Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Legal Issues To Check Before You Sign
- 1. Roles and responsibility
- 2. Scope of personal information
- 3. Purpose limitation
- 4. Security obligations
- 5. Sub-processors and outsourcing chains
- 6. Overseas disclosure and data location
- 7. Data breach notification
- 8. Assistance with privacy requests and investigations
- 9. Data retention, return, and deletion
- 10. Audit rights and evidence
- 11. Liability, indemnities, and contract hierarchy
- Key Takeaways
- Official Sources to Check
A lot of Australian businesses sign a supplier's data processing terms without really checking what they say. That creates problems fast, especially when customer data is involved, overseas hosting is part of the deal, or the provider's standard wording shifts most of the risk back to you. Common mistakes include assuming the provider's privacy policy is enough, missing clauses that allow broad subcontracting, and accepting security promises that are too vague to enforce.
A proper DPA check helps you work out whether the agreement actually matches your privacy obligations, your customer promises, and the way your business uses data day to day. It also helps you spot where the contract is silent on breach notification, overseas disclosure, deletion of data, audit rights, and liability. If you are about to sign with a software platform, cloud host, payroll system, marketing tool, or outsourced service provider, this guide explains what to review and where Australian businesses usually get caught.
Overview
A DPA, or data processing agreement, sets the rules for how a service provider handles personal information on your behalf. For Australian businesses, the point of a DPA check is to make sure the contract reflects the Privacy Act, your real data flows, and the commercial risk you are actually taking on before you sign.
- Identify who is disclosing data, who is processing it, and whether the provider acts only on your instructions.
- Check what personal information is covered, why it is being used, and whether the stated purposes match your operations.
- Review security commitments, access controls, encryption, retention periods, and backup practices.
- Confirm whether data is stored or accessed overseas, and whether cross border disclosure risks are allocated clearly.
- Look at subcontracting rules, including whether sub-processors can be added without notice.
- Check breach notification timing, cooperation obligations, and who bears response costs.
- Review deletion and return of data at the end of the contract.
- Assess indemnities, liability caps, audit rights, and whether the provider's standard terms leave you exposed.
What DPA Check Means For Australian Businesses
A DPA check is a contract review and privacy review focused on how another business handles personal information for you. It is not just a box-ticking exercise, and it is not the same thing as skimming a privacy policy.
In practice, a DPA often sits inside a SaaS agreement, master services agreement, cloud services contract, outsourcing deal, payroll platform contract, or marketing technology subscription. Sometimes it appears as a separate annex. Sometimes it is buried in online terms that a founder clicks through before the team starts using the product.
The main question is simple: if this provider mishandles personal information, can your business show that it took reasonable steps before it signed?
That matters because many Australian businesses remain accountable for personal information they collect, even when a third party stores or processes it. If your provider sends data offshore, loses it, uses it for a broader purpose, or refuses to delete it when the relationship ends, the commercial and regulatory fallout usually lands on your business first.
When a DPA matters most
A DPA check is especially important before you accept the provider's standard terms in situations like these:
- You use a cloud platform to store customer, patient, employee, or user account data.
- You engage a payroll, HR, bookkeeping, or recruitment provider that handles staff information.
- You use a marketing, CRM, analytics, or customer support tool that collects names, email addresses, phone numbers, behavioural data, or purchase history.
- You outsource development, support, data entry, or back office functions to local or overseas contractors.
- You deal with sensitive information, such as health information, identity documents, financial details, or children's data.
- You have enterprise customers who ask for privacy schedules, security details, or processor terms before signing.
Why Australian privacy law shapes the review
Australian businesses often focus on price, functionality, and implementation timelines. The privacy clauses get less attention until procurement asks questions, a customer demands contractual assurances, or there is a security incident.
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, businesses that are covered by the Act need to think carefully about collection, use, disclosure, storage, overseas disclosure, security, and access to personal information. Even where a smaller business falls outside some Privacy Act obligations, a DPA still matters because contracts, confidentiality duties, customer expectations, and reputational risk do not disappear.
If the provider stores or accesses information outside Australia, cross border disclosure issues become a major part of the DPA check. This is where founders often get caught. The contract may say data can be transferred globally or disclosed to affiliates and sub-processors in multiple jurisdictions, with very little control or visibility from your side.
What a DPA should do in plain English
A sensible DPA should tell you, in workable terms, all of the following:
- What data the provider can handle.
- Why it can handle that data.
- How long it can keep the data.
- What security measures it must maintain.
- Whether it can engage third party sub-processors.
- Where the data will be stored or accessed.
- What happens if there is a data breach.
- What assistance the provider gives if an individual requests access or correction.
- How data is returned or deleted when the contract ends.
- What remedies you have if the provider does not comply.
If those points are vague, missing, or inconsistent with the main agreement, the DPA check has already done its job by showing you where the risk sits before you sign a contract.
Legal Issues To Check Before You Sign
The legal issues to review are usually practical, not theoretical. You want to know whether the contract matches your actual data handling and whether you can rely on the provider's promises if something goes wrong.
1. Roles and responsibility
The contract should clearly state whether the provider processes personal information only on your documented instructions, or whether it has rights to use the data for its own purposes. This distinction affects control, accountability, and risk.
Watch for broad wording that lets the provider use your data to improve its services, develop products, train models, perform benchmarking, or combine information across customers. Some of that use may be acceptable, but only if it is clearly explained and commercially justified.
2. Scope of personal information
The DPA should describe the categories of information being handled. If the agreement says only “customer data”, that may be too loose.
It helps to check whether the data includes:
- Names, contact details, and account credentials.
- Payment-related information.
- Employee records.
- Sensitive information, including health data or identity documents.
- Usage data, location data, device identifiers, or analytics information.
The broader the dataset, the more carefully the rest of the contract needs to be drafted.
3. Purpose limitation
The provider should only process the information for agreed business purposes. If the wording allows use for “internal business operations” or “other compatible purposes”, ask what that actually means before you rely on a verbal promise.
This issue often matters with marketing platforms, AI-enabled tools, support software, and analytics products. Their standard terms may allow wide internal use of customer data unless the DPA narrows it properly.
4. Security obligations
Security language should be specific enough to be meaningful. A promise to use “appropriate technical and organisational measures” may be market standard, but it is often too vague on its own.
Look for concrete commitments such as:
- Encryption in transit and at rest where appropriate.
- Role-based access controls and least-privilege permissions.
- Logging and monitoring.
- Patch management and vulnerability management.
- Staff confidentiality obligations and training.
- Backup, recovery, and business continuity practices.
- Testing and review of security controls.
If your business handles more sensitive data, ask whether the contract should also deal with certifications, penetration testing, or minimum security standards in more detail.
5. Sub-processors and outsourcing chains
Many providers rely on a chain of other vendors. The DPA should say whether sub-processors are allowed, how they are appointed, and whether you receive notice of material changes.
Before you sign, check:
- Whether the provider can appoint new sub-processors without telling you.
- Whether there is a current list of sub-processors.
- Whether equivalent privacy and security obligations flow down to those sub-processors.
- Whether you have any right to object in higher-risk situations.
If the provider cannot tell you where your data may end up, that is a red flag.
6. Overseas disclosure and data location
For Australian businesses, overseas data handling is often the hardest part of a DPA check. The agreement should identify where data is stored or accessed, or at least give a reliable framework for those locations.
You should also check whether the provider can move data between regions without notice. If your customer contracts, internal privacy settings, or procurement commitments assume Australian storage, a generic “global infrastructure” clause may create a conflict.
This matters not just for privacy compliance but also for customer trust, tender responses, and internal risk management.
7. Data breach notification
The DPA should set a clear timeframe for notifying you about an actual or suspected data breach affecting your information. “Without undue delay” is common, but it may not be enough on its own.
Before you sign, consider whether the contract should address:
- When the provider must notify you.
- What information it must give you initially.
- How it updates you as facts develop.
- Who leads containment and remediation.
- Who pays for investigation, notification, and response steps.
If the clause is too soft, your business may lose valuable time dealing with mandatory notification assessments and customer communications.
8. Assistance with privacy requests and investigations
If an individual asks for access to their information, correction of records, or deletion in some contexts, your provider may hold the data needed to respond. The DPA should require reasonable assistance.
The same point applies if a regulator or enterprise customer asks questions about data handling. You do not want the provider saying support is out of scope or chargeable at premium consulting rates unless that was made clear before you signed.
9. Data retention, return, and deletion
One of the most overlooked issues is what happens when the contract ends. A usable DPA should state whether data is returned, exported, deleted, anonymised, or retained for limited legal or backup reasons.
Check for practical details such as:
- How long you have to retrieve data after termination.
- Whether deletion applies to active systems and backups.
- Whether the provider can keep de-identified or aggregated information.
- Whether deletion is certified or merely stated.
This matters before you spend money on setup, because migration away from a provider becomes much harder if end-of-term rights and data retention obligations are weak.
10. Audit rights and evidence
You do not always need a broad audit right, but you do need a realistic way to verify compliance. For smaller businesses, that may mean access to certifications, summaries of security controls, independent reports, or a structured questionnaire response.
If the provider refuses all transparency while asking you to accept broad liability exclusions, the allocation of risk may be out of balance.
11. Liability, indemnities, and contract hierarchy
The commercial clauses can completely change the value of the privacy clauses. A provider may promise strong data protection standards in one schedule, then cap all liability at a month of fees in the main agreement.
Review:
- Whether privacy breaches fall within the general liability cap.
- Whether confidentiality and data misuse claims are carved out.
- Whether you indemnify the provider too broadly for your instructions or data content.
- Which document prevails if the DPA conflicts with the main agreement.
This is often where founders discover that the provider's standard terms are not really negotiable unless the issue is raised early.
Common Mistakes With DPA Check
The most common mistake is treating the DPA as standard paperwork that can wait until after commercial terms are agreed. Once the deal is operationally committed, your leverage usually drops.
Relying on the provider's privacy policy instead of the contract
A privacy policy is not a substitute for enforceable contractual obligations. It may describe general practices, but it usually does not give your business tailored rights on notification, deletion, audit access, or sub-processor control.
Assuming “industry standard” wording protects you
Market wording is not always business-friendly wording. Clauses that sound acceptable at a glance may still allow wide internal use of data, broad overseas transfers, minimal incident notice, or near-total limitation of liability.
Failing to map the real data flow
A DPA check only works if you know what data is actually moving. Businesses often review the agreement before confirming which teams will use the system, whether staff will upload spreadsheets, or whether customers will input sensitive information.
That gap can produce a contract that looks fine on paper but does not match operational reality.
Overlooking subcontracting risk
The visible provider is not always the full picture. Hosting companies, support centres, analytics vendors, email infrastructure, and backup services may all sit underneath the main platform.
If the DPA gives blanket approval to future sub-processors with little transparency, your business may have limited control over where personal information travels.
Ignoring end-of-contract issues
Founders focus on implementation and growth, not exit. But disputes often start at termination, especially where data export tools are poor, deletion takes months, or the provider retains broad rights over aggregated datasets.
Not checking consistency across documents
The order form, master agreement, acceptable use policy, security schedule, support terms, and DPA may all say slightly different things. A common mistake is reviewing the DPA in isolation and missing a conflict elsewhere.
For example, the DPA may say data is processed only on instructions, while the platform terms allow product improvement use. Or the DPA may refer to deletion on termination, while the main agreement allows indefinite retention for legal, operational, or backup purposes.
Leaving privacy review too late in procurement
Internal teams often choose a provider first and escalate the DPA later. That creates pressure to accept weak terms because the business has already invested time in demos, integration planning, and stakeholder approvals.
Here is where a simple internal process helps. Before you sign, identify who checks privacy, security, procurement, and commercial liability issues, and make sure the review happens before implementation is locked in.
FAQs
Is a DPA always required for Australian businesses?
Not always as a standalone document, but if another provider handles personal information for your business, you should have clear contractual terms covering data use, security, breach reporting, and end-of-contract handling. Sometimes those terms sit in a schedule rather than a separate DPA.
What is the difference between a DPA and a privacy policy?
A DPA is a contract between businesses about how data is processed. A privacy policy is a public-facing statement that explains how your business handles personal information. They serve different purposes and one does not replace the other.
Do small businesses need to worry about DPA checks?
Yes. Even if some small businesses are not fully caught by the Privacy Act in every case, they still face contractual risk, confidentiality issues, customer expectations, and reputational exposure if a provider mishandles data.
What if the provider stores data overseas?
You should check where the data is stored or accessed, whether sub-processors are involved, what protections apply, and whether your own customer commitments allow that offshore handling. Overseas hosting is common, but it should be understood and documented before you sign.
Can I rely on a provider's standard online terms?
Sometimes, but only after a real review. Standard terms often work for low-risk tools, yet they can be a poor fit where you handle sensitive information, enterprise customer data, or a high volume of personal information.
Key Takeaways
- A DPA check is a practical review of whether a provider's contract matches your privacy obligations and real data flows.
- Australian businesses should focus on data scope, permitted use, security, overseas disclosure, sub-processors, breach notification, deletion, and liability before they sign.
- The main risk is often not the privacy wording alone, but the way it interacts with the provider's broader commercial terms and liability cap.
- Founders often get caught by vague security promises, broad internal data use rights, hidden subcontracting, and weak end-of-contract deletion rights.
- A good review happens before you accept the provider's standard terms, not after implementation is underway.
If you want help with contract review, privacy compliance, data breach clauses, liability negotiations, you can reach us on 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.
Official Sources to Check
Rules and regulator guidance can change. Check the current official material most relevant to this issue before relying on the article:





