DField SolutionsMérnöki stúdió · Budapest
Loading · Töltődik
Skip to content

DPA and TIA (data processing and transfer impact assessment)

Related service Cybersecurity

DEFINITION

Two mandatory GDPR documents for any business handling personal data. DPA (Data Processing Agreement): signed with every third-party vendor receiving your customers' data (Mailchimp, Stripe, SimplePay, Mailgun, GLS). TIA (Transfer Impact Assessment): mandatory if you use a non-EU (US) provider — Google Analytics, Mailchimp, many US SaaS tools. NAIH audits ask for both. Missing them = data transfer without legal basis, can trigger an immediate stop order.

RELATED TERMS06
  • Threat model

    A structured exercise that walks the system's actors, attack surface, risks, and controls. Day one of every DField project · before any code.

  • Penetration test (pentest)

    Manual + tooled attack simulation that reveals what an attacker could achieve. We deliver findings as PRs in your repo, not an 80-page PDF.

  • DevSecOps

    Security as a continuously-running CI step (SAST, DAST, SCA, IaC scan), not an annual project. Runs against every push; every sprint closes at least one security bug.

  • MFA (Multi-factor auth)

    Two or more factors (TOTP, WebAuthn, biometric) beyond a password. Table-stakes in SaaS today · enterprise procurement disqualifies you without it.

  • SOC 2

    A US audit framework for confidentiality, integrity, availability, and privacy controls. For SaaS, the Type II audit (6–12 months of observation) is the standard enterprise baseline.

  • ISO 27001

    International standard for Information Security Management Systems (ISMS). Often preferred in Europe instead of or alongside SOC 2. 3-year certification cycle.

MENTIONED IN THE BLOG08