Helia HR

DPA (Data Processing Agreement)

The GDPR-required contract between a company (controller) and a vendor processing personal data on its behalf (processor). For an HR system, mandatory paperwork — not a formality.

A Data Processing Agreement is the contract GDPR (Article 28) requires whenever one company processes personal data on another's behalf. With an HR system the roles are unambiguous: your company is the controller — it decides why and how employee data is used — and the software vendor is the processor, storing and handling that data strictly on your instructions.

A proper DPA pins down:

  • What is processed and why — the data categories and purposes, in writing.
  • Sub-processors — the hosting and email providers underneath, plus the duty to announce changes to that list.
  • Security measures and breach notification — what protections exist and how fast you hear about incidents.
  • End of contract — return or deletion of the data, not an ambiguous archive.
  • Transfers — safeguards if any data leaves the EU/EEA.

Practically, the DPA is a prerequisite, not a formality. An HR tool holds exactly the categories regulators and auditors care about — identity documents, compensation, absence records — so a vendor that cannot produce one breaks your own GDPR posture from day one. It is routinely the first document a privacy-conscious client's lawyer or a due-diligence questionnaire asks for.

In Helia, the Data Processing Agreement is published on the security pages and available to every customer; the product itself is EU-hosted, access to PII is role-gated, and an audit log records who accessed what.

Track it instead of defining it

Helia gives IT services teams the directory, capacity matrix, time off and client invoicing behind these numbers — in one place.