DPA Check: Audit Data Processing Agreements and Privacy Compliance

Alex Solo
byAlex Solo11 min read

If your business uses a payroll platform, CRM, email marketing tool, cloud storage provider or outsourced support team, you are probably sharing personal information with someone else to handle on your behalf. That is where a DPA check matters. Many New Zealand businesses sign the provider's standard terms without checking who is actually responsible for security, whether overseas transfers are allowed, or what happens after a data breach. Another common mistake is assuming a privacy policy fixes everything, even when the contract with the service provider says very little about deletion, subcontractors or audit rights.

A proper DPA check helps you work out whether your data processing agreement matches your Privacy Act 2020 obligations and your real business practices. Before you sign a contract, before you accept the provider's standard terms, and before you rely on a verbal promise about security or data hosting, it pays to review the details carefully. This guide explains what a DPA check covers, what New Zealand businesses should look for, where founders often get caught, and how to spot clauses that need negotiation.

Overview

A DPA check is a legal and practical review of the contract terms that apply when another party handles personal information for your business. The aim is to make sure the agreement reflects New Zealand privacy requirements, allocates risk sensibly, and matches how data is actually collected, stored, used and deleted.

  • Identify who is acting as the agency and who is acting as the service provider or processor in practice.
  • Check what personal information is being handled, for what purpose, and under whose instructions.
  • Review security commitments, breach notification timing, and incident response obligations.
  • Confirm whether information is stored or accessed outside New Zealand and what safeguards apply.
  • Check whether subcontractors or sub-processors can be used, and on what notice.
  • Review retention, return and deletion obligations at the end of the contract.
  • Look at indemnities, liability caps, audit rights and any clauses that shift too much risk onto your business.
  • Make sure the agreement lines up with your privacy policy, internal processes and customer promises.

What DPA Check Means For New Zealand Businesses

A DPA check means checking whether your contracts actually support your privacy compliance, not just whether the document has the right title.

In New Zealand, privacy obligations generally sit under the Privacy Act 2020. If your business collects personal information and uses another provider to store, analyse, transmit or otherwise handle that information, you still need to take reasonable steps to protect it. Outsourcing the function does not outsource responsibility for getting the basics right.

That matters for startups and SMEs because modern operations rely heavily on third party tools. A small ecommerce brand may use a website host, payment platform, fulfilment app and customer support software. A professional services firm may use cloud document storage, AI tools, bookkeeping software and a virtual assistant. A healthcare-adjacent business may engage appointment software and offshore support. In each case, personal information can move through several providers very quickly.

When Do You Need A DPA Check?

You should consider a DPA check before you sign any service arrangement where another party will process personal information for your business. This is especially relevant when the provider will host customer records, staff records, marketing lists, usage data, support tickets or sensitive information.

Founder moments where this usually comes up include:

  • before you sign up to a SaaS platform that stores customer data
  • before you move records into a cloud system
  • before you engage an outsourced admin, support or development team
  • before you accept the provider's standard terms for payroll, HR or CRM software
  • before you migrate data to a provider with offshore servers
  • before you renew a supplier contract after your business has grown and the volume of personal information has changed

Why The Privacy Act 2020 Matters

The Privacy Act 2020 sets out privacy principles around collection, use, storage, access, correction and disclosure of personal information. For many businesses, the practical issue is not whether those principles exist, but whether day to day contracts support them.

If a provider suffers a security incident, delays telling you, refuses to delete data after termination, or appoints unknown subcontractors overseas, your business can end up exposed. A DPA check helps reduce that gap between legal responsibility and operational reality.

What Counts As Personal Information?

Personal information is broader than many founders expect. It is not limited to passport details or medical records. It can include:

  • customer names, emails, phone numbers and addresses
  • employee records and HR notes
  • IP addresses and online identifiers where they can relate to an individual
  • support tickets and chat logs
  • marketing preferences and purchase history
  • photos, voice recordings and device data
  • information that becomes sensitive because of context, such as complaint records or performance notes

If your supplier handles any of that on your behalf, the contract deserves a closer look.

Why A DPA Is Different From A Privacy Policy

A privacy policy explains to individuals how your business collects, uses and discloses their personal information. A DPA or equivalent processing clause deals with your relationship with the service provider handling that information for you.

This is where founders often get caught. They invest time in website privacy wording and collection notices, but accept supplier terms that say almost nothing about security standards, breach reporting, deletion or subcontracting. The external statement and the internal contract then do not match.

The right DPA check focuses on the clauses that control risk when things go wrong, not just the definitions page.

1. Roles And Instructions

The agreement should make clear whether the provider is handling information only on your documented instructions, or whether it has broader rights to use the data. If the provider can use data for its own analytics, product training, profiling or marketing, you need to know that before you sign.

Check whether the contract clearly covers:

  • the purpose of processing
  • the categories of personal information involved
  • the categories of individuals affected, such as customers, staff or end users
  • the provider's obligation to act only on your instructions, subject to legal requirements

Vague wording creates room for later disputes.

2. Security Standards

The agreement should say what security measures the provider will maintain, and those promises should be specific enough to be useful.

Look for clauses dealing with:

  • access controls and authentication
  • encryption in transit and at rest, where appropriate
  • staff confidentiality obligations
  • vulnerability management and testing
  • data segregation in multi-tenant systems
  • backups, disaster recovery and business continuity

If the contract only says the provider will use commercially reasonable efforts, ask whether that is enough for the type of information involved.

3. Privacy Breach Notification

The contract should require the provider to notify you promptly if it becomes aware of a privacy or security incident affecting your data. Promptly should ideally mean a clear timeframe, not a vague promise to notify without undue delay.

Before you accept the provider's standard terms, check:

  • how quickly notice must be given
  • what details the provider must include in the notice
  • whether the provider must cooperate with your investigation
  • whether the provider must preserve evidence and help with remediation
  • who controls external communications and notices to affected individuals

Under New Zealand law, some privacy breaches may be notifiable. Delayed notice from a supplier can make your own compliance much harder.

4. Overseas Disclosure And Data Hosting

If personal information will be stored or accessed outside New Zealand, the contract should say where, by whom and on what basis. Overseas hosting is common, but it should never be treated as a minor footnote.

Questions to pin down include:

  • which countries will host or receive the data
  • whether support staff in other countries can access it remotely
  • what safeguards or contractual protections apply
  • whether data transfers can be changed during the term without notice

This is especially important where the data set includes employee records, financial details, health-related information or vulnerable customer information.

5. Sub-processors And Subcontractors

The provider should not have unlimited freedom to hand your data to unknown third parties. Most modern providers use subcontractors, but the contract needs controls around that.

Check for:

  • a list of current sub-processors, or at least a mechanism to access it
  • notice before new sub-processors are appointed
  • a right to object in appropriate cases
  • the provider's obligation to impose equivalent privacy and security terms on subcontractors
  • continued liability by the main provider for subcontractor failures

If a provider says it can use any affiliate or supplier at any time on any terms, that is a red flag.

6. Retention, Return And Deletion

The agreement should tell you what happens to the data when the contract ends. Many businesses assume the provider will delete everything automatically. That assumption is often wrong.

You want clarity on:

  • how long data is retained during the term
  • what happens on termination or expiry
  • whether your business can request return of data in a usable format
  • when deletion must occur
  • whether backups are also deleted, anonymised or retained for a limited period
  • whether the provider can keep copies for legal or operational reasons, and if so, under what limits

7. Audit Rights And Evidence Of Compliance

You do not always need an intrusive audit clause, but you do need enough comfort that the provider can demonstrate compliance. For smaller businesses, this may mean security certifications, independent reports, policy summaries or questionnaire responses rather than on-site inspections.

The key issue is whether you have any practical way to verify the promises being made.

8. Liability, Indemnities And Contract Priority

Risk allocation matters just as much as privacy wording. A supplier may promise strong controls in a DPA schedule, then neutralise those promises with a low liability cap or broad exclusions in the main terms.

Before you sign a contract, compare:

  • the liability cap for privacy and confidentiality breaches
  • any exclusions for indirect loss
  • indemnities for third party claims
  • whether data breach costs are expressly covered
  • which document prevails if the DPA conflicts with the master services agreement

If the DPA says one thing and the main agreement says another, the priority clause can decide the outcome.

9. Assistance With Privacy Requests

If an individual asks for access to their information or requests a correction, your provider may hold the records you need. The agreement should require reasonable assistance so your business can respond properly and on time.

This often gets missed in standard software terms, especially where the platform is sold globally and not adapted for New Zealand privacy expectations.

Common Mistakes With DPA Check

The most common DPA check mistake is treating the document as routine admin instead of a real risk allocation exercise.

Assuming Big Providers Do Not Negotiate

Some larger providers will not rewrite every clause, but many will answer security questionnaires, share supporting documents, offer alternative schedules, or confirm operational points in writing. Even where the legal terms stay mostly standard, you can still identify risk and decide whether the product is suitable.

Do not assume no review is needed just because the supplier is well known.

Reviewing Only The DPA And Not The Main Contract

A processing schedule rarely stands alone. The main subscription terms, order form, acceptable use policy and service description can all affect privacy risk. This is where liability caps, suspension rights, termination rights, and subcontractor powers often sit.

A useful DPA check reads the full contract set together.

Failing To Match The Contract To Actual Data Flows

Founders often review the paper but not the workflow. The agreement might say one thing, while staff are exporting spreadsheets, using personal devices, forwarding emails, or connecting extra integrations that widen the data footprint.

Ask practical questions such as:

  • who uploads the data
  • who can access it internally
  • what integrations are switched on
  • whether test environments contain live personal information
  • whether the provider can use support access tools to view records

If the real process is messier than the contract assumes, privacy compliance can break down quickly.

Ignoring Renewals And Legacy Suppliers

Many SMEs do a careful review when first buying software, then leave the contract untouched for years. Meanwhile the business grows, more staff use the platform, extra modules are added and more sensitive data is uploaded.

Legacy supplier arrangements deserve periodic review, especially after a product expansion, acquisition, process change or offshore support rollout.

Relying On Sales Statements Instead Of Contract Terms

A sales call might mention New Zealand hosting, strict encryption or deletion on cancellation. If those promises do not appear in the contract or supporting documents, they can be difficult to enforce later.

Before you rely on a verbal promise, ask for it to be reflected clearly in the signed terms or documented schedule.

Missing Internal Privacy Documents

A DPA check should line up with your internal and external privacy documents. If your customer-facing notices say you only share information where necessary, but your supplier terms allow broad internal reuse or open-ended subcontracting, there is a mismatch.

Consistency matters across:

  • privacy policies
  • customer contracts
  • employee notices
  • internal data handling policies
  • supplier onboarding processes

Treating Deletion As An Afterthought

The end of the contract is often where hidden risk sits. Old backups, dormant accounts and archived exports can keep personal information alive long after the service relationship ends.

If deletion and return processes are not clear before you sign, sorting it out later can be expensive and disruptive.

FAQs

Is a DPA always a separate document?

No. Sometimes the processing terms sit in a schedule, annexure or privacy section of the main services agreement. The key issue is the substance of the terms, not the document title.

Do small New Zealand businesses need to worry about DPAs?

Yes. If a small business uses third party providers to handle customer, staff or user information, the same practical privacy issues arise. The scale may be smaller, but the contractual risks are still real.

What if the provider stores data overseas?

That does not automatically make the arrangement unlawful, but it does mean you should check where the data goes, what safeguards apply and whether the contract supports your Privacy Act obligations.

Can I just rely on the provider's privacy policy?

No. A privacy policy is usually written for general information and may not create the contractual protections your business needs. You should review the binding contract terms as well.

How often should a business do a DPA check?

Review before you sign, on major renewals, when data use changes, when sensitive information is added, or after a material security incident or supplier restructure.

Key Takeaways

  • A DPA check reviews whether your supplier contracts properly deal with personal information handling, security, breach response, overseas transfers and deletion.
  • New Zealand businesses remain responsible for privacy compliance even when a third party processes information on their behalf.
  • Before you sign, compare the DPA terms with the main contract, your privacy policy and your actual data flows.
  • Pay close attention to security commitments, breach notification timing, sub-processor controls, retention rules and liability caps.
  • Do not rely on sales statements or verbal promises. Important privacy and security assurances should appear in the contract documents.
  • Periodic reviews matter, especially when your business grows, adds new systems, or starts sharing more sensitive information with providers.

If you want help with supplier contracts, privacy compliance, overseas data transfer terms, liability clauses, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.

Get your customer-facing terms right

When should you formalise this?

If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.

Alex Solo
Alex SoloCo-Founder

Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.

Get your customer-facing terms right

Get in touch with our team

Tell us what you need and we'll come back with a fixed-fee quote - no obligation, no surprises.

Need support?

Need help with your business legals?

Speak with Sprintlaw to get practical legal support and fixed-fee options tailored to your business.