SUMMARY
-
Data Controller is ultimately liable for any breach occurring during data processing activities.
- The Data Processing Agreement (DPA) is a tool for vendor management and sets out the vendor’s obligations and responsibilities.
- DPA should cover scope of processing, specified purposes, security obligations, breach notifications and indemnification.
- There are operational risks that should be considered when drafting a DPA.
-
Audit and self-assessment should be utilized to confirm that vendor adopts the appropriate measures to protect personal data.

