Definition
A data processing agreement (DPA) is a contract, required under GDPR and similar laws, between a data controller (the organisation that decides why and how personal data is processed) and a data processor (a vendor that processes that data on the controller's instructions). It sets out the subject matter, duration, nature and purpose of the processing, the types of data and categories of people involved, and the obligations and rights of the controller.
The law prescribes much of the content. The processor must only act on documented instructions, ensure staff confidentiality, apply appropriate security, not engage sub-processors without authorisation, help the controller respond to data-subject requests and breaches, delete or return data at the end, and submit to audits.
A DPA that omits these terms is non-compliant, and using a processor with no DPA at all is itself a breach by the controller.
In context
In iGaming, an operator is a controller and has a web of processors: the affiliate tracking platform, CRM and email tools, analytics providers, KYC and AML verification vendors, payment service providers, customer-support software, cloud hosting, and often the affiliate networks themselves. Each relationship that involves personal data — player identifiers, contact details, device and behavioural data, documents — needs a DPA, and the operator is expected to have done due diligence that the processor can actually meet its obligations.
Affiliates sit on both sides. When an affiliate receives player-level or lead-level personal data from an operator (for postbacks, reconciliation, or sub-affiliate management), the affiliate is a processor and needs a DPA with the operator.
When the affiliate uses its own vendors — a tracker, an email platform, a hosting provider — it is a controller and needs DPAs with them. Common gaps are informal data sharing over spreadsheets and APIs with no agreement, sub-processors (a tracker's own cloud vendor) not being disclosed or authorised, and international transfer terms missing when data leaves the EEA.
Regulators treat a missing or inadequate DPA as a standalone violation, separate from any actual misuse of the data, so the paperwork itself is part of compliance.
Worked example
Onboarding a new CRM vendor, an operator's legal team requires a DPA covering documented-instructions-only processing, EU data residency, a named list of sub-processors, breach notification within 24 hours, and deletion on termination. An affiliate receiving FTD-level data from the operator signs a matching DPA as processor; another affiliate that shares lead data with a third party with no agreement is flagged in an audit.
Related terms
Frequently asked questions
Browse the full iGaming & affiliate glossary — hundreds of EN/RU terms with examples.
← Back to glossary