{"id":3133,"date":"2025-09-15T09:49:00","date_gmt":"2025-09-15T07:49:00","guid":{"rendered":"https:\/\/consalta.ba\/?p=3133"},"modified":"2026-03-17T14:49:20","modified_gmt":"2026-03-17T13:49:20","slug":"dpa-do-you-have-one-yet-and-why-not","status":"publish","type":"post","link":"https:\/\/consalta.ba\/en\/dpa-do-you-have-one-yet-and-why-not\/","title":{"rendered":"DPA \u2014 Do You Have One Yet, and Why Not?"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"3133\" class=\"elementor elementor-3133\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9eb3c04 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9eb3c04\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-91cc279\" data-id=\"91cc279\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-0271bbb elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"0271bbb\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-9d82f5e\" data-id=\"9d82f5e\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4815ce6 elementor-widget elementor-widget-image\" data-id=\"4815ce6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"768\" height=\"487\" src=\"https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303-768x487.jpg\" class=\"attachment-medium_large size-medium_large wp-image-3141\" alt=\"data processing agreement\" srcset=\"https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303-768x487.jpg 768w, https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303-300x190.jpg 300w, https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303-1024x649.jpg 1024w, https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303-18x12.jpg 18w, https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg 1210w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-5e3c413\" data-id=\"5e3c413\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d98ba7e elementor-widget elementor-widget-text-editor\" data-id=\"d98ba7e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>You use cloud hosting? You outsource payroll? Your marketing agency sends emails on your behalf? Your IT support provider has remote access to company systems? Quick question &#8211; <strong>do you have a Data Processing Agreement with any of them?<\/strong><\/p>\n<p>If you hesitated, you&#8217;re not alone. Most companies in Bosnia and Herzegovina haven&#8217;t even heard of a Data Processing Agreement (DPA), let alone signed one. But with the new &#8220;<strong><a href=\"https:\/\/consalta.ba\/new-personal-data-protection-law-in-bh-and-iso-27701\/\">Zakon o za\u0161titi li\u010dnih podataka<\/a>&#8220;<\/strong> (Law on Personal Data Protection) coming into force in October 2025, that needs to change &#8211; fast.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-890593a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"890593a\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5707019\" data-id=\"5707019\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a23ba4c elementor-widget elementor-widget-text-editor\" data-id=\"a23ba4c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2>What Is a Data Processing Agreement?<\/h2>\n<p>A Data Processing Agreement is a contract between a\u00a0<strong>controller<\/strong> (your company &#8211; the one that decides why and how personal data is used) and a <strong>processor<\/strong>\u00a0(any external party that handles that data on your behalf). It spells out the ground rules: what data is being processed, for what purpose, how long, what security measures must be in place, and what happens to the data when the relationship ends.<\/p>\n<p>Think of it this way: if you hand someone the keys to your customer database, a DPA is the written agreement that says exactly what they can and can&#8217;t do with those keys.<\/p>\n<p>The legal basis for this requirement is &#8220;<strong>\u010clan 30&#8243;<\/strong>\u00a0(Article 30) of the new law, which lays out in detail what such an agreement must contain and what obligations the processor takes on.<\/p>\n<h2>Why the New Law Changes Everything<\/h2>\n<p>Bosnia and Herzegovina&#8217;s previous data protection framework \u2014 dating back to 2006 &#8211; didn&#8217;t require this kind of formal agreement between controllers and processors. Companies could (and did) share personal data with external providers based on little more than a general service contract and a handshake.<\/p>\n<p>The new law changes that completely. Modelled closely on the EU&#8217;s\u00a0<a href=\"https:\/\/gdpr-info.eu\/art-28-gdpr\/\" target=\"_blank\" rel=\"noopener\">GDPR Article 28<\/a>, it requires that every controller-processor relationship is governed by a written agreement &#8211; and &#8220;written&#8221; includes electronic form, so a signed PDF or digital contract counts.<\/p>\n<p>Here&#8217;s the silver lining: if your company already works with EU partners, there&#8217;s a good chance you have GDPR-compliant DPAs in place for those relationships. Since the new B&amp;H law mirrors the GDPR requirements closely,\u00a0<strong>those existing agreements likely cover most of what you need<\/strong>. The gap is usually with your domestic processor relationships &#8211; the local IT company, the accounting firm, the HR software provider.<\/p>\n<h2>Do You Actually Need One? (Spoiler: Probably Yes)<\/h2>\n<p>This is where most companies get surprised. When you hear &#8220;data processor,&#8221; you might picture a large outsourcing firm handling millions of records. In reality, the definition is much broader. Here are everyday relationships that almost certainly require a DPA:<\/p>\n<ul>\n<li><strong>Cloud and SaaS providers:<\/strong>\u00a0Microsoft 365, Google Workspace, AWS, or any cloud hosting where personal data is stored<\/li>\n<li><strong>External bookkeeping and payroll:<\/strong>\u00a0your accountant handles employee salary data, tax IDs, bank details<\/li>\n<li><strong>IT support and managed services:<\/strong>\u00a0if they can access your systems remotely, they can access personal data<\/li>\n<li><strong>Marketing tools and CRM platforms:<\/strong>\u00a0Mailchimp, HubSpot, or any tool managing customer contact information<\/li>\n<li><strong>HR software: <\/strong>platforms handling employee records, leave management, recruitment data<\/li>\n<li><strong>Physical security providers:<\/strong>\u00a0if a third party manages your CCTV system, they&#8217;re processing personal data<\/li>\n<\/ul>\n<p><strong>The rule of thumb is simple: if someone outside your organization touches personal data on your behalf, you need a DPA.<\/strong><\/p>\n<p>And it doesn&#8217;t stop there. The law also addresses\u00a0<strong>sub-processors<\/strong> &#8211; if your processor hires another processor (say, your IT provider uses a sub-contracted cloud service), that relationship needs to be covered too. Your processor can&#8217;t engage a sub-processor without your prior written approval, and the same data protection obligations must flow down the chain.<\/p>\n<h2>What Must Be in the Agreement<\/h2>\n<p>Article 30 is quite specific about what the DPA must include. In plain terms, the processor commits to:<\/p>\n<ul>\n<li><strong>Follow your instructions only: <\/strong>process data solely based on your documented instructions, nothing more<\/li>\n<li><strong>Ensure confidentiality:<\/strong>\u00a0all people with access to the data must be bound by confidentiality obligations<\/li>\n<li><strong>Implement proper security:<\/strong>\u00a0 apply appropriate technical and organizational measures to protect the data (the law details these in \u010dlan 34)<\/li>\n<li><strong>Respect sub-processor rules:<\/strong>\u00a0no hiring additional processors without your written consent<\/li>\n<li><strong>Help you respond to data subject requests:<\/strong>\u00a0if a customer asks to see or delete their data, the processor must assist<\/li>\n<li><strong>Delete or return data when done:<\/strong>\u00a0once the service ends, the processor must either delete all personal data or hand it back to you<\/li>\n<li><strong>Allow audits:<\/strong>\u00a0you (or an auditor you appoint) must be able to inspect and verify compliance<\/li>\n<\/ul>\n<p>If this list looks familiar to anyone who&#8217;s dealt with GDPR, that&#8217;s because it&#8217;s essentially the same. The Croatian Data Protection Authority (<a href=\"https:\/\/azop.hr\/\" target=\"_blank\" rel=\"noopener\">AZOP<\/a>) has even published a DPA template \u2014 and since both laws share the same GDPR DNA, it&#8217;s a useful reference point. Bosnia&#8217;s\u00a0<strong>Agencija za za\u0161titu li\u010dnih podataka<\/strong>\u00a0may issue its own standard contractual clauses in the future (the law explicitly allows for this), but for now, you&#8217;ll need to draft your own or adapt an existing template.<\/p>\n<h2>What Happens If You Don&#8217;t Have One?<\/h2>\n<p>Beyond the obvious legal risk under the new law, the practical consequences are worth thinking about. If a processor mishandles personal data and there&#8217;s no DPA in place, you as the controller have\u00a0<strong>no contractual basis to hold them accountable<\/strong>. You&#8217;re exposed, and so are the people whose data was compromised.<\/p>\n<p>There&#8217;s also a growing commercial reality. EU companies (especially those subject to <a href=\"https:\/\/consalta.ba\/en\/how-nis2-affects-bosnian-companies-even-though-were-not-in-the-eu\/\">NIS2<\/a> or GDPR supply chain requirements) increasingly ask partners and vendors to demonstrate that proper DPAs are in place. If you work with clients in Croatia, Slovenia, Germany (or anywhere in the EU), <strong>not having DPAs can cost you business<\/strong>, not just fines.<\/p>\n<h2>It&#8217;s Simpler Than It Sounds<\/h2>\n<p>If this all feels overwhelming, take a breath. A well-drafted DPA is largely a one-time effort per processor relationship. Once you&#8217;ve mapped out who processes personal data on your behalf and put agreements in place, you&#8217;re covered &#8211; with periodic reviews when relationships or services change.<\/p>\n<p>The first step is straightforward:\u00a0<strong>make a list of every external party that has access to personal data in your organization<\/strong>. You&#8217;ll likely be surprised how long that list is. From there, it&#8217;s a matter of drafting agreements that meet the law&#8217;s requirements and getting them signed before October 2025.<\/p>\n<p>If you&#8217;d like help mapping your processor relationships or drafting DPAs that actually meet the new law&#8217;s requirements,\u00a0<a href=\"https:\/\/consalta.ba\/contact\/\">book a free 30-minute consultation<\/a> &#8211; we&#8217;ll help you figure out where you stand and what needs to happen next.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-3e1464db elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"3e1464db\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-72b0dc2c\" data-id=\"72b0dc2c\" data-element_type=\"column\" data-e-type=\"column\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-4d830200 elementor-section-content-middle elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4d830200\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-b8ad1e6\" data-id=\"b8ad1e6\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-28e422b8 elementor-widget elementor-widget-heading\" data-id=\"28e422b8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Would you like to start a project with us?<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2893f4df elementor-widget elementor-widget-text-editor\" data-id=\"2893f4df\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The initial consultation is free! We believe in truly helping our clients. You\u2019ll talk with one of our consultants directly. No pushy sales \u2013 no strings attached.<br \/><span style=\"font-weight: bold;\">Go ahead \u2013 check for yourself, now!<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-61725805\" data-id=\"61725805\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6b7389df elementor-align-right elementor-tablet-align-center elementor-widget elementor-widget-button\" data-id=\"6b7389df\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/consalta.ba\/contact\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Free consultation<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Most companies in Bosnia and Herzegovina don&#8217;t have Data Processing Agreements with their external service providers. With the new &#8220;Zakon o za\u0161titi li\u010dnih podataka coming into force in October 2025&#8221;, that needs to change \u2014 fast.<\/p>\n","protected":false},"author":1,"featured_media":3141,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"disabled","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[81,36,66],"tags":[82,85,83,84],"class_list":["post-3133","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection","category-privacy","category-regulation","tag-data-protection","tag-dpa","tag-privatnost","tag-ugovor-o-procesiranju"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DPA \u2014 Do You Have One Yet, and Why Not? - Consalta % %<\/title>\n<meta name=\"description\" content=\"Bosnia&#039;s new data protection law requires a Data Processing Agreement for every controller-processor relationship. Here&#039;s what you need \u2014 and why.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/consalta.ba\/en\/dpa-do-you-have-one-yet-and-why-not\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DPA \u2014 Do You Have One Yet, and Why Not? - Consalta % %\" \/>\n<meta property=\"og:description\" content=\"Bosnia&#039;s new data protection law requires a Data Processing Agreement for every controller-processor relationship. Here&#039;s what you need \u2014 and why.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/consalta.ba\/en\/dpa-do-you-have-one-yet-and-why-not\/\" \/>\n<meta property=\"og:site_name\" content=\"Consalta\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-15T07:49:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-17T13:49:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1210\" \/>\n\t<meta property=\"og:image:height\" content=\"767\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"OJB\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"OJB\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/\"},\"author\":{\"name\":\"OJB\",\"@id\":\"https:\\\/\\\/consalta.ba\\\/en\\\/#\\\/schema\\\/person\\\/b8449ee47559258a18597f3b91629afc\"},\"headline\":\"DPA \u2014 Do You Have One Yet, and Why Not?\",\"datePublished\":\"2025-09-15T07:49:00+00:00\",\"dateModified\":\"2026-03-17T13:49:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/\"},\"wordCount\":1157,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/consalta.ba\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/consalta.ba\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/dpa-e1772830346303.jpg\",\"keywords\":[\"data protection\",\"dpa\",\"privatnost\",\"ugovor o procesiranju\"],\"articleSection\":[\"data protection\",\"Privacy\",\"Regulation\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/\",\"url\":\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/\",\"name\":\"DPA \u2014 Do You Have One Yet, and Why Not? - Consalta % %\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/consalta.ba\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/consalta.ba\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/dpa-e1772830346303.jpg\",\"datePublished\":\"2025-09-15T07:49:00+00:00\",\"dateModified\":\"2026-03-17T13:49:20+00:00\",\"description\":\"Bosnia's new data protection law requires a Data Processing Agreement for every controller-processor relationship. Here's what you need \u2014 and why.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/#primaryimage\",\"url\":\"https:\\\/\\\/consalta.ba\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/dpa-e1772830346303.jpg\",\"contentUrl\":\"https:\\\/\\\/consalta.ba\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/dpa-e1772830346303.jpg\",\"width\":1210,\"height\":767,\"caption\":\"data processing agreement\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/consalta.ba\\\/dpa-do-you-have-one-yet-and-why-not\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/consalta.ba\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"data protection\",\"item\":\"https:\\\/\\\/consalta.ba\\\/category\\\/data-protection\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"DPA \u2014 Do You Have One Yet, and Why Not?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/consalta.ba\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/consalta.ba\\\/en\\\/\",\"name\":\"Consalta\",\"description\":\"Get Certified!\",\"publisher\":{\"@id\":\"https:\\\/\\\/consalta.ba\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/consalta.ba\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/consalta.ba\\\/en\\\/#organization\",\"name\":\"Consalta\",\"url\":\"https:\\\/\\\/consalta.ba\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/consalta.ba\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/consalta.ba\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/Logo-getcert-2024_transpback_blue-black.png\",\"contentUrl\":\"https:\\\/\\\/consalta.ba\\\/wp-content\\\/uploads\\\/2024\\\/11\\\/Logo-getcert-2024_transpback_blue-black.png\",\"width\":\"617\",\"height\":\"90\",\"caption\":\"Consalta\"},\"image\":{\"@id\":\"https:\\\/\\\/consalta.ba\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/ba.linkedin.com\\\/company\\\/consalta-d.o.o.\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/consalta.ba\\\/en\\\/#\\\/schema\\\/person\\\/b8449ee47559258a18597f3b91629afc\",\"name\":\"OJB\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/69c0cb70266add0c68274346f544f85223697fb0959d7a797c6a99b8e6babcba?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/69c0cb70266add0c68274346f544f85223697fb0959d7a797c6a99b8e6babcba?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/69c0cb70266add0c68274346f544f85223697fb0959d7a797c6a99b8e6babcba?s=96&d=mm&r=g\",\"caption\":\"OJB\"},\"sameAs\":[\"https:\\\/\\\/consalta.ba\"],\"url\":\"https:\\\/\\\/consalta.ba\\\/en\\\/author\\\/admin_8k999oh2\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DPA \u2014 Do You Have One Yet, and Why Not? - Consalta % %","description":"Bosnia's new data protection law requires a Data Processing Agreement for every controller-processor relationship. Here's what you need \u2014 and why.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/consalta.ba\/en\/dpa-do-you-have-one-yet-and-why-not\/","og_locale":"en_US","og_type":"article","og_title":"DPA \u2014 Do You Have One Yet, and Why Not? - Consalta % %","og_description":"Bosnia's new data protection law requires a Data Processing Agreement for every controller-processor relationship. Here's what you need \u2014 and why.","og_url":"https:\/\/consalta.ba\/en\/dpa-do-you-have-one-yet-and-why-not\/","og_site_name":"Consalta","article_published_time":"2025-09-15T07:49:00+00:00","article_modified_time":"2026-03-17T13:49:20+00:00","og_image":[{"width":1210,"height":767,"url":"https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg","type":"image\/jpeg"}],"author":"OJB","twitter_card":"summary_large_image","twitter_misc":{"Written by":"OJB","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/#article","isPartOf":{"@id":"https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/"},"author":{"name":"OJB","@id":"https:\/\/consalta.ba\/en\/#\/schema\/person\/b8449ee47559258a18597f3b91629afc"},"headline":"DPA \u2014 Do You Have One Yet, and Why Not?","datePublished":"2025-09-15T07:49:00+00:00","dateModified":"2026-03-17T13:49:20+00:00","mainEntityOfPage":{"@id":"https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/"},"wordCount":1157,"commentCount":0,"publisher":{"@id":"https:\/\/consalta.ba\/en\/#organization"},"image":{"@id":"https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/#primaryimage"},"thumbnailUrl":"https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg","keywords":["data protection","dpa","privatnost","ugovor o procesiranju"],"articleSection":["data protection","Privacy","Regulation"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/","url":"https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/","name":"DPA \u2014 Do You Have One Yet, and Why Not? - Consalta % %","isPartOf":{"@id":"https:\/\/consalta.ba\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/#primaryimage"},"image":{"@id":"https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/#primaryimage"},"thumbnailUrl":"https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg","datePublished":"2025-09-15T07:49:00+00:00","dateModified":"2026-03-17T13:49:20+00:00","description":"Bosnia's new data protection law requires a Data Processing Agreement for every controller-processor relationship. Here's what you need \u2014 and why.","breadcrumb":{"@id":"https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/#primaryimage","url":"https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg","contentUrl":"https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg","width":1210,"height":767,"caption":"data processing agreement"},{"@type":"BreadcrumbList","@id":"https:\/\/consalta.ba\/dpa-do-you-have-one-yet-and-why-not\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/consalta.ba\/en\/"},{"@type":"ListItem","position":2,"name":"data protection","item":"https:\/\/consalta.ba\/category\/data-protection\/"},{"@type":"ListItem","position":3,"name":"DPA \u2014 Do You Have One Yet, and Why Not?"}]},{"@type":"WebSite","@id":"https:\/\/consalta.ba\/en\/#website","url":"https:\/\/consalta.ba\/en\/","name":"Consalta","description":"Get Certified!","publisher":{"@id":"https:\/\/consalta.ba\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/consalta.ba\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/consalta.ba\/en\/#organization","name":"Consalta","url":"https:\/\/consalta.ba\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/consalta.ba\/en\/#\/schema\/logo\/image\/","url":"https:\/\/consalta.ba\/wp-content\/uploads\/2024\/11\/Logo-getcert-2024_transpback_blue-black.png","contentUrl":"https:\/\/consalta.ba\/wp-content\/uploads\/2024\/11\/Logo-getcert-2024_transpback_blue-black.png","width":"617","height":"90","caption":"Consalta"},"image":{"@id":"https:\/\/consalta.ba\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/ba.linkedin.com\/company\/consalta-d.o.o."]},{"@type":"Person","@id":"https:\/\/consalta.ba\/en\/#\/schema\/person\/b8449ee47559258a18597f3b91629afc","name":"OJB","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/69c0cb70266add0c68274346f544f85223697fb0959d7a797c6a99b8e6babcba?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/69c0cb70266add0c68274346f544f85223697fb0959d7a797c6a99b8e6babcba?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/69c0cb70266add0c68274346f544f85223697fb0959d7a797c6a99b8e6babcba?s=96&d=mm&r=g","caption":"OJB"},"sameAs":["https:\/\/consalta.ba"],"url":"https:\/\/consalta.ba\/en\/author\/admin_8k999oh2\/"}]}},"rttpg_featured_image_url":{"full":["https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg",1210,767,false],"landscape":["https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg",1210,767,false],"portraits":["https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg",1210,767,false],"thumbnail":["https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303-150x150.jpg",150,150,true],"medium":["https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303-300x190.jpg",300,190,true],"large":["https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303-1024x649.jpg",1024,649,true],"1536x1536":["https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg",1210,767,false],"2048x2048":["https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303.jpg",1210,767,false],"trp-custom-language-flag":["https:\/\/consalta.ba\/wp-content\/uploads\/2026\/03\/dpa-e1772830346303-18x12.jpg",18,12,true]},"rttpg_author":{"display_name":"OJB","author_link":"https:\/\/consalta.ba\/en\/author\/admin_8k999oh2\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/consalta.ba\/en\/category\/data-protection\/\" rel=\"category tag\">data protection<\/a> <a href=\"https:\/\/consalta.ba\/en\/category\/privacy\/\" rel=\"category tag\">Privacy<\/a> <a href=\"https:\/\/consalta.ba\/en\/category\/regulation\/\" rel=\"category tag\">Regulation<\/a>","rttpg_excerpt":"Most companies in Bosnia and Herzegovina don't have Data Processing Agreements with their external service providers. With the new \"Zakon o za\u0161titi li\u010dnih podataka coming into force in October 2025\", that needs to change \u2014 fast.","_links":{"self":[{"href":"https:\/\/consalta.ba\/en\/wp-json\/wp\/v2\/posts\/3133","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/consalta.ba\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/consalta.ba\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/consalta.ba\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/consalta.ba\/en\/wp-json\/wp\/v2\/comments?post=3133"}],"version-history":[{"count":18,"href":"https:\/\/consalta.ba\/en\/wp-json\/wp\/v2\/posts\/3133\/revisions"}],"predecessor-version":[{"id":3168,"href":"https:\/\/consalta.ba\/en\/wp-json\/wp\/v2\/posts\/3133\/revisions\/3168"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/consalta.ba\/en\/wp-json\/wp\/v2\/media\/3141"}],"wp:attachment":[{"href":"https:\/\/consalta.ba\/en\/wp-json\/wp\/v2\/media?parent=3133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/consalta.ba\/en\/wp-json\/wp\/v2\/categories?post=3133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/consalta.ba\/en\/wp-json\/wp\/v2\/tags?post=3133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}