hello@newnorth.nl+31 (0) 85 401 31 62
/Journal

The data processing agreement (DPA) across your tracking stack

ReferencePrivacy2023.01.30
Freek Kampen
Freek KampenCo-founder, New North Digital

What belongs in a data processing agreement, which vendors in your measurement setup need one, and where to find yours at Google.

What a data processing agreement is

A data processing agreement, or DPA, is the contract between the party that decides why and how personal data gets processed and the party that carries that out on its behalf.

You are the controller: you decide to measure visitor behaviour and what you use it for. The processor is the vendor that stores or handles the data for you, such as your analytics, email or hosting provider.

The GDPR requires that contract as soon as a processor handles personal data for you. What follows is not legal advice. The details differ per organisation and per vendor, and your lawyer or data protection officer has the last word.

What belongs in it

  • Subject and purpose. What the processor may use the data for, and what it may not. Using it for its own purposes is not part of that.
  • Data types and data subjects. Which categories of data, and about whom: visitors, customers, applicants.
  • Duration and retention. How long the processing runs and what happens to the data when it ends: returned or deleted.
  • Security. The technical and organisational measures the processor takes, such as encryption, access control and logging.
  • Sub-processors. Whether the processor may bring in others, how it tells you, and whether you can object.
  • Transfers outside the EEA. Which countries the data reaches and on what legal basis.
  • Data breaches. How quickly the processor informs you and what it tells you, so you can meet your own notification duty.
  • Cooperation. Help with requests from data subjects, such as access or deletion, and your right to verify that the agreement is being kept.

Who you need one with

Walk your measurement setup from front to back and note per vendor what it gets to see.

Google. For Analytics and Ads the arrangement runs through the data processing terms you accept in your account settings. In GA4 you will find them under Admin, Account settings, in the data processing terms section, which is also where you fill in the contact for breach notifications. In Google Ads they sit in account settings under data protection. Note that Google acts as a processor for some services and as an independent controller for others, so read which role applies per service.

Your consent management platform. It stores consent logs with an identifier and often an IP address. That needs an agreement.

The host of your server-side container. With a service like Stape or Taggrs the container runs on their infrastructure and every hit passes their servers. Run it yourself on Google Cloud Run and that data falls under your Google Cloud terms. We compared the two routes in Cloud Run or Stape.

Your advertising platforms. Meta, Microsoft, LinkedIn, TikTok and Pinterest each have their own business tools terms. For some components you are joint controllers rather than controller and processor.

Your email tool, your CRM and your hosting provider. This is where the data that actually matters lives: names, addresses, order history.

Your data warehouse. BigQuery, Snowflake or whatever you use, plus whoever builds dashboards on it and the agency with access. We belong on that list too.

Server-side does not remove your role

A server-side container changes the route, not the destination. Hits go to your own subdomain first and then on to Google, Meta or whoever else you are feeding.

You gain control: you can strip fields before they move on, truncate IP addresses and decide which platform receives which field. You lose no obligation whatsoever. For every destination behind your container the question is the same as it was in front of it: who receives what, in which role, and where is that written down.

The container host has joined that list.

What to do with this

  • List every party that receives data through your site or your container, including tools somebody added once and forgot.
  • Find where the agreement lives per vendor: a signable annex, an account setting you tick, or a clause in the general terms.
  • Accept Google's data processing terms and fill in the breach notification contact, even if the account was created years ago.
  • Ask for the sub-processor list and check which of them sit outside the EEA.
  • Put the list next to your cookie banner and your record of processing activities. A vendor that appears in one and nowhere else is a signal something is off.
  • Have your lawyer or data protection officer review the outcome. This article is a checklist, not advice.

Want to talk about this?

Let's talk data.

Tell us about your stack, your goals, the data you wish you had.

Takes 1 minute