Data Processing Agreement (DPA)
A data processing agreement is a legally binding contract between a data controller and a data processor that governs how personal data is handled. Under GDPR, a DPA is required whenever an organization shares personal data with a third-party service provider.
Why It Matters
When an AI agent governance platform routes traffic that contains personal data, the platform provider may become a data processor (or sub-processor) under GDPR. This triggers DPA requirements before the platform can be deployed.
Self-hosting the gateway component eliminates this classification for some architectures: if personal data never leaves the customer's infrastructure, the governance vendor may not qualify as a processor. This is why self-hosted deployment is a priority for EU buyers in regulated industries.
DPA requirements include specifying the types of personal data processed, the purposes of processing, the duration, data deletion obligations, sub-processor management, and technical and organizational security measures.