Sesion / Glossary / Data Processing Agreement (DPA)

Data Processing Agreement (DPA)

Operations

A data processing agreement (DPA) is the contract required when a vendor processes personal data on a hotel's behalf, defining what the processor may do with guest data, its security obligations and what happens on breach or termination.

In practice

Under GDPR the hotel is typically the data controller and its PMS, CRM, messaging and analytics vendors are processors, each requiring a DPA. Reputable hotel tech vendors provide standard DPAs, and their absence is a procurement red flag.

The DPA is also a due diligence tool. It reveals where data is hosted, which subprocessors are involved and how deletion is handled at contract end. Keeping a simple register of vendors and their DPAs turns audits and incidents from panic into paperwork.

← sesion.org · All categories · Advisors · Blog · Glossary