Data Processing Agreement

How personal information is handled between you and your customer.

A contract required whenever a vendor processes personal data on a business's behalf, setting out what the vendor can do with that data, security obligations, and what happens in a breach. Under Canadian privacy law (PIPEDA), a business remains responsible for personal data even after handing it to a third party, so a DPA is how that responsibility gets allocated in writing.

Business days
1–5Business days
Lawyer reviewed
100%Lawyer reviewed
Surprise bills
$0Surprise bills

What a Data Processing Agreement should include

  1. Roleswho determines the purpose of the processing and who processes on the other's behalf.

  2. Scope of processingwhat categories of personal information, for what purpose, and for how long.

  3. Sub-processorswho else touches the data, and whether the customer must approve additions.

  4. Security measuresthe safeguards you commit to, described specifically enough to be meaningful.

  5. Breach notificationhow quickly you tell the customer, and what information you provide.

  6. Return and deletionwhat happens to the data when the relationship ends.

When you need one

When you handle personal information on a customer's behalf and they ask for one — which enterprise and public-sector buyers routinely do. In Canada the governing frameworks are PIPEDA federally and, for Quebec, the province's Law 25; a DPA drafted only against European requirements will not necessarily address either.

How Ruby drafts it

  1. Tell us what you need

    Describe the agreement, your business context, and how fast you need it. A few smart questions, not a legal questionnaire. Your price and turnaround are confirmed before anything starts.

  2. Ruby drafts it

    Once pricing is confirmed a qualified Ruby lawyer is assigned to your file, and the first draft is built from your answers and real Canadian statute.

  3. A licensed lawyer reviews every line

    A lawyer licensed in Canada reviews and finalizes the document before it reaches you, and writes the plain-language summary that comes with it.

  4. Signed, stored, and yours to revisit

    You get the final agreement and its summary, stored so you can come back to it rather than hunting through email for the current version.

The fee is set before any of that starts. Hourly billing moves as scope does; a flat fee is one number, confirmed in writing, that doesn’t change after the work is done. See how Ruby prices agreements.

Questions people ask

No. A privacy policy is a public notice to the individuals whose information you collect. A DPA is a contract between two businesses about handling information one of them is responsible for. Most SaaS companies need both, for different audiences.

You still need the agreement, and where the data lives becomes one of the terms in it. Canadian customers increasingly ask about data residency and about disclosure to foreign authorities, so it is worth knowing your answer before it is asked.

Yes, and that is common — a DPA attached to a SaaS agreement or MSA is easier to keep consistent than a standalone document negotiated separately.

Looking for the plain definition rather than the document? See Data Processing Agreement in the Ruby legal glossary.

This page is general information about Canadian business law and is not legal advice. Laws differ by province and change over time, and how they apply depends on your circumstances. For advice on your situation, speak with a lawyer licensed in your province.

Need a Data Processing Agreement?

Ruby drafts it for a flat $799 CAD, confirmed before any work begins, with a licensed Canadian lawyer on every document.

Ask Ruby
Call usSubmit your matter