In everyday use, Data Processing Agreement and Data Processing Addendum describe the same thing: a contract that satisfies Article 28(3) of the General Data Protection Regulation (GDPR) by governing how a processor may handle personal data for a controller. Neither term appears in the GDPR itself, which speaks only of a contract or other legal act.
The difference is structural rather than legal. An agreement is typically a standalone contract that the parties sign in its own right. An addendum is a document that attaches to an existing agreement, such as a master services agreement or a set of online terms, and takes its commercial framework, term, and often its liability provisions from that parent document.
That distinction rarely changes whether you are compliant. It frequently changes what you should check.
Why the naming is inconsistent
The market settled on different conventions for different sales motions. Enterprise suppliers negotiating bespoke contracts often produce a schedule or annex inside the master agreement. Volume software suppliers publish a standard addendum on a web page and incorporate it by reference into their online terms. Some organizations use a standalone agreement because their supplier relationships have no other written contract to attach to.
All three approaches can satisfy Article 28(3). What matters is that a binding instrument exists, that it contains the mandatory content, and that you can produce the version you actually agreed to.
Where the difference genuinely matters
Four practical consequences follow from the structure, and each is worth a specific check.
Which document governs when they conflict
An addendum sits inside a hierarchy. The parent agreement usually contains an order-of-precedence clause, and it may or may not place the data protection terms above the commercial terms. Check that the data protection provisions prevail over conflicting general provisions for matters within their scope, because a generously drafted confidentiality clause in a master agreement can otherwise undercut a narrower processing instruction.
Whether the terms can change without you
A standalone signed agreement changes only when both parties sign something new. An addendum incorporated by reference to a web page can change when the supplier updates that page, subject to whatever notice the parent terms require.
This is the single most consequential difference. If your contract points at a URL, the terms binding you are the terms at that URL, and you should be capturing the version you relied on rather than trusting the link to stay still. The same reasoning applies to sub-processor lists published as pages, which is why our article on why subprocessor lists change treats those pages as living documents rather than fixed disclosures.
What the liability position actually is
Addenda commonly inherit the liability cap of the parent agreement. That is not automatically unreasonable, but it should be a decision rather than a surprise. Read the cap, read any carve-outs, and confirm whether data protection breaches sit inside or outside the general limitation.
What term and termination apply
An addendum usually lives and dies with the parent agreement. A standalone agreement may have its own term. The practically important question is what happens to the data at the end: whether return or deletion obligations survive termination, on what deadline, and with what treatment of backups. Our guide to vendor offboarding and deletion evidence covers what to require and what to keep.
What to check regardless of the label
Whichever instrument you are handed, the substantive review is the same, because Article 28(3) does not care about the filename. Confirm that the document contains:
- A specific description of the processing, its duration, nature, and purpose.
- The categories of personal data and of data subjects.
- A documented-instructions clause covering international transfers.
- Confidentiality obligations on authorized personnel.
- Security measures described specifically enough to be tested.
- The sub-processing model, with notice and objection mechanics.
- Assistance with data subject rights, breach notification, and impact assessments.
- Deletion or return at the end of the service, with deadlines.
- Information and audit rights that can be exercised in practice.
Our GDPR Article 28 requirements guide works through the clause content, and the review checklist turns it into a sequence you can run. If you are meeting the instrument for the first time, start with what a Data Processing Addendum is.
A note on schedules, annexes, and exhibits
You will also encounter the processing terms as Schedule 2, Annex A, or an exhibit to a master agreement. Treat these exactly as you would an addendum. The questions are unchanged: does it contain the mandatory content, does it prevail over conflicting terms, can it change unilaterally, and can you produce the version in force on a given date.
Frequently asked questions
Does the GDPR require one form over the other?
No. Article 28(3) requires a contract or other legal act that is binding on the processor and sets out the specified content. It is silent on structure and on what the document is called.
Is an addendum weaker than an agreement?
Not inherently. An addendum that contains the mandatory content and prevails over conflicting terms is as effective as a standalone agreement. Weakness comes from inherited limitations, unilateral change rights, or missing content, not from the format.
The supplier published its addendum on a web page. Is that acceptable?
It can be, provided the parent terms incorporate it properly and the supplier is bound by it. The operational duty that comes with it is yours: capture the version you accepted, with a date, and notice when it changes.
Which should we ask for?
Ask for whichever the supplier can execute quickly, then spend the review effort on content and on the change-control position. Insisting on a particular structure usually costs negotiation time without improving the outcome.
Where DPAFlow fits in
The risk this article keeps returning to is drift: terms and disclosures that change on a supplier's website after you have relied on them. DPAFlow checks vendor Data Processing Agreement pages, sub-processor lists, and trust-center pages on a scheduled, recurring basis, records what changed with dated evidence including captured page text and change differences, and sends email alerts so the change reaches a person rather than sitting unnoticed.
Your team decides whether a change is material and what follows. DPAFlow does not interpret contracts and does not provide legal advice. The evidence model is described on the evidence page, and the workflow for legal reviewers on the legal use case page.
This article describes a structural distinction in general terms. It is not legal advice, and the contractual calls belong to your counsel.