The Zendesk DPA
The Zendesk DPA is the contract that says what a vendor may and may not do with data you're responsible for. Most teams sign it and never read it.
What the Zendesk DPA is for
Under GDPR, a controller has to have a written agreement with any processor handling personal data on its behalf. The DPA is that agreement. It is an addendum because it bolts onto your subscription contract instead of replacing it.
The point of it is enforceability. A security page is a promise. A DPA is a promise with a remedy attached, which is why procurement asks for it and why your own customers ask you for one in turn.
Equivalent addenda exist for other regimes: UK, Swiss, and a growing pile of US state privacy laws. Vendors usually fold them into one document with jurisdiction-specific schedules. Read which regimes yours actually names, because assuming coverage is how gaps happen.
What it typically covers
Sub-processors, and why the list matters
A sub-processor is a company your processor uses to help deliver the service: hosting, mail delivery, analytics, their own support tooling. They touch some of your data and you never chose them. That's normal, and it's also the part of the chain most organisations have the least visibility into.
The DPA should tell you how new sub-processors are notified and what you can do about one you object to. Read that clause properly. The remedy is often narrower than people assume, and it frequently amounts to a right to leave rather than a right to have that vendor excluded.
Practical advice: subscribe to the vendor's sub-processor change notifications if they offer them, and send them somewhere that isn't one person's inbox. Then pull the current list from Zendesk's own legal pages on the day you need it. Never copy a sub-processor list out of an article, including this one. It changes.
Where to find it and how to sign it
Vendors at this scale generally publish a standard DPA on their legal pages, and it's often either incorporated into the main agreement by reference or available to accept electronically. Sometimes there is nothing to sign and you simply need a copy for the file.
Ask your account team or check Zendesk's legal and trust pages for the current route, rather than assuming you're covered because somebody said so in 2021.
Then store the executed copy with its version and date somewhere your auditor can find it in under a minute. Half the pain of a security review is document archaeology, and it is entirely avoidable.
One more habit worth building: put a recurring reminder against renewal to check whether the published version has moved on from the one in your file. Vendors revise these documents, sometimes for good reasons like a new transfer framework, and the copy you signed three years ago doesn't update itself. Ten minutes a year, and it's the difference between a clean answer and a fortnight of email.
What the DPA doesn't cover
Frequently asked questions
Where do you find and sign the DPA?
In the Zendesk legal centre. The Zendesk data processing agreement, formally the Zendesk data processing addendum, is signed there and includes the Zendesk standard contractual clauses for transfers. The Zendesk sub-processors list is published alongside it and worth subscribing to.
Do we need a DPA with Zendesk?
If personal data subject to GDPR or a similar law is processed on your behalf, a written processing agreement is required. Most teams using a helpdesk are in that position.
Is the DPA the same as the terms of service?
No. The main agreement is commercial. The DPA is the data protection layer on top of it, and it usually incorporates transfer clauses as annexes.
Where do I get a copy of the Zendesk DPA?
Zendesk's legal and trust pages, or your account team. Get the current version rather than reusing whatever was filed at signup, because these documents get revised.
What happens if we object to a new sub-processor?
Read the objection clause. There is normally a defined notification window and a defined remedy, and the remedy is often termination rather than exclusion of that sub-processor from the service.
Does the DPA cover apps we install from the marketplace?
Usually not. Those vendors have their own terms and their own processing. If an app reads ticket data, it belongs in your own record of processing activities.
One fewer processor to paper
Every tool touching your queue is another agreement to keep current. Ticket Merger reads tickets to compare them and keeps no conversation content beyond that comparison.
Start free trial14-day free trial. No credit card required.