Skip to content
Legiscope
Menu
Data Privacy

GDPR Data Processing Agreement: Clause and Annex Review

Review a vendor DPA against Article 28, connect clauses to service evidence, resolve annex gaps and document contract decisions.

A data processing agreement (DPA) is the usual contractual instrument between a data controller and a data processor under the GDPR. Every time an organisation engages a vendor, cloud provider, payroll bureau, or any third party that handles personal data on its behalf, Article 28 requires a binding written contract or other qualifying legal act that sets out that processing relationship.

The signature is only part of the review. A controller must select a processor offering sufficient guarantees and ensure that the binding terms match the purchased service. Missing annexes, inconsistent scope and ineffective assistance procedures can leave a gap even where a document is labelled “DPA”. The EDPB controller and processor guidelines explain why terms should contain concrete information about implementation.

Use this guide to produce a review record: the relevant clause, service evidence, unresolved gap, owner and agreed resolution. For the statutory duties and wider controller–processor relationship, start with the Article 28 explanation.

What Does Article 28 Require in a Data Processing Agreement?

Article 28(3) GDPR prescribes the minimum content that every data processing agreement gdpr must include. The contract must be in writing, which includes electronic form, and must set out:

  • Subject matter and duration of the processing
  • Nature and purpose of the processing
  • Types of personal data processed
  • Categories of data subjects whose data is processed
  • Obligations and rights of the controller

These are not optional boilerplate elements. Each clause must be specific to the actual processing relationship. A generic template that fails to describe the concrete processing activities will not satisfy the regulation.

Beyond the descriptive clauses, Article 28(3)(a)-(h) imposes eight specific obligations on the processor:

  1. Process only on documented instructions from the controller, unless required by EU or Member State law.
  2. Ensure confidentiality – all authorised persons must be under a confidentiality commitment.
  3. Implement appropriate security measures in accordance with Article 32.
  4. Respect the conditions for engaging sub-processors, including prior written authorisation.
  5. Assist the controller in responding to data subject rights requests.
  6. Assist with breach notification, DPIAs, and prior consultation under Articles 32-36.
  7. At the controller’s choice, delete or return personal data after services end, deleting copies unless EU or Member State law requires storage.
  8. Make available all information necessary to demonstrate compliance and contribute to audits.

Read the clauses together with their annexes and incorporated terms. Article 28(3) also requires the processor to tell the controller immediately if, in its opinion, an instruction infringes GDPR or other applicable EU or Member State data protection law. A contract should identify the route for that escalation.

How Should You Handle Sub-Processor Obligations?

The sub-processor chain is where many data processing agreement gdpr arrangements break down. Article 28(2) requires that a processor must not engage another processor without prior specific or general written authorisation of the controller.

Under specific authorisation, the processor obtains written consent before engaging each sub-processor. Under general authorisation, the processor informs the controller of intended changes, giving the controller the opportunity to object. The DPA must specify which model applies and document the objection mechanism.

Article 28(4) requires that the same data protection obligations in the controller-processor DPA be imposed on every sub-processor by contract. The processor remains fully liable for the sub-processor’s performance.

What Audit Rights Must the DPA Include?

Article 28(3)(h) requires the processor to make available all information necessary to demonstrate compliance and to allow for and contribute to audits conducted by the controller or a mandated auditor. Effective audit clauses should address:

  • Scope – whether the controller can audit premises, systems, and documentation, and how third-party reports or certifications contribute to assurance without extinguishing Article 28 audit rights
  • Frequency and notice – how often audits may occur and required notice periods
  • Cost allocation – who bears audit costs
  • Sub-processor coverage – whether audit rights extend down the chain

The DPA must preserve the right to conduct direct audits even where third-party certifications are accepted as the default, particularly following security incidents.

How Should International Transfers Be Addressed?

Where a processor or sub-processor is located outside the EEA, the data processing agreement gdpr must address international data transfers under Chapter V of the GDPR. The DPA should specify:

  • The transfer mechanism relied upon – adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or Article 49 derogation
  • Where the chosen transfer tool requires it, an assessment of destination-country law and practice, commonly documented as a Transfer Impact Assessment (TIA)
  • Supplementary measures where the TIA reveals gaps, such as encryption with controller-held keys

The EDPB Recommendations 01/2020 on supplementary measures remain the authoritative reference. Any DPA involving transfers to a non-adequate jurisdiction that omits these elements is exposed to enforcement risk.

Common Mistakes in Data Processing Agreements

Using generic templates without customisation. A data processing agreement gdpr that describes the processing as “providing services” without specifying data types, data subject categories, or purposes fails Article 28(3).

Failing to update DPAs when processing changes. When the scope changes – new data categories, new purposes, new sub-processors – the agreement must be updated. A record of processing activities that reflects current processing but an outdated DPA creates a compliance gap supervisory authorities will identify.

Missing data deletion provisions. The obligation to delete or return personal data at the end of the relationship is frequently absent or vaguely drafted. Specifying the deletion timeline, method, and provision of a deletion certificate strengthens compliance.

What Evidence Should a DPA Review Produce?

Keep a clause-to-evidence table rather than a binary “DPA present” flag. A reviewer should be able to trace the legal requirement to an enforceable clause and the service-specific annex. For security, record the annex version and evidence supporting the measures. For assistance, identify contacts, requested information, time commitments and escalation routes. For deletion, establish what happens to active records, backups and copies held by sub-processors.

A contract that repeats Article 28 verbatim may still omit how the parties will perform their obligations. Conversely, an incorporated electronic DPA can be binding without a separate wet-ink signature. Preserve the acceptance evidence, date, applicable order and version; do not equate “unsigned PDF” with “no contract” without checking the contracting process.

The Commission’s Decision (EU) 2021/915 provides controller-processor standard clauses for Article 28. It is distinct from the international transfer clauses in Decision 2021/914. Choose the appropriate instrument and complete its annexes; a domestic Article 28 template does not itself authorise a restricted transfer.

Example: a payroll service adds remote support

Compare the new support operation with the existing instructions. Identify whether another legal entity accesses payroll data, from where, for which purpose and with which permissions. Check sub-processor authorisation, confidentiality, security, transfer safeguards and the notice given before the change. Record any unanswered question as a gap with an owner and decision date.

Then test one assistance scenario: can the provider locate a leaver’s record, apply an authorised correction or deletion, and return evidence? Use the rights workflow and retention rules to define the request. Close the review only when the agreed contract and the live arrangement are consistent, or record the unresolved restriction and escalation. The wider GDPR requirements remain relevant to the controller’s own processing.

For a portfolio review, separate retrieval, legal analysis, negotiation and verification before allocating staff time. The DPA audit cost model helps build an organisation-specific budget and pilot a tool without treating a hypothetical saving as a measured result.

Checklist for a Compliant Data Processing Agreement

Use this checklist alongside your GDPR compliance checklist to verify each DPA in your vendor portfolio:

  • [ ] Subject matter, duration, nature, and purpose of processing described specifically
  • [ ] Types of personal data and categories of data subjects identified
  • [ ] All eight Article 28(3) processor obligations included
  • [ ] Sub-processor authorisation model specified (specific or general)
  • [ ] Sub-processor flow-down clause requiring equivalent obligations
  • [ ] Sub-processor change notification and objection mechanism documented
  • [ ] Audit rights preserved, with scope, frequency, and cost terms
  • [ ] International transfer mechanism identified and any required destination-country assessment
  • [ ] Data deletion or return obligations with timeline and certification
  • [ ] Controller due diligence on processor documented

Frequently Asked Questions

Is a data processing agreement always required under GDPR?

A binding written contract or other legal act under Union or Member State law is required for processing on behalf of a controller. There is no small-volume exception. Confirm the roles and existing incorporated terms before deciding that a separate new agreement is required.

Can we use the processor’s standard DPA template?

You can, provided it meets all Article 28 requirements and accurately describes the specific processing performed. The controller remains responsible for verifying adequacy and customising the template where standard terms do not reflect the actual processing relationship.

What happens if our processor refuses to sign a DPA?

You cannot lawfully engage that processor. If a vendor will not sign a DPA or agree to mandatory Article 28 clauses, you must either negotiate until the agreement is compliant or find an alternative processor. Using a processor without a DPA exposes the controller to enforcement action.

How often should DPAs be reviewed?

There is no fixed review period in the GDPR, but best practice is to review DPAs at least annually and whenever there is a material change in the processing relationship. Your ROPA review cycle is a natural trigger for DPA reviews.

Does the DPA need to cover data breach notification?

Yes. Article 28(3)(f) requires the processor to assist the controller with breach notification obligations under Articles 33 and 34. The DPA should specify the notification timeline (typically without undue delay and within a fixed number of hours), the information to be provided, and the cooperation obligations during incident response.

FAQ

What is a Data Processing Agreement (DPA) under GDPR?

A DPA is a legally binding contract required by Article 28 GDPR between a data controller and a data processor. It must specify the processing subject matter, duration, nature, purpose, data types, and the processor’s obligations including security, sub-processor management, and audit rights.

Are standard template DPAs (e.g. vendor terms) acceptable under GDPR?

Yes, if they cover all mandatory Article 28(3) elements. Many cloud vendors (AWS, Google, Microsoft) offer pre-signed DPAs. Controllers should verify these cover all required clauses rather than accepting them unchecked, as some vendor templates favour the vendor.

What happens to a DPA when the controller-processor relationship ends?

Article 28(3)(g) requires the processor to delete or return all personal data to the controller at the end of services. The DPA must specify which option applies and within what timeframe. EU or Member State law may require storage of particular data; document that exception and restrict further use accordingly.

Do DPAs need to be updated when GDPR changes or new regulations apply?

Review terms when applicable law or the actual processing changes. A sub-processor change may use the agreed general-authorisation process without rewriting every clause. Distinguish Article 28 clauses under Decision 2021/915 from transfer SCCs under Decision 2021/914; their purposes and applicability differ.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
02Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

International transfers require the appropriate Chapter V route. Adequacy decisions, including the EU–US Data Privacy Framework for covered recipients, fall under Article 45. Standard Contractual…

April 30, 2026
03Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — a useful reminder to examine whether the organisation supports the DPO’s actual tasks and…

July 7, 2026
04Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
05Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
06Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

Cassie (Syrenis) is positioned by its maker around consent and preference management, with publicly advertised ROPA and data-subject rights capabilities as well. If you are looking for an…

July 9, 2026
07Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026
08Data Privacy

Cookie Audit: How to Map Your Website's Cookies

A cookie audit is the foundational step for any website's GDPR and ePrivacy compliance. Without a complete, documented inventory of every cookie and tracking technology deployed on your site, your…

March 28, 2026