NDA vs DPA: What SaaS Vendors and Customers Get Wrong
Confidentiality agreements and Data Processing Agreements serve different purposes. When you need each, and common SaaS contract mistakes.
NDA purpose
Protect confidential business information — product plans, pricing, technical architecture not yet public.
DPA purpose
Govern processing of personal data under GDPR Article 28 — subprocessors, security measures, breach notification, deletion.
Common mistake: NDA only
Customer shares user emails, logs, or support tickets. An NDA does not create lawful processor obligations.
Common mistake: DPA only
Trade secrets and roadmap items are not "personal data." You still need confidentiality terms.
SaaS bundle
| Document | Covers |
|---|---|
| MSA | Commercial terms |
| NDA | Pre-sales / evaluation secrets |
| DPA | Customer personal data in the service |
| Security exhibit | Technical controls |
Negotiation tips
- Keep DPA as a schedule to MSA, not inside the NDA
- Align NDA survival with DPA deletion timelines
- EU customers: verify GDPR NDA review checklist
Use NDAShield for inbound NDA templates; use counsel for DPA regulatory fit.