A Data Processing Agreement is the contract GDPR (Article 28) requires whenever one company processes personal data on another's behalf. With an HR system the roles are unambiguous: your company is the controller — it decides why and how employee data is used — and the software vendor is the processor, storing and handling that data strictly on your instructions.
A proper DPA pins down:
- What is processed and why — the data categories and purposes, in writing.
- Sub-processors — the hosting and email providers underneath, plus the duty to announce changes to that list.
- Security measures and breach notification — what protections exist and how fast you hear about incidents.
- End of contract — return or deletion of the data, not an ambiguous archive.
- Transfers — safeguards if any data leaves the EU/EEA.
Practically, the DPA is a prerequisite, not a formality. An HR tool holds exactly the categories regulators and auditors care about — identity documents, compensation, absence records — so a vendor that cannot produce one breaks your own GDPR posture from day one. It is routinely the first document a privacy-conscious client's lawyer or a due-diligence questionnaire asks for.
In Helia, the Data Processing Agreement is published on the security pages and available to every customer; the product itself is EU-hosted, access to PII is role-gated, and an audit log records who accessed what.