A GDPR Data Processing Agreement and a HIPAA Business Associate Agreement are not interchangeable, even though both control how third parties handle sensitive data. A GDPR DPA covers personal data processed for a controller in the EU or UK context. A BAA covers protected health information under HIPAA when a vendor works with a covered entity or another business associate.

TLDR: A GDPR DPA is built around controller processor duties, data subject rights, international transfers, and Article 28 requirements. A BAA is built around HIPAA rules for protected health information, permitted uses, safeguards, and breach reporting. For example, a telehealth company using a cloud analytics tool may need a GDPR DPA for EU patient account data and a BAA for U.S. patient treatment records. In one vendor review of 50 SaaS tools, a privacy team might find that 70% offer a standard DPA, but only 25% will sign a BAA.

What a DPA Agreement Means

The phrase “DPA agreement” is often used loosely. In GDPR work, it usually means a Data Processing Agreement. This contract is required when a controller uses a processor to handle personal data on its behalf.

Under GDPR, the DPA must spell out what data is processed, why it is processed, how long it is kept, and what security controls apply. It must also cover subprocessors, audit rights, deletion, return of data, and help with data subject requests.

The annoying part is that many vendors bury these terms in separate links, security exhibits, and product pages. A legal team can lose 20 minutes just checking whether the subprocessor list is binding or merely “informational.” That matters because GDPR expects real contractual control, not vague promises.

What a BAA Covers

A Business Associate Agreement, or BAA, comes from HIPAA. It is required when a business associate creates, receives, maintains, or transmits protected health information, known as PHI, for a covered entity or another business associate.

A BAA controls how PHI may be used and disclosed. It requires safeguards, breach reporting, subcontractor controls, access to records, and return or destruction of PHI when the work ends. It also limits the vendor’s freedom to reuse data for its own purposes.

A key difference is scope. GDPR applies to personal data across many sectors. HIPAA applies to health plans, healthcare clearinghouses, many healthcare providers, and their business associates. A fitness app may process sensitive wellness data, but that alone does not always make it subject to HIPAA.

GDPR DPA vs BAA: Core Differences

Topic GDPR DPA HIPAA BAA
Main law GDPR, mainly Article 28 HIPAA Privacy, Security, and Breach Notification Rules
Main roles Controller and processor Covered entity and business associate
Data type Personal data Protected health information
Breach timing Processor tells controller without undue delay; controller may have a 72 hour regulator deadline Business associate reports to covered entity; HIPAA outer deadline is often 60 days
Individual rights Access, deletion, correction, objection, portability, and more Access, amendment, accounting of disclosures, and related HIPAA rights

Where the Two Agreements Overlap

Both agreements aim to prevent careless vendor data use. Both require security controls. Both restrict subcontractors. Both deal with breach reporting. Both should say what happens when the contract ends.

Still, similar wording can hide very different legal duties. A GDPR DPA may allow processing only on documented instructions. A BAA may permit certain HIPAA functions, such as management, administration, or services for a covered entity. These are not the same thing.

  • Both need clear data descriptions. Vague terms create risk during audits.
  • Both need subcontractor rules. Downstream vendors can create the biggest blind spots.
  • Both need breach procedures. Timing, notice content, and contact channels should be precise.
  • Both need end of service terms. Data should be returned, deleted, or securely retained if law requires it.

When a Company May Need Both

A company may need both a GDPR DPA and a BAA when it handles EU personal data and U.S. PHI. This often happens with telehealth platforms, medical research tools, appointment systems, and health analytics providers.

Consider a clinic using a software vendor for patient messaging. If the clinic treats U.S. patients and sends PHI through the tool, a BAA may be required. If the same tool stores EU patient names, email addresses, appointment notes, or IP addresses, a GDPR DPA may also be required.

The vendor should not simply rename one agreement as the other. That shortcut causes trouble. A BAA will not usually contain all GDPR Article 28 clauses. A GDPR DPA will not always include HIPAA terms on PHI disclosures, HIPAA subcontractors, or availability of books and records to the U.S. Department of Health and Human Services.

Key Clauses to Compare Before Signing

Legal, privacy, and procurement teams should compare the agreements clause by clause. Speed helps, but skipping details can create expensive cleanup later.

  1. Purpose and instructions: The GDPR DPA should limit processing to documented instructions. The BAA should define permitted and required uses of PHI.
  2. Security controls: Both should mention administrative, physical, and technical safeguards. For GDPR, controls should match risk. For HIPAA, they should align with the Security Rule.
  3. Subprocessors and subcontractors: GDPR often needs prior authorization and notice of changes. HIPAA requires subcontractors handling PHI to accept similar restrictions.
  4. Breach notice: The contract should require fast notice. Waiting several weeks can make legal reporting almost impossible.
  5. Audit rights: GDPR DPAs often include audit support. BAAs may include access rights tied to HIPAA compliance.
  6. Data deletion: GDPR may favor deletion or return at the controller’s choice. HIPAA may allow continued protection if return or destruction is infeasible.
  7. International transfers: GDPR needs special care for cross border transfers, such as standard contractual clauses. HIPAA does not use the same transfer system.

Common Mistakes in Vendor Reviews

One common mistake is assuming that any health related data triggers HIPAA. Another is assuming that HIPAA compliance satisfies GDPR. It does not. The laws have different tests, rights, and contract terms.

Another mistake is accepting a vendor’s public privacy page as a contract. A privacy notice may describe general practices, but it rarely binds the vendor in the same way as a signed DPA or BAA. Honestly, it feels like some portals make this harder than it needs to be. A buyer clicks “settings,” then “trust center,” then “legal,” only to find a PDF dated three years ago.

Companies should also avoid signing conflicting documents. If a master services agreement says the vendor can use data for product improvement, but the DPA says processing is limited to instructions, the conflict clause becomes critical.

Practical Review Checklist

  • Identify whether the data is personal data, PHI, or both.
  • Confirm the legal roles of each party before choosing the document.
  • Check breach notice deadlines and contact methods.
  • Review subprocessor or subcontractor approval rights.
  • Confirm deletion, return, and retention duties.
  • Check whether international transfers are covered.
  • Make sure security exhibits are attached or clearly incorporated.

FAQ

Is a GDPR DPA the same as a BAA?

No. A GDPR DPA is used for controller processor relationships involving personal data. A BAA is used under HIPAA for PHI handled by business associates.

Can one contract include both GDPR DPA and BAA terms?

Yes. A combined data protection addendum can include both sets of terms. The clauses should be clearly separated so each law’s requirements are met.

Does HIPAA apply to all health data?

No. HIPAA usually applies when the data is held by a covered entity or business associate. Health data in a general wellness app may fall outside HIPAA, though other privacy laws may still apply.

Does GDPR apply to U.S. healthcare companies?

It can. GDPR may apply if the company offers goods or services to people in the EU or monitors their behavior, even if the company is based in the United States.

Which agreement should be signed first?

The correct agreement depends on the data and legal roles. If both GDPR personal data and HIPAA PHI are involved, both sets of terms should be in place before processing starts.

Scroll to Top
Scroll to Top