All resources
Trust Center8 min read

Data Processing Agreement guide

The contractual topics that should govern WhyBecause processing customer meeting data.

Why a DPA is needed

Article 28 GDPR requires processing by a processor to be governed by a contract or other legal act. The DPA turns security and privacy expectations into enforceable instructions and responsibilities.

Core DPA schedule

  • Subject matter, duration, nature and purpose of processing.
  • Categories of data and data subjects.
  • Customer instructions and confidentiality obligations.
  • Security measures and incident notification.
  • Subprocessor authorization and change notice.
  • Support for rights requests, DPIAs, deletion, return and audits.

WhyBecause DPA availability

A production-ready DPA must reflect the final legal entity, hosting configuration, transfer mechanisms and subprocessor schedule. Until that document is formally published, customers should contact hello@whybecause.io for the current contractual position.

This page is an explanatory guide, not the signed DPA itself.

Official sources

Use the authoritative texts below when making legal or compliance decisions.

This resource provides general product and operational information. It is not legal advice. Your organization remains responsible for assessing its specific use, lawful basis and obligations.