Data Processing Agreements (DPAs) arrive in two directions: customers send you their standard DPA for you to sign as a processor, and vendors send you their DPA when you onboard their services as a sub-processor. In both cases, the DPA needs to be reviewed against the GDPR Article 28 requirements before signing. Manual review is time-consuming. Automated review is fast, consistent, and catches what manual reviewers miss.
Why DPA Review Matters
Controllers who sign non-compliant DPAs are in breach of Article 28 — regardless of whether they noticed the gap. Processors who sign customer DPAs that impose unworkable obligations create operational risks. In both cases, the document you sign becomes the evidence in any ICO, EDPB, or BaFin investigation.
The volume of DPAs in any SaaS company's contract stack is significant:
- Every SaaS tool that accesses your customer data requires a DPA
- Every enterprise customer will send a DPA for your signature as their processor
- Every sub-processor you use should have a DPA in place
A company with 20 SaaS tools, 50 enterprise customers, and 5–10 sub-processors has 75–80 DPAs to maintain. Reviewing each one manually is unsustainable.
The Article 28 Checklist for DPA Review
When reviewing any DPA — whether you are signing as a processor or issuing as a controller — the following elements must be present and adequate:
Subject Matter and Duration
- Is the subject matter of processing clearly defined?
- Is the duration of processing stated (or tied to the contract term)?
Nature and Purpose of Processing
- Is the purpose of processing specified?
- Is the nature of processing described (storage, analysis, transmission, etc.)?
Type of Personal Data
- Are the categories of personal data enumerated?
- Are special category data types identified where applicable?
Categories of Data Subjects
- Are the categories of individuals whose data is processed identified?
Instructions Clause
- Does the processor commit to processing only on documented instructions?
- Is there a mechanism for giving and recording instructions?
- Is there an obligation to notify the controller if an instruction would infringe GDPR?
Confidentiality
- Do persons authorised to process personal data have confidentiality obligations?
- Is the basis for confidentiality specified (contract, professional obligation, statutory)?
Security Measures
- Are appropriate technical and organisational measures specified?
- Is there a reference to an Annex or Security Schedule with specifics, or are measures described in the DPA body?
Sub-Processor Management
- Is there a general or specific authorisation for sub-processors?
- Is there a notification obligation when sub-processors change?
- Does the processor impose equivalent obligations on sub-processors?
- Is there a right for the controller to object to new sub-processors?
Data Subject Rights Assistance
- Does the processor assist with data subject rights requests?
- Is a process or timeline specified?
Compliance Assistance
- Does the processor assist with security obligations (Article 32)?
- Does the processor assist with DPIA preparation (Article 35)?
- Does the processor assist with breach notification?
Deletion or Return
- Is there an obligation to delete or return data on contract termination?
- Are timelines specified?
- Does the obligation cover data at sub-processors?
- Is there a certification of deletion requirement?
Audit Rights
- Does the controller have audit and inspection rights?
- Is the process for conducting audits specified (notice, scope)?
- Are certifications accepted as an alternative (with explicit agreement)?
International Transfers
- If data is transferred outside the EEA, is the transfer mechanism specified?
- If SCCs are used, is the correct 2021 version and module referenced?
- If the Data Privacy Framework is used, is the processor's DPF certification confirmed?
Red Flags in DPAs You Receive
When reviewing a vendor's standard DPA before signing:
Outdated SCCs: If the DPA references SCCs from 2010 (the old version), the transfer mechanism is invalid. The 2021 SCCs replaced them.
Blanket sub-processor authorisation without notice: "Customer agrees that [Vendor] may use sub-processors" with no notification obligation and no right to object violates Article 28(2).
Deletion on request rather than on termination: Some DPAs require you to separately request deletion after termination rather than making it automatic. This creates a risk of data persisting indefinitely.
Audit rights replaced entirely by certifications: While certifications can satisfy audit rights, this must be explicitly agreed. A DPA that simply says "we hold ISO 27001" without granting audit rights is insufficient.
No liability alignment: Some vendor DPAs limit all liability including data breaches to a small cap. Check whether this conflicts with your obligations as a controller to data subjects.
How ComplyOne Automates DPA Review
ComplyOne's DPA review tool:
- Accepts a DPA in PDF or Word format
- Analyses it against the complete Article 28 checklist
- Identifies missing clauses, inadequate provisions, and common red flags
- Generates a gap report with specific recommendations
- For processor DPAs you issue to customers: generates a compliant DPA template for your use
The tool covers both EU GDPR and UK GDPR requirements — flagging where a DPA addresses only one framework when both apply.