Data Processing Agreement (DPA)

A Data Processing Agreement (DPA), known as Auftragsverarbeitungsvertrag (AVV) in German law, is a legally required contract under Art. 28 GDPR between a data controller and a data processor. It defines how personal data is handled, protected, and what obligations the processor has.

What is a Data Processing Agreement (DPA)?

A Data Processing Agreement (DPA) -- called Auftragsverarbeitungsvertrag (AVV) in German -- is a mandatory contract under Article 28 of the GDPR. Whenever a company (the data controller) engages a third-party service (the data processor) that handles personal data on its behalf, a DPA must be in place before any data is shared. For GDPR-compliant messaging platforms, this means: if you use SendSeven to send WhatsApp messages, emails, or SMS to your customers, SendSeven processes personal data (phone numbers, email addresses, message content) on your behalf -- a DPA is required.

The DPA is not a formality. It is a binding legal document that specifies: what data is processed, for what purpose, how long it is stored, what security measures are implemented, what happens in case of a data breach, and how data is returned or deleted when the contract ends. Without a DPA, both parties risk GDPR fines -- even if the actual data processing is perfectly secure.

Why is a DPA Important?

Legal obligation: Art. 28 GDPR explicitly requires a written contract (or equivalent electronic form) between controller and processor. Operating without one is a direct GDPR violation, undermining any effort toward proper consent management. German data protection authorities (Datenschutzbehorden) routinely check for DPAs during audits and have issued fines specifically for missing agreements.

Liability clarity: The DPA defines who is responsible for what. If a data breach occurs at the processor's end, the DPA determines the notification obligations, remediation steps, and liability distribution. Without a DPA, these responsibilities are legally ambiguous -- which typically means the controller bears full liability.

Sub-processor transparency: Most SaaS providers use sub-processors (cloud hosting, CDN, email delivery). The DPA must list all sub-processors and require them to maintain equivalent data protection standards. This creates a chain of accountability from your company through the messaging platform down to the infrastructure provider.

DACH market requirement: In Germany, Austria, and Switzerland, DPAs are taken particularly seriously. The German term Auftragsverarbeitungsvertrag (AVV) appears in virtually every B2B procurement checklist. Enterprise customers and public sector organizations will not engage a messaging provider without a signed AVV/DPA -- it is a non-negotiable prerequisite.

What Does a DPA Contain?

A compliant DPA under Art. 28 GDPR must include the following elements:

Subject and duration: What service is being provided? How long does the data processing last? For SendSeven, this covers the provision of messaging services for the duration of the customer contract.

Nature and purpose: Specifically what data processing activities occur -- e.g., storing contact data, routing messages across channels, generating delivery reports, providing analytics dashboards.

Types of personal data: Phone numbers, email addresses, names, message content, IP addresses, device information, conversation metadata.

Technical and organizational measures (TOMs): Encryption standards (TLS 1.3, AES-256), access controls (role-based permissions, two-factor authentication), backup procedures, physical security of data centers, employee confidentiality obligations.

Sub-processor list: All third parties involved in data processing, their location, and the specific service they provide. Changes to sub-processors require advance notification to the controller.

Data breach notification: The processor must notify the controller without undue delay (typically within 24-72 hours) of any personal data breach, including the nature of the breach and recommended countermeasures.

Data Processing Agreement with SendSeven

SendSeven provides a comprehensive DPA (AVV) that meets all Art. 28 GDPR requirements. As a German company (SendSeven GmbH), the agreement is governed by German law and fully addresses DACH market compliance expectations. The DPA covers all technical and organizational measures, lists all sub-processors with EU-based infrastructure, and defines clear data breach notification procedures.

All customer data is processed exclusively within EU data centers (Frankfurt, Dublin) -- no transfers to third countries. The DPA is available upon request and can be signed electronically. For enterprise customers requiring custom DPA clauses or on-premise due diligence, our team is available to discuss specific requirements. Contact us to request your DPA.