Data Processing Agreement Glossary
A Data Processing Agreement (DPA) is a contract that defines how a vendor may handle data provided by a customer or institution. In education, the term matters because AI tools often process student data, assessment material, communications, or institutional records. A useful tool may still be unsuitable for protected data if the vendor relationship lacks the required legal and operational safeguards.
A good DPA addresses permitted use, retention, deletion, subcontractors, security controls, breach notification, audit rights, and whether data may be used for model training. Without such an agreement, sending protected student information to a third-party AI system may create compliance risk even if the pedagogical use is sensible.
This is one reason local-first architectures are attractive. If an institution processes protected data on infrastructure it controls, without an outside processor, the vendor-contract problem may shrink substantially. Other privacy, security, retention, and access obligations remain.
Source
- European Union, General Data Protection Regulation, Article 28, Processor: https://eur-lex.europa.eu/eli/reg/2016/679/art_28/oj