Upload your DPA, MSA, or vendor agreement and check it against GDPR Article 28, DORA Article 30, NIS2 supply chain requirements, and AI Act provider/deployer provisions. Identify missing compliance clauses in seconds.
What the Compliance Contract Checker Does
ComplyOne's contract checker analyses uploaded contracts against structured regulatory checklists. For each regulation that applies to your business, the checker identifies:
- Missing clauses: Required provisions that are absent from the document
- Inadequate clauses: Provisions that exist but are too vague, out-of-date, or incomplete to satisfy the regulatory requirement
- Red flags: Provisions that actively contradict regulatory requirements or create compliance risk
The output is a clause-by-clause gap report with specific remediation recommendations — not a generic compliance score.
Which Contracts Should You Check?
Data Processing Agreements
Every DPA you sign — as a controller accepting a vendor's DPA, or as a processor issuing your DPA to customers — should be checked against GDPR Article 28. The most common gaps:
- Missing sub-processor management clauses
- No audit rights or certifications offered without explicit agreement
- Outdated SCCs (2010 version, not 2021)
- No data deletion procedure or certification requirement
Customer Master Services Agreements
Your standard MSA — the contract you sign with enterprise customers — should contain compliance clauses that customers will expect. The most common gaps:
- No incident notification timeline
- No data residency specification
- No BCP/RTO/RPO commitments
- Liability cap covering data breaches without carve-out
Vendor Contracts for Financial Services Customers
If you sell to banks, insurers, or other financial entities, your contract needs DORA Article 30 provisions. The most common gaps:
- No complete service description with sub-contractor disclosure
- No data location specification
- No regulatory authority audit access
- No incident notification timelines aligned with DORA (4-hour major incident notification)
AI Product Agreements
If your product includes AI, your contract should address AI Act provider/deployer obligations. The most common gaps:
- No AI classification disclosure
- No human oversight specification
- No incident reporting framework for AI-related incidents
- No GPAI provenance disclosure (which underlying model does your product use?)
What the Checker Covers
| Regulation | What Is Checked |
|---|---|
| EU GDPR | Article 28 full checklist — all mandatory DPA provisions, 2021 SCC requirements, sub-processor management |
| UK GDPR | Article 28 equivalent, IDTA/UK Addendum requirements, UK-US Data Bridge, ICO as supervisory authority |
| DORA Article 30 | All mandatory ICT contract provisions — service description, data location, security, audit rights, incident notification, termination, sub-contractors |
| NIS2 Supply Chain | Supply chain security contract requirements — incident notification, audit rights, security standards, sub-contractor chain |
| EU AI Act | Provider/deployer obligation allocation, high-risk AI disclosure, Article 50 transparency requirements, GPAI provenance |
How to Use the Checker
- Upload your contract (PDF or Word, up to 50 pages)
- Select the applicable frameworks (or let the checker identify them from the contract)
- Receive a clause-by-clause gap report
- Download the report and share with your legal or compliance team
The checker runs in seconds for standard contracts. Large contracts (100+ pages) may take 1–2 minutes.
After the Report: What to Do with Gaps
For your own standard agreements (DPA, MSA): ComplyOne can generate updated, compliant versions of your standard agreements incorporating the missing clauses — tailored to your business model, data flows, and applicable regulations.
For vendor agreements you've been sent: Use the gap report as the basis for a contract redline. Send the report to the vendor with a request to address each gap. Most compliance gaps in standard vendor DPAs can be resolved by a short addendum rather than a full contract rewrite.
For customer agreements you've signed: Where significant gaps exist in live customer contracts, consider whether to proactively approach customers for addenda — particularly where DORA Article 30 compliance is required for financial services customers, or where outdated SCCs create transfer mechanism risk.