Home Blog DPA vs NDA: Why You Probably Need Both

GDPR

DPA vs NDA: Why You Probably Need Both

Posted by Kevin Yun|August 30, 2026

They are different instruments doing different jobs, and signing one does nothing to discharge the other. An NDA is a private contract in which parties agree to keep information secret. A data processing agreement is a set of terms the GDPR requires whenever someone processes personal data on your behalf, with eight specific obligations listed in Article 28(3). An NDA has never satisfied Article 28.

This article covers what each instrument actually is, the eight terms Article 28(3) demands, why the confidentiality overlap causes the confusion, what happens if you rely on the wrong one, and how the distinction shows up in real vendor paperwork.

What An NDA Is, And What It Is Not

An NDA is ordinary contract law. Two parties agree that certain information will not be disclosed, define what counts as confidential, set a duration, carve out exceptions for information already public or independently developed, and agree a remedy for breach.

Nothing about that is data protection law. An NDA is enforceable between the parties who signed it and creates no rights for anyone else. Crucially, the people whose personal data you are discussing are not parties to it, cannot enforce it, and gain nothing from its existence.

An NDA also protects information in the abstract: source code, pricing, roadmaps, customer lists, anything the definition captures. It does not care whether the information relates to an identifiable person, which is the only thing the GDPR cares about.

The Eight Terms Article 28(3) Requires

Article 28(3) is prescriptive in a way NDAs never are. The contract must set out the subject matter and duration of the processing, its nature and purpose, the types of personal data, the categories of data subjects, and the controller's obligations and rights.

It must then stipulate that the processor:

Processes personal data only on documented instructions from the controller, including as to third-country transfers. Ensures that people authorised to process the data have committed to confidentiality or are under a statutory duty of it. Takes all measures required by Article 32. Respects the conditions for engaging another processor. Assists the controller in responding to data subject requests. Assists with the obligations in Articles 32 to 36, covering security, breach notification and impact assessments. Deletes or returns the data at the end of the service, at the controller's choice. And makes available the information needed to demonstrate compliance, allowing for audits and inspections.

Note the second one. Confidentiality is a single sub-paragraph out of eight, and even there it is narrower than an NDA: it obliges the processor to bind its own authorised personnel, not merely to keep quiet itself.

Why The Overlap Causes The Confusion

Both documents contain a confidentiality clause, both get signed during vendor onboarding, and both arrive from the legal function. It is easy to conclude they are variants of the same thing.

They are not, because they answer different questions. The NDA asks: may you tell anyone? The DPA asks: on whose instructions are you acting, what may you do with the data, who else may touch it, what happens when the customer wants it back, and what happens when something goes wrong.

Confidentiality is one clause of eight in the DPA and the entire substance of the NDA. Reading across from one to the other therefore loses seven obligations, including every one that matters when a service ends or a breach occurs. This is also why a general services agreement with a confidentiality section does not qualify; Article 28 requires the terms, not merely a contract in which secrecy is mentioned.

What Actually Goes Wrong

Three failure modes recur, and none of them involve secrecy.

The first is deletion. An NDA says nothing about returning or erasing data when the relationship ends, so a vendor holding a copy of your customer records after termination is doing nothing wrong under the NDA. Article 28(3)(g) is the term that makes that a breach.

The second is subprocessing. An NDA typically permits disclosure to the recipient's own advisers and affiliates. Article 28 requires authorisation before another processor is engaged, and requires equivalent obligations to flow down. Without it you have no visibility of the chain and no route to object.

The third is instructions. Without documented instructions, a vendor is free to use your data for its own purposes and will often say so in its terms. The clause that prevents a support tool from training a model on your customers' tickets is Article 28(3)(a), not an NDA.

How This Looks In Real Vendor Paperwork

The instruments genuinely are separate in practice, and the vendor DPAs verified for this blog on 7 August 2026 show it clearly.

Typeform's data processing terms sit inside section 4 of its privacy policy, with the help centre confirming no separate signature is needed, which is a useful demonstration that a DPA is a set of obligations rather than a document type. If you are trying to work out where a given vendor's obligations actually live, the pattern across twelve vendors is set out in our look at whether Typeform is GDPR compliant and its neighbours.

Zapier's position is more pointed: its documentation states that it cannot sign DPAs issued by other companies, offering its own instead. Sentry's DPA is opt-in, entered into by the party that electronically accepts it, which means paying for the product does not put one in place. In each case the vendor's NDA, if any, is a separate matter entirely, and none of these arrangements would be discoverable from one.

If you are assembling this paperwork because a customer has sent you a review pack, the wider set of documents buyers ask for is worth understanding before you start, since the first vendor security questionnaire usually arrives with several of them attached. For the contents of the DPA itself, and what each clause is doing, our guide to what a DPA is covers it properly.

Common Mistakes With DPAs And NDAs

Accepting an NDA in place of a DPA. This is the core error. A vendor offering "we'll sign your NDA" when you asked for Article 28 terms has not answered the question, and the gap only becomes visible at termination or after an incident.

Assuming a mutual NDA covers personal data flowing both ways. Direction matters for data protection. Establish who is controller and who is processor for each flow; an NDA is silent on roles and roles determine the obligations.

Signing a DPA with no processing details filled in. Annexes left blank or completed with "as described in the agreement" fail Article 28(3)'s requirement to specify subject matter, duration, data types and categories of data subject.

Treating the DPA as the end of the vendor assessment. The contract records obligations; it does not verify that the vendor meets them. Subprocessor lists, transfer mechanisms and retention settings still need checking against the vendor's live pages.

Forgetting a DPA is needed with contractors as well as companies. A freelance developer with production access is a processor. The instrument is the same one a large vendor would sign, even if the commercial relationship is much smaller.

FAQ

Can an NDA ever satisfy GDPR requirements?

No. Article 28(3) lists eight specific obligations a processor contract must contain, of which confidentiality is one. An NDA covers that single element and none of the others, so it cannot discharge the requirement no matter how comprehensively it is drafted.

Do I need both a DPA and an NDA with the same vendor?

Usually yes. The DPA is mandatory wherever personal data is processed on your behalf. The NDA protects your commercial information, which the DPA does not touch. They cover different material and are often executed at different points in the sales cycle.

Who signs the DPA, us or the vendor?

Both, though increasingly neither signs anything. Many vendors incorporate their terms into the main agreement or make acceptance electronic, so the DPA takes effect without a signature step. Record which version applies and the date it took effect.

Does a DPA need to be a separate document?

No. Article 28 requires a contract or other legal act containing the specified terms; it does not require a standalone file. Terms incorporated into a master agreement or published online and referenced by it can satisfy the requirement perfectly well.

Closing Thought

The reason this confusion persists is that both documents feel like the same kind of obstacle: paperwork between you and a signed deal. Treated that way, whichever one arrives first gets filed and the other never gets chased.

They are not the same kind of obstacle. The NDA protects you from your vendor. The DPA protects your customers' data from both of you, and it is the one a regulator will ask to see. ComplyDog handles DPA signing through DocuSign and Dropbox Sign integrations and hosts your subprocessor list and security page on your own domain, which turns the recurring version of this request into a link. It does not draft your NDA, which remains a job for a lawyer who knows your commercial position.