Data Processing Agreement
How personal information is handled between you and your customer.
A contract required whenever a vendor processes personal data on a business's behalf, setting out what the vendor can do with that data, security obligations, and what happens in a breach. Under Canadian privacy law (PIPEDA), a business remains responsible for personal data even after handing it to a third party, so a DPA is how that responsibility gets allocated in writing.
- Business days
- 1–5Business days
- Lawyer reviewed
- 100%Lawyer reviewed
- Surprise bills
- $0Surprise bills
What a Data Processing Agreement should include
Roles — who determines the purpose of the processing and who processes on the other's behalf.
Scope of processing — what categories of personal information, for what purpose, and for how long.
Sub-processors — who else touches the data, and whether the customer must approve additions.
Security measures — the safeguards you commit to, described specifically enough to be meaningful.
Breach notification — how quickly you tell the customer, and what information you provide.
Return and deletion — what happens to the data when the relationship ends.
When you need one
When you handle personal information on a customer's behalf and they ask for one — which enterprise and public-sector buyers routinely do. In Canada the governing frameworks are PIPEDA federally and, for Quebec, the province's Law 25; a DPA drafted only against European requirements will not necessarily address either.
How Ruby drafts it
Tell us what you need
Describe the agreement, your business context, and how fast you need it. A few smart questions, not a legal questionnaire. Your price and turnaround are confirmed before anything starts.
Ruby drafts it
Once pricing is confirmed a qualified Ruby lawyer is assigned to your file, and the first draft is built from your answers and real Canadian statute.
A licensed lawyer reviews every line
A lawyer licensed in Canada reviews and finalizes the document before it reaches you, and writes the plain-language summary that comes with it.
Signed, stored, and yours to revisit
You get the final agreement and its summary, stored so you can come back to it rather than hunting through email for the current version.
The fee is set before any of that starts. Hourly billing moves as scope does; a flat fee is one number, confirmed in writing, that doesn’t change after the work is done. See how Ruby prices agreements.
Or did you mean one of these?
These get confused with a Data Processing Agreement often enough to be worth ruling out before you buy the wrong document.
Questions people ask
No. A privacy policy is a public notice to the individuals whose information you collect. A DPA is a contract between two businesses about handling information one of them is responsible for. Most SaaS companies need both, for different audiences.
You still need the agreement, and where the data lives becomes one of the terms in it. Canadian customers increasingly ask about data residency and about disclosure to foreign authorities, so it is worth knowing your answer before it is asked.
Yes, and that is common — a DPA attached to a SaaS agreement or MSA is easier to keep consistent than a standalone document negotiated separately.
Looking for the plain definition rather than the document? See Data Processing Agreement in the Ruby legal glossary.
This page is general information about Canadian business law and is not legal advice. Laws differ by province and change over time, and how they apply depends on your circumstances. For advice on your situation, speak with a lawyer licensed in your province.
Need a Data Processing Agreement?
Ruby drafts it for a flat $799 CAD, confirmed before any work begins, with a licensed Canadian lawyer on every document.
