Every SaaS vendor that processes personal data for EU customers must have a compliant Data Processing Agreement (DPA). But most vendor contracts — even those with a DPA attached — are missing critical clauses that GDPR Article 28 mandates. The gap is often invisible until an enterprise customer's legal team or a DPA audit finds it.
This article identifies the most common missing GDPR clauses in vendor contracts and explains what complete compliance looks like.
The Article 28 Requirement
GDPR Article 28 requires that any processor handling personal data on behalf of a controller must be bound by a written contract or legal act. That contract must include specific, mandatory provisions — not optional items to include if convenient, but requirements without which the contract is non-compliant.
Many companies have DPAs that look complete but omit or inadequately address key elements. Controllers using those vendors are in violation of Article 28 — regardless of the vendor's own compliance status.
The 10 Most Commonly Missing GDPR Clauses
1. Processing Only on Documented Instructions
The DPA must state that the processor processes personal data only on the controller's documented instructions. Many DPAs include this as a vague statement ("we will process data as instructed") without specifying what instructions look like, how they are given, and what happens when the processor receives a request for processing outside those instructions.
What complete compliance looks like: A clear mechanism for instructions (the contract itself plus a written instruction process), a clause requiring the processor to notify the controller if any instruction appears to infringe GDPR.
2. Notification of Legally Binding Disclosure Requests
If the processor receives a legally binding request from a government or law enforcement to disclose personal data, GDPR Article 28(3)(a) requires the processor to inform the controller — unless prohibited by law.
Commonly missing: Many DPAs are silent on this. Vendors simply do not include the obligation.
3. Confidentiality of Persons Authorised to Process
All personnel with access to personal data must be bound by a confidentiality obligation — either by contract or statutory duty.
Commonly missing or inadequate: A statement that staff "have appropriate confidentiality obligations" without specifying the mechanism. The DPA should confirm either individual confidentiality agreements or that personnel are bound by professional rules of confidentiality.
4. Sub-Processor Management
This is the most frequently incomplete area. Article 28(4) requires that the processor imposes the same data protection obligations on any sub-processor as apply under the DPA with the controller.
Common gaps:
- DPA grants general authorisation for sub-processors with no notification requirement
- No obligation on the processor to maintain a current sub-processor list
- No mechanism for the controller to object to new sub-processors
- No requirement that sub-processors are bound to equivalent contractual terms
5. Data Subject Rights Assistance
The processor must assist the controller in responding to data subject rights requests — access, erasure, portability, rectification. The DPA should specify how this assistance is provided.
Commonly missing: The clause says "we will assist" without specifying a timeline, a process, or how requests are routed between the parties.
6. Security Measures Specification
Article 28(3)(c) requires appropriate technical and organisational security measures, referenced in the DPA. Many DPAs include a generic security appendix or a link to a security policy URL that may change.
Best practice: An Annex or Security Addendum specifying the security measures in detail — encryption standards, access controls, penetration testing schedule, incident response procedures.
7. DPIA Assistance
Where a data protection impact assessment (DPIA) is required, the processor must assist the controller. DPAs frequently omit this entirely or include an unworkable "we will assist upon request" clause.
What to look for: A clause specifying that the processor will provide the information needed for DPIA completion — including information about sub-processors, data flows, and security measures.
8. Deletion or Return at Contract End
The DPA must address what happens to personal data at contract termination. The processor must either delete or return all personal data. Many DPAs say "we will delete data within 30 days" without addressing backup retention, archived data, or data held by sub-processors.
Common gap: No clause addressing backup retention periods or the procedure for confirming deletion has occurred.
9. Audit Rights
The controller must have the right to audit the processor's compliance with the DPA. Article 28(3)(h) requires this. Many DPAs replace audit rights with an obligation to provide certifications (SOC 2, ISO 27001) — which is only acceptable if explicitly agreed.
Best practice: Audit rights with a specified notice period and scope, with an explicit option to use certifications as an alternative with controller agreement.
10. International Transfer Mechanism
If the processor uses sub-processors outside the EEA, the DPA must address the transfer mechanism. Many DPAs reference the standard contractual clauses but do not specify which module applies, or use outdated 2010 SCCs instead of the 2021 version.
How ComplyOne Identifies Missing Clauses
ComplyOne's contract review tool analyses your vendor DPAs against the complete Article 28 checklist, identifies missing or inadequate clauses, and generates a clause-by-clause remediation report. Upload a DPA and receive a compliance gap analysis in minutes.