top of page

Founders - If you're in the business of collecting data, don't DIY the DPA

Aug 17
3 min read

At the risk of sounding like I regularly don a tin-foil hat, I firmly believe data is one of the most valuable assets (and dangers) in our society today. 


As individuals, we routinely trade our data - our privacy - for access to services that are free: social media, technology conveniences (yes, I'm talking about Siri who always seems to be ready to chat whenever I mention "cereal"). Whether those services are truly "free" is a conversation for another time, but the key point is this: individuals should get to make that decision for themselves.


As a founder, if you are in the business of collecting, storing, or processing data, you are in a position of great trust and with it comes great responsibility. This is where many founders underestimate their exposure.


Data protection is not just a compliance box to check or a document to sign and forget. It is a core business risk issue. Even if you're not collecting anything sensitive, like social security numbers. When something goes wrong, whether it is a breach, a rogue vendor, or unclear data handling practices, the consequences do not land on the platform that made the mistake. They land on you.


That is why mechanisms like Data Processing Agreements (DPAs) matter.


DPAs are not bureaucracy for bureaucracy’s sake. They are the legal framework that governs what happens to data once it leaves your hands and enters a vendor’s systems. If you use cloud hosting, payroll providers, CRMs, analytics tools, or marketing platforms, you are almost certainly relying on DPAs, whether you realize it or not.


So, what is actually in a DPA?

At a minimum, a well-drafted DPA should clearly address:


  • What data is being processed and for what purpose

  • Who owns and controls the data, and who is responsible for it

  • How the data must be protected, including required security measures

  • Limits on use and access, including whether subcontractors are allowed

  • Breach notification obligations, including timing and responsibility

  • Support for data subject rights, such as access, deletion, or correction requests

  • What happens to the data when the relationship ends, including return or destruction


In simple terms, a DPA answers the uncomfortable but essential question:

“What happens to our users’ data when something goes wrong?”


Founders often sign vendor DPAs without reading them, assume “industry standard” terms are sufficient, or postpone addressing them until a deal stalls or an incident occurs. By then, leverage is gone, and so are the options.


Tips on how to review a DPA: 

When reviewing a DPA, the goal is not to memorize GDPR articles or negotiate every clause. The goal is to understand where risk flows when things break.

Here are the questions founders should ask:


1. Who is wearing the risk if the vendor messes up? 

Look beyond breach notification timelines. Focus on indemnities, caps on liability, and exclusions. Many DPAs impose strict obligations on processors while quietly carving out meaningful remedies for you.


2. Are the security obligations concrete or aspirational? 

“Industry standard security measures” sounds comforting until you realize it is undefined. Strong DPAs either attach security controls or tie them to recognized frameworks.


3. What subcontractors are actually allowed? 

Open-ended subprocessor clauses shift risk downstream in ways you can’t see. The more critical the vendor, the more transparency and control you should demand.


4. What happens after termination? 

Data deletion clauses are often vague, delayed, or conditioned on internal backup policies. If the relationship ends badly, this is where disputes surface.


5. Does the DPA scale with your business? 

Many “standard” DPAs are written for low-risk use cases. If your product grows, expands internationally, or becomes data-critical, yesterday’s acceptable DPA becomes tomorrow’s liability.


If data is part of your business model, data protection must be part of your legal strategy. DPAs are not just about regulatory compliance. They are about trust, accountability, and protecting the future of your company.

Because when data is an asset, protection is the price of doing business.


*Disclaimer: This newsletter is for informational purposes only and does not constitute legal advice.

 
 
 

Comments


bottom of page