Data processing agreement (DPA) is a legally binding document. It’s signed between two key data processing actors under GDPR – the data controller and the data processor.
It regulates the details of data processing, such as the scope and purpose, as well as the relationship between those actors. In addition, it assigns certain obligations required by the new EU law.
Read more about this topic on the Piwik PRO blog: Check out the 7 elements every DPA should have.
Data processing agreement
-

How to recover lost conversions without adding compliance risk
Not every visitor who leaves is lost. Some just need a nudge. Funnel Recovery brings them back to the form, booking or application they started, using analytics and data activation tools your compliance team already approved.
-

HIPAA violations and fines: What healthcare organizations need to know
Quick summary HIPAA violations happen when a covered entity or business associate fails to meet the HIPAA Privacy, Security or Breach Notification Rule. Civil penalties range from a few hundred dollars to more than $2 million per violation, set across four tiers based on how much the organization knew. What this guide covers: HIPAA violation…
Other definitions
Recent posts from Piwik PRO blog
- How to recover lost conversions without adding compliance risk
- HIPAA violations and fines: What healthcare organizations need to know
- The EDPB’s new data anonymization guidelines: what they mean for your analytics data
- What is considered protected health information (PHI) under HIPAA? A guide for healthcare marketers
- We checked 59 hospital websites. 73% kept tracking visitors after opt-out.
- HEALTHCARE WEBSITE TRACKING REPORT 2026: Are healthcare companies one audit away from a compliance crisis?
- Anonymous website visitor tracking: How to do useful analytics without personal data [Updated]
- What is PII, non-PII, and personal data? [Updated]