{"id":15058,"date":"2024-09-18T13:26:56","date_gmt":"2024-09-18T11:26:56","guid":{"rendered":"https:\/\/www.cookiebot.com\/en\/?p=15058"},"modified":"2026-03-12T09:16:05","modified_gmt":"2026-03-12T08:16:05","slug":"what-is-a-data-processing-agreement-dpa","status":"publish","type":"post","link":"https:\/\/www.cookiebot.com\/en\/what-is-a-data-processing-agreement-dpa\/","title":{"rendered":"What is a DPA? Understanding data processing agreements"},"content":{"rendered":"\n<p>Organizations often rely on third-party service providers to process data on their behalf for a variety of purposes, such for managing customer relationships, handling payroll, conducting marketing campaigns, or analyzing website performance, to name just a few. While outsourcing these functions can help organizations work more smoothly, it also introduces risks associated with data privacy and security, such as data breaches or unauthorized access.<\/p>\n\n\n\n<p>A data processing agreement (DPA) helps mitigate these risks by outlining clear responsibilities for both parties, the entity that collects data and the third-party service provider that processes it on their behalf. It enables personal data to be handled securely and helps organizations maintain compliance with global data privacy laws like the European Union\u2019s <a href=\"https:\/\/www.cookiebot.com\/en\/gdpr\/\">General Data Protection Regulation (GDPR)<\/a> and the <a href=\"https:\/\/www.cookiebot.com\/en\/what-is-ccpa\/\">California Consumer Privacy Act (CCPA)<\/a>\/<a href=\"https:\/\/www.cookiebot.com\/en\/cpra\/\">California Privacy Rights Act (CPRA)<\/a>.<\/p>\n\n\n\n<p>We look at what a data processing agreement is, when it\u2019s required, and what must be included to achieve regulatory compliance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-a-dpa\">What is a DPA?<\/h2>\n\n\n\n<p>A data processing agreement (DPA) is a legal contract between two key parties involved in the handling of personal data or personal information: the data controller and the data processor. It outlines the responsibilities of both parties and establishes clear guidelines for how data will be processed.<\/p>\n\n\n\n<p>The data controller (or controller) is the entity, such as a business or other organization, that determines the purpose and means of processing personal data. It is responsible for ensuring that data processing complies with applicable laws.<\/p>\n\n\n\n<p>The data processor (or processor) is a third-party entity that processes personal data on behalf of the controller and under the controller\u2019s instructions.<\/p>\n\n\n\n<p>A data processing agreement is also known as a data privacy agreement, data protection agreement, or data privacy addendum. Some laws simply refer to it as a contract between the controller and processor.<\/p>\n\n\n\n<p>The term \u201cprocessing\u201d refers to any operation or set of operations performed on personal data, whether manual or automated. The GDPR definition of the term includes <em>\u201ccollection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction\u201d <\/em>as operations that constitute processing.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-is-the-purpose-of-a-data-processing-agreement\">What is the purpose of a data processing agreement?<\/h2>\n\n\n\n<p>A data processing agreement (DPA) plays a central role in ensuring that personal data is handled properly when shared between a data controller and a data processor. Its purpose is to create a clear framework that protects personal data and aligns both parties with the requirements of data protection laws.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-assists-in-meeting-legal-requirements\">Assists in meeting legal requirements<\/h3>\n\n\n\n<p>A DPA serves as a legally binding document that sets out the obligations of both the controller and the processor under applicable data protection laws. Some of the regulations that mandate a DPA include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>European Union General Data Protection Regulation (GDPR)<\/li>\n\n\n\n<li>California Consumer Privacy Act (CCPA)\/California Privacy Rights Act (CPRA)<\/li>\n\n\n\n<li><a href=\"https:\/\/www.cookiebot.com\/en\/uk-gdpr\/\">United Kingdom General Data Protection Regulation (UK-GDPR)<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.cookiebot.com\/en\/popia\/\">South Africa Protection of Personal Information Act (POPIA)<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.cookiebot.com\/en\/thailand-pdpa\/\">Thailand Personal Data Protection Act<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/usercentrics.com\/knowledge-hub\/india-digital-personal-data-protection-act-dpdpa\/\">India Digital Personal Data Protection Act (DPDP Act)<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.cookiebot.com\/en\/personal-information-protection-law-pipl\/\">China Personal Information Protection Law<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.cookiebot.com\/en\/virginia-vcdpa\/\">Virginia Consumer Data Protection Act (VCDPA)<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.cookiebot.com\/en\/colorado-privacy-act-cpa\/\">Colorado Privacy Act (CPA)<\/a><\/li>\n<\/ul>\n\n\n\n<p>Since many of these laws have extraterritorial reach, even companies operating outside these regions may need to comply when handling personal data of people from within those jurisdictions. By having a DPA in place, businesses reduce the risk of legal penalties associated with noncompliance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-clarifies-responsibilities-of-the-parties\">Clarifies responsibilities of the parties<\/h3>\n\n\n\n<p>The DPA clearly defines the roles and responsibilities of the data controller and processor. It specifies how personal data will be processed, stored, and protected, helping to ensure the processor acts solely on the controller\u2019s instructions. This clarity helps prevent misunderstandings and helps ensure that both parties adhere to their obligations regarding data handling.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-helps-protect-data-subjects\"><strong>Helps protect data subjects<\/strong><\/h3>\n\n\n\n<p>A DPA details the technical and organizational measures that both parties must follow, including specific security measures the data processor must implement. These can include encryption, access controls, and regular security audits, all designed to safeguard personal data from unauthorized access or breaches.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-establishes-protocols\"><strong>Establishes protocols<\/strong><\/h3>\n\n\n\n<p>A DPA establishes clear procedures for handling personal data, including the engagement and use of sub-processors. It outlines specific provisions for data security, breach notification procedures, and the responsibilities of each party in the event of a data incident. This structured approach helps both parties know exactly what steps to take if a security issue arises, reducing the risk of delays or confusion during critical moments.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-facilitates-international-data-transfers\"><strong>Facilitates international data transfers<\/strong><\/h3>\n\n\n\n<p>When personal data crosses borders, the agreement outlines the safeguards required to ensure that the data receives the same level of protection it would under domestic laws. This might include the use of standard contractual clauses (SCCs) when transferring data to countries that don\u2019t have robust privacy laws.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-when-is-a-data-processing-agreement-required\">When is a data processing agreement required?<\/h2>\n\n\n\n<p>A data processing agreement is required whenever an entity that is acting as a controller and needs a DPA shares personal data with a third-party service provider for data processing purposes. The DPA must be signed prior to any data processing taking place.<\/p>\n\n\n\n<p>Small businesses, sole proprietors, nonprofits, government organizations, and others must enter into DPAs if the following conditions apply:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>they are required to comply under a regulation that mandates a DPA, based on the location of the data subject and specific compliance thresholds related to the type of entity, annual revenue, or other relevant criteria<\/li>\n\n\n\n<li>they are considered a data controller, meaning they are responsible for determining the purpose and means of processing<\/li>\n\n\n\n<li>they share data with third-party processors for processing purposes<\/li>\n<\/ul>\n\n\n\n<p>If you collect or process data from an individual in the EU\/EEA, you must comply. For US states\u2019 privacy laws, check the compliance thresholds to determine if you must comply.<\/p>\n\n\n\n<p>Entities that are considered data processors under the law and process personal data on behalf of and on the instructions of controllers must enter into a DPA with the controller.<\/p>\n\n\n\n<p>Here are some examples of situations when a data processing agreement would be required:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>if your organization hires an external IT support firm to manage your systems, and they have access to employee or customer personal data, you need a DPA to ensure they handle the data securely and comply with privacy laws<\/li>\n\n\n\n<li>when you use a payment gateway like Stripe or PayPal to handle online transactions, a DPA is required because the payment processor accesses personal data like names, addresses, and payment information<\/li>\n\n\n\n<li>if you use a platform like HubSpot or Mailchimp to manage your email campaigns, newsletters, or marketing communications, you need a DPA as these platforms process personal data such as email addresses and interaction history on your behalf<\/li>\n\n\n\n<li>if you host your website with a service provider like Amazon Web Services (AWS) or GoDaddy, and personal data from your website, for example through user accounts or contact forms, is stored on their servers, you must have a DPA to regulate the processing and protection of that data<\/li>\n\n\n\n<li>when you hire a recruitment agency to manage job applications and collect candidates' resumes or contact details on your behalf, a DPA is required to ensure the secure handling of the personal data involved in the recruitment process<\/li>\n\n\n\n<li>if you work with a logistics provider to handle your product deliveries, and they have access to customer data like addresses or order history, you need a DPA to protect that personal information<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-cookies-and-data-processing-agreements\"><strong>Cookies and data processing agreements<\/strong><\/h2>\n\n\n\n<p><a href=\"https:\/\/www.cookiebot.com\/en\/tracking-cookies\/\">Tracking cookies<\/a> often collect personal data like IP addresses and browsing behavior, which qualifies as personal data under many global data protection regulations. When businesses use cookies to gather this data, they often rely on third-party service providers, such as analytics or marketing platforms. This makes it necessary for businesses to enter into DPAs with these third parties to ensure that the processing of cookie data complies with applicable data privacy laws.<\/p>\n\n\n\n<p>Under the GDPR, cookies that collect personal data require explicit consent from users, with the exception of strictly necessary cookies. If a business uses a third-party data processor to process data from cookies, the DPA should outline how that processor will handle personal data collected through cookies, including security measures and compliance with users' right to revoke or withdraw consent. Websites that collect personal data in this manner should use a <a href=\"https:\/\/www.cookiebot.com\/\">consent management platform (CMP)<\/a> to obtain <a href=\"https:\/\/www.cookiebot.com\/en\/cookie-consent\/\">cookie consent<\/a>.<\/p>\n\n\n\n<p>The CCPA\/CPRA doesn\u2019t require explicit consumer consent to collect personal information through cookies in many cases, with some exceptions, such as sensitive information and minors\u2019 personal information. However, consumers have the right to opt out of the sale or sharing of their personal information, and to limit the use or disclosure of sensitive information. If a business uses cookies to collect data that could be sold or shared, the DPA should include clauses that ensure the third party complies with the opt-out rights of consumers and provides transparency about data usage.<\/p>\n\n\n<div class=\"cta-block cta-block--size-s cta-block--only-buttons cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                    <h2 class=\"cta-block__title no-default-margin like-h4\">\n                        Do you have DPAs with all your data processors?                    <\/h2>\n                                                    <div class=\"cta-block__description like-text-md\">\n                        <p>Scan your website to know which third-party cookies you use so you can check if you have DPAs in place with these entities.<\/p>\n                    <\/div>\n                                                                                                                                                        <\/div>\n                            <div class=\"cta-block__right-column\">\n                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"c09d6d34-bce5-476a-b325-9f91d6f5474e\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"https:\/\/www.cookiebot.com\/en\/cookie-checker\/\" target=\"\">\n<span>Run cookie checker<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                        <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-needs-to-be-included-in-a-data-protection-agreement\">What needs to be included in a data protection agreement?<\/h2>\n\n\n\n<p>The specific contractual obligations in a DPA can be different depending on the data privacy law in question.<a href=\"https:\/\/gdpr-info.eu\/art-28-gdpr\/\"> Art. 28 GDPR<\/a> and the CCPA\/CPRA specify particular requirements that must be included in a DPA. Some regulations simply state that a contract is necessary, without detailing the DPA requirements.<\/p>\n\n\n\n<p>Regardless of the specific law, a well structured DPA should generally include the following elements:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>purpose and scope of processing<\/li>\n\n\n\n<li>types and categories of personal data to be processed<\/li>\n\n\n\n<li>how long the data will be retained for<\/li>\n\n\n\n<li>obligations of the controller and processor<\/li>\n\n\n\n<li>technical and organizational measures to be implemented for data security<\/li>\n\n\n\n<li>provisions regarding engagement and use of sub-processors<\/li>\n\n\n\n<li>provisions regarding data return or deletion<\/li>\n\n\n\n<li>how the processor will assist the controller in fulfilling its obligations related to data subjects\u2019 rights<\/li>\n\n\n\n<li>procedures for data breach notifications, including timelines and responsibilities<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-what-are-the-gdpr-dpa-requirements\">What are the GDPR DPA requirements?<\/h3>\n\n\n\n<p>Art. 28 GDPR requires controllers to enter into agreements with processors to ensure that personal data is processed securely and in compliance with the law. These agreements must include the following key provisions:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>processors can only process personal data based on the documented instructions of the controller, including restrictions on transferring data outside the EU unless explicitly instructed<\/li>\n\n\n\n<li>processors must ensure that anyone authorized to process the personal data is bound by confidentiality obligations<\/li>\n\n\n\n<li>DPA must detail the technical and organizational measures that the processor will take to protect the personal data under<a href=\"https:\/\/gdpr-info.eu\/art-32-gdpr\/\"> Art. 32 GDPR<\/a>, including encryption and data access controls<\/li>\n\n\n\n<li>processors cannot engage another processor (sub-processor) without the controller\u2019s written authorization<\/li>\n\n\n\n<li>if appointed, a sub-processor must be bound by the same data protection obligations as the processor<\/li>\n\n\n\n<li>processors must assist the controller in fulfilling obligations related to data subject rights, such as access, rectification, and erasure requests<\/li>\n\n\n\n<li>at the end of the contract, processors must either delete or return all personal data to the controller, unless retention is required by law<\/li>\n\n\n\n<li>processors must permit the controller to audit and inspect the processing activities to ensure compliance with the GDPR<\/li>\n\n\n\n<li>processors must assist the controller in fulfilling its obligations under the GDPR, particularly Art. 32 to 36, which include data security, data breach and notifications of breach, data protection impact assessments, and prior consultation<\/li>\n<\/ul>\n\n\n\n<p>Some entities are required to appoint a Data Protection Officer (DPO) under the GDPR. One of the DPO's key tasks is to monitor compliance with the GDPR, which includes ensuring that controllers have the necessary DPAs in place when sharing personal data with processors.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-what-are-the-ccpa-cpra-dpa-requirements\">What are the CCPA\/CPRA DPA requirements?<\/h3>\n\n\n\n<p>Under<a href=\"https:\/\/casetext.com\/statute\/california-codes\/california-civil-code\/division-3-obligations\/part-4-obligations-arising-from-particular-transactions\/title-1815-california-consumer-privacy-act-of-2018\/section-1798100-general-duties-of-businesses-that-collect-personal-information\"> Section 1798.100(d)<\/a> of the CCPA, as amended by the CPRA, businesses (the regulation\u2019s term for controllers) must have contracts with third parties, service providers, and contractors when sharing consumers\u2019 personal information. These contracts are equivalent to DPAs and must include the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>that personal information shared between the business and the third party, service provider, or contractor can only be used for the purposes outlined in the agreement<\/li>\n\n\n\n<li>the third party, service provider, or contractor must be obligated to comply with applicable obligations under the regulation, including providing the same level of privacy protection as businesses are required to provide<\/li>\n\n\n\n<li>businesses have the right to ensure that the third party, service provider, or contractor handles the personal information in line with the business\u2019s obligations under the regulation<\/li>\n\n\n\n<li>if the third party, service provider, or contractor realizes they can't meet their data protection obligations anymore, they must inform the business<\/li>\n\n\n\n<li>businesses can take steps to stop and correct any unauthorized user of personal information if they are notified of a problem<\/li>\n<\/ul>\n\n\n<div class=\"cta-block cta-block--size-s cta-block--only-buttons cb-ctx--blue\">\n        <div class=\"cta-block__glass\">\n        <div class=\"cta-block__inner\">\n            <div class=\"cta-block__left-column\">\n                                                                    <div class=\"cta-block__description like-text-md\">\n                        <p>Does your website collect personal data from individuals in the EU\/EEA and California? Learn about all your compliance obligations under the GDPR and CCPA\/CPRA.<\/p>\n                    <\/div>\n                                                                                                                                                        <\/div>\n                            <div class=\"cta-block__right-column\">\n                                                                <div class=\"cta-block__buttons\">\n                                                    <div class=\"cta-block__buttons__button-wp\">\n                                <a id=\"df12ffdf-d1ed-45e1-bd88-b1525e9c562c\" class=\"cb-button cb-button-size-l cb-button-contained  no-default-link-decoration cb-button-icon-right cta-block__buttons__button\" href=\"https:\/\/www.cookiebot.com\/en\/ccpa-vs-gdpr\/\" target=\"\">\n<span>Read more<\/span><\/a>\n                                                            <\/div>\n                                                                        <\/div>\n                                                        <\/div>\n                    <\/div>\n    <\/div>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-the-fines-for-not-having-a-data-privacy-agreement\">What are the fines for not having a data privacy agreement?<\/h2>\n\n\n\n<p>Not entering into a DPA when legally required can lead to significant consequences, including violations of data protection laws that may trigger hefty fines and result in reputation damage.<\/p>\n\n\n\n<p>Under the GDPR, the penalties for noncompliance can be severe. The regulation establishes two tiers of fines based on the nature and severity of the infringement:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>for less severe infringements, organizations can face fines of up to EUR 10 million or 2 percent of the company\u2019s total global annual revenue from the preceding financial year, whichever is higher<\/li>\n\n\n\n<li>for more serious violations, fines can reach up to EUR 20 million or 4 percent of the company\u2019s total global annual revenue, whichever is higher<\/li>\n<\/ul>\n\n\n\n<p>The enforcement of these fines is carried out by data protection authorities in each EU member state, which assess the situation based on various factors, including the nature and gravity of the infringement.<\/p>\n\n\n\n<p>The CCPA\/CPRA also imposes penalties for noncompliance, including the failure to establish necessary contracts like DPAs. Businesses that violate the CCPA can be subject to civil penalties of up to USD 2,500 for each unintentional violation and up to USD 7,500 for each intentional violation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-signing-the-dpa-as-a-controller\">Signing the DPA as a controller<\/h2>\n\n\n\n<p>When signing a DPA as a controller, you\u2019re the entity that determines why and how personal data will be processed.<\/p>\n\n\n\n<p>You must ensure that the agreement clearly outlines how the processor can use personal data, and verify that the processor commits to complying with all relevant data privacy laws. The processor should agree to process data only based on your explicit instructions.<\/p>\n\n\n\n<p>You are ultimately responsible for the data processing activities, which means you must consider the implications of any international data transfers and ensure that the processor complies with all relevant regulations.<\/p>\n\n\n\n<p>By meticulously reviewing and signing the DPA, you ensure that the processor is legally bound to protect the personal data in line with your regulatory obligations, helping you achieve compliance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-signing-the-dpa-as-a-processor\">Signing the DPA as a processor<\/h2>\n\n\n\n<p>When signing a DPA as a processor, you\u2019re the entity processing personal data on the controller\u2019s behalf. You\u2019re also responsible for complying with the obligations specifically laid on you under the different data privacy laws.<\/p>\n\n\n\n<p>You must agree to process personal data only based on the controller\u2019s written instructions, and ensure that all personnel authorized to process the personal data are bound by confidentiality obligations, either through employment contracts or other legal agreements.<\/p>\n\n\n\n<p>You should also ensure that the DPA accounts for all applicable data privacy laws and be prepared to provide the controller with all information necessary to demonstrate compliance with data protection obligations.<\/p>\n\n\n\n<p>You\u2019re responsible for ensuring that any sub-processors you engage comply with the terms of the DPA, and you must obtain the controller's consent before engaging sub-processors.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-to-create-a-data-processing-agreement\">How to create a data processing agreement<\/h2>\n\n\n\n<p>There is no mandated process for drafting a DPA under any of the regulations that require it. Businesses are free to draft a DPA themselves, use a template or guide, or engage a qualified legal professional to draft the DPA for them.<\/p>\n\n\n\n<p>The United Kingdom\u2019s Data Protection Authority, the Information Commissioner\u2019s Office (ICO), has published a <a href=\"https:\/\/ico.org.uk\/for-organisations\/uk-gdpr-guidance-and-resources\/accountability-and-governance\/guide-to-accountability-and-governance\/accountability-and-governance\/contracts\/\">checklist<\/a> you can use as a starting point if you wish to draft a DPA yourself.<\/p>\n\n\n\n<p>It is advisable to consult a qualified legal professional or privacy expert, such as a Data Protection Officer (DPO), to draft or review your DPA. Since a DPA is a binding legal agreement, professional guidance helps to confirm that it complies with all the requirements of the relevant privacy laws, enhancing your DPA compliance.<\/p>\n\n\n\n<p>A legal expert can help tailor the agreement to your specific data processing activities and identify any potential legal pitfalls.<\/p>\n\n\n","protected":false},"excerpt":{"rendered":"<p>Organizations often rely on third-party service providers to process data on their behalf for a variety of purposes, such for managing customer relationships, handling payroll, conducting marketing campaigns, or analyzing website performance, to name just a few. While outsourcing these functions can help organizations work more smoothly, it also introduces risks associated with data privacy [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":15067,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":true,"editor_notices":[],"footnotes":""},"categories":[1],"tags":[],"class_list":["post-15058","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"thumbnail_status":false,"thumbnail_url":"https:\/\/www.cookiebot.com\/en\/wp-content\/uploads\/sites\/7\/2024\/09\/cb_some_1200x630_dpa_091724.jpg","_links":{"self":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/15058","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/comments?post=15058"}],"version-history":[{"count":0,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/posts\/15058\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media\/15067"}],"wp:attachment":[{"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/media?parent=15058"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/categories?post=15058"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookiebot.com\/en\/wp-json\/wp\/v2\/tags?post=15058"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}