DPA Agreement Template for South Africa
Generate a bespoke document
What is a DPA Agreement?
A Data Processing Agreement (DPA) is a legally binding contract that is mandatory under South African law when one organization (the data processor) processes personal information on behalf of another organization (the data controller). This document type is specifically required by the Protection of Personal Information Act (POPIA) and must be in place before any processing of personal information begins. The DPA Agreement includes essential provisions such as the scope of processing, security measures, confidentiality obligations, and procedures for handling data breaches. It's particularly crucial for compliance with South African data protection regulations and may also need to consider international standards when dealing with cross-border data transfers. The agreement serves as a critical tool for ensuring accountability and establishing clear responsibilities in data processing relationships.
Trusted by high-performance teams
About the DPA Agreement
A Data Processing Agreement (DPA) is a fundamental legal document required under South Africa's Protection of Personal Information Act (POPIA) that establishes the contractual relationship between organizations when personal information is processed by third parties. Under POPIA, you must have a written DPA in place before any data processor begins handling personal information on your behalf, making this document essential for legal compliance and data protection.
When do you need this document?
You need a DPA Agreement whenever your organization engages a third-party service provider to process personal information on your behalf. This includes cloud storage providers, payroll companies, marketing agencies handling customer data, IT support services accessing employee information, or any outsourced function involving personal data. The agreement is also required when appointing sub-processors, establishing data sharing arrangements with business partners, or engaging international service providers that may transfer data outside South Africa. POPIA mandates that the DPA must be signed before any processing activities commence, making it a prerequisite for lawful data processing relationships.
Key legal considerations
Your DPA must clearly define the scope and purpose of data processing, specifying exactly what personal information will be processed and for what purposes. The agreement must establish comprehensive security measures that both parties will implement, including technical and organizational safeguards to protect personal data. You need to include provisions for data breach notification procedures, ensuring the data processor will notify you immediately of any security incidents. The contract must address data subject rights, establishing procedures for handling access requests, corrections, and deletions. Additionally, you must include clauses covering the return or destruction of personal information upon termination of the agreement, and restrictions on the processor's ability to engage sub-processors without your prior written consent.
Legal requirements in South Africa
Under POPIA, your DPA must comply with specific statutory requirements outlined in Section 21 of the Act. The agreement must ensure that personal information is processed only on your documented instructions as the data controller, and the processor must implement appropriate technical and organizational measures to secure the data. You must include provisions requiring the processor to assist with data protection impact assessments when necessary and to cooperate with the Information Regulator during investigations. The contract must address cross-border data transfers if applicable, ensuring adequate protection levels in recipient countries or implementing appropriate safeguards. Your DPA should also designate an Information Officer as required by POPIA and establish clear procedures for handling complaints and regulatory inquiries. The agreement must be governed by South African law and include dispute resolution mechanisms within South African jurisdiction.
GOVERNING LAW
Applicable law
This DPA Agreement is drafted to comply with South Africa law. Key legislation includes:
Constitution of South Africa (Section 14): Establishes the fundamental right to privacy, which forms the constitutional basis for data protection in South Africa.
Electronic Communications and Transactions Act (ECTA): Governs electronic communications and transactions, including provisions relevant to the electronic storage and transmission of personal information.
Consumer Protection Act: Contains provisions relating to consumer privacy and the protection of consumer information in commercial transactions.
Promotion of Access to Information Act (PAIA): Regulates access to information and should be considered in DPAs regarding data subject access requests and transparency requirements.
Regulation of Interception of Communications Act (RICA): Relevant for provisions regarding the interception and monitoring of communications, which may be applicable in data processing scenarios.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

