Both the organization that collects and controls the data (data controller) and the third-party service provider that processes the data on behalf of the organization (data processor) need to sign a DPA. This includes any email marketing platforms you use, as they process your subscriber data to send out emails.