What Is a DPA and Why Clients Ask
A plain-English guide to Data Processing Agreements for small firms: what they are, when clients request one, and what to check before you sign.
· By ProjectSend Team

A longtime client emails you asking for a Data Processing Agreement before sharing their tax documents. If you have never seen one before, it can feel like a legal trap. It is not -- but it is a real obligation in certain situations. Here is what it means, when it matters, and what to look for before you sign.
What Is a Data Processing Agreement?
A Data Processing Agreement (DPA) is a written contract between a data controller (your client) and a data processor (you) that specifies how personal data is used, stored, and protected. It became standard practice after the EU's GDPR took effect in 2018 and is now common across regulated US industries as well.
Under Article 28 of the GDPR, any organization in the EU (or any company that handles data about EU residents) must have a DPA in place with every third party that processes that data on their behalf. That is why European clients, and US firms with EU-based customers, are sending these requests. The DPA documents what you do with the data and what steps you would take if something went wrong.
When Do Clients Ask for a DPA?
Clients typically ask when EU data regulations apply to them, when their industry is subject to a US privacy law with similar requirements, or when their legal team runs a standard vendor-compliance check. It is most common with accounting firms, agencies, and law firms that work with EU-based clients or handle regulated financial data.
- EU and UK clients, or US companies with EU customers: GDPR and UK GDPR both require a DPA with every third-party processor.
- US financial firms, including tax preparers: the Gramm-Leach-Bliley Act Safeguards Rule requires written agreements with any service provider that handles customer financial data.
- Healthcare-adjacent clients: HIPAA uses the term Business Associate Agreement (BAA) rather than DPA, but the contractual structure is the same.
- Large enterprise clients: many run vendor-compliance checklists that include a DPA by default, regardless of regulation.
What a DPA Typically Covers
A standard DPA, whether drafted under GDPR, a US state framework, or a client's internal policy, usually addresses:
- The scope of data being processed: what data, for what purpose, and for how long.
- Security measures the processor has in place.
- Sub-processors: the tools and services you use that also handle the data (email, file-sharing software, cloud storage).
- Breach notification: timelines and steps if data is exposed or lost.
- Data-subject rights: access, correction, and deletion on request.
- Geographic location of data storage.
- Data deletion or return to the client at the end of the engagement.
Does a Small US Firm Actually Need One?
If all of your clients are US-based and outside regulated industries, a DPA may never come up. But if a client asks for one, refusing can cost you the engagement. More practically: having a documented process for how you handle client data is good practice regardless of legal requirements. Consult your legal advisor to understand which rules apply to your specific situation.
One practical step: use file-sharing tools that give you an audit trail you can point to. A dedicated client portal records who uploaded, downloaded, and previewed every file, making sub-processor disclosures concrete rather than theoretical. See how email compares to a dedicated client portal when handling sensitive client documents.
For a broader framework, the NIST Privacy Framework is a practical starting point for mapping the privacy practices your firm has in place before negotiating or signing a DPA.
What to Look for Before You Sign
When a client sends you a DPA to review:
- Check the scope: make sure it describes only the data you actually process, not a broader set you never touch.
- Review the sub-processor list you will need to disclose. Any tool that handles client data -- including file-sharing software -- goes on that list. Review your provider's privacy policy and sub-processor documentation before signing.
- Note breach-notification timing: some agreements require you to notify within 24 to 72 hours of discovering an issue.
- Read the data-deletion clause: you may be required to delete or return all data within a set window after the engagement ends.
- Flag anything that seems out of scope or impractical to your legal advisor before signing.
ProjectSend Cloud gives every client their own access-controlled space, with a full audit trail of every upload, download, and file preview -- the kind of concrete record that backs up what you write in a DPA. Check the security features and start free -- no credit card, no time limit -- from the plans page.
Frequently asked questions
- Do I need to provide a DPA to every client?
- Not necessarily. It depends on whether GDPR, the Gramm-Leach-Bliley Safeguards Rule, or another regulation applies to them. Many smaller US clients will never ask. If they do, it is worth drafting a standard template with a lawyer rather than re-negotiating each time.
- Does ProjectSend Cloud provide a DPA?
- Please review the privacy policy at projectsend.cloud/privacy for current details on data handling and sub-processors. If you have specific compliance requirements, reach out before signing up.
- What is the difference between a DPA and a Business Associate Agreement?
- A Business Associate Agreement (BAA) is the HIPAA equivalent: a written contract with a vendor who handles protected health information. If your clients are in healthcare, they will ask for a BAA. Under GDPR or GLBA, they ask for a DPA.
- What happens if I refuse to sign a DPA a client requests?
- GDPR requires data controllers to work only with processors who can provide sufficient guarantees. In practice, refusing may disqualify you from a contract with EU-based clients. Having a standard DPA ready avoids that friction.
- What is a sub-processor?
- A sub-processor is any third-party tool you use to handle client data, including cloud storage, email, and file-sharing software. DPAs usually require you to disclose them and pass through the same data-protection obligations.
ProjectSend Team. Written by the people who build and maintain ProjectSend, the open source client file portal (since 2011), and run ProjectSend Cloud.
Got a file to send? Start with it.
Drop it on our home page and confirm your email — no account first, no card. On the free plan you get a private link to share it and 2 GB of space, for as long as you need the account.
Or ask Claude or ChatGPT to do it
Connect your assistant to your ProjectSend account and ask in plain words. Everything it does shows up in your account as done by your AI assistant.
- “Save this summary as a PDF and give me a private link for my client.”
- “Did anyone download the contract I shared on Monday?”
- “Create a client account for Dana at Acme and send her the Q3 report.”Pro and Business
Keep reading
- Email Attachments vs. Client Portal
Email covers quick files just fine. Once your documents get sensitive, five things go wrong. A client portal fixes all of them without replacing your inbox.