards. A business claiming that treatment must take reasonable measures to prevent association with a consumer or household, publicly commit to maintain the information in deidentified form, and contractually bind recipients to the same restrictions. Virginia imposes similar safeguards, a public commitment against reidentification, and binding limits on anyone who receives the data.
You should test the clause against the vendor's process and prohibit reidentification, limit disclosure, require technical safeguards, and preserve deletion duties for source data. If someone can link the records to a consumer, the records remain identifiable.
Reviewing a Standard Vendor DPA
Many software vendors offer a standard DPA and decline edits. Before onboarding, you should review the permitted purposes, sensitive data, subcontractors, incident timing, consumer request support, audit evidence, deletion, and use of aggregated or deidentified data.
If the vendor rejects a requested change, documentation can record the rejected term and the controls that reduce the remaining risk. The file can identify who approved the remaining risk, the affected data, the business reason for acceptance, and any operational restriction.
You should maintain a vendor inventory that identifies each provider receiving personal data, the data involved, the processing purpose, storage locations, subcontractors, and governing DPA. Whenever a vendor adds a data collection feature to its service, changes a subprocessor, or begins using customer data for artificial intelligence, you should review that inventory.
Throughout the vendor relationship, you should apply the DPA. It must state the permitted work, assign security duties, set response times, govern every recipient, and document deletion. With those terms, you retain control while the vendor has possession.
Related practice area: Privacy Law
This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.
Need advice tied to your business issue?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry