How to Review a Data Processing Agreement: A Checklist

How to review a data processing agreement: the subprocessor notice, objection window, breach clock and audit clauses to check, with real vendor wording.

By The ClauseTrail team 9 min read

A data processing agreement is only useful if you know which clauses to read and what “good” looks like when you find them. This is a practitioner checklist for the Article 28 fields that matter once a SaaS vendor is live: subprocessor notice, objection windows, breach notification and audit rights.

You do not need to mark up every recital. You do need a repeatable pass that a privacy counsel, a security reviewer and procurement can share, so the same gaps do not get rediscovered at renewal.

What Article 28 requires in a data processing agreement

Article 28 of the GDPR sets the frame. The controller may only use processors that provide sufficient guarantees, and the processing must be governed by a contract (or other binding act) that covers, among other things, documented instructions, confidentiality, security, assistance with data-subject rights, deletion or return at the end, and the rules for engaging other processors.

Article 28(2) and 28(4) are the subprocessor spine: the processor needs the controller’s authorisation before engaging another processor, and that other processor must be bound by the same data-protection obligations. Almost every SaaS DPA turns the specific-authorisation model into a general authorisation with a published list, advance notice and a chance to object. That is why the notice and objection clauses are not boilerplate. They are how the authorisation works in practice. For the list itself, see our guide on what a subprocessor is.

Article 28(3)(f) also requires the processor to help the controller meet its security and breach duties under Articles 32 to 36. The clock the vendor promises you in the DPA is where that help becomes measurable.

Subprocessor notice: days, channel and what counts as notice

Start with three numbers and one channel.

  1. How many days of advance notice before a new subprocessor may process your data.
  2. How notice is delivered (email to a named contact, a portal, a mailing list you must subscribe to).
  3. What the notice must contain (entity name, purpose, location, and whether the list URL is authoritative).

As of our check on 25 September 2026, Stripe’s DPA says Stripe will email the user at least 30 days before adding a subprocessor takes effect. As of the same day’s check, Atlassian’s DPA promises at least 30 days’ notice to subscribed emails before a new subprocessor may process customer personal data. Both are clear advance-notice models. Flag any DPA that only says “reasonable notice”, that posts a silent list update with no email, or that makes notice conditional on you finding a changelog yourself.

Also check whether affiliates and “infrastructure” providers sit inside or outside the notice duty. Carve-outs that swallow cloud hosts, CDNs or support tools gut the clause. If the list and the DPA disagree on who is covered, treat that as a review finding, not a drafting quirk.

Objection windows: separate from notice, and easy to miss

Notice and objection are related but not the same. Notice is how early you hear. The objection window is how long you have to push back on reasonable data-protection grounds, and what happens if you do (termination right, escalation, or silence treated as acceptance).

Read HubSpot carefully on this point. As of our check on 25 September 2026, HubSpot’s DPA gives customers 30 days from notification to object to a new subprocessor on reasonable grounds relating to the protection of customer personal data. That is an objection window measured from the notice, not necessarily a promise that the change waits 30 days after you first hear about it, unless another sentence says so. When you review the agreement, write down both figures if both exist, and refuse to collapse them into one spreadsheet cell labelled “30 days”.

Ask what “reasonable grounds” means in the vendor’s playbook, whether objection can block the engagement or only let you exit, and whether the window still runs if notice went to an abandoned inbox. Operationally, someone on your side must own the mailbox and the calendar invite that matches the window.

Breach notification: the number lives in the DPA

Article 33(2) of the GDPR requires a processor to notify the controller of a personal data breach “without undue delay” after becoming aware of it. The GDPR does not put a fixed hour count on that processor-to-controller duty. Your data processing agreement is where a number usually appears.

Compare real clauses. As of 25 September 2026, Stripe commits to notify without undue delay and, for Data Incidents affecting personal data subject to the GDPR or UK GDPR, no later than 48 hours. HubSpot states notice without undue delay and no later than 72 hours after becoming aware of a customer personal data breach. Atlassian states notice without undue delay and, where feasible, no later than 72 hours after becoming aware of a Security Incident. Those are different promises, including different triggers and Atlassian’s “where feasible” qualifier. A review that only ticks “breach clause present” hides the difference.

Also check:

  • Whether the clock starts on awareness of a security incident or of a personal data breach.
  • What the notice must include (nature, categories, approximate numbers, likely consequences, measures taken).
  • Whether the vendor notifies you before public statements or regulator contact when you are the controller.
  • How subprocessors’ incidents flow up to you.

Your own 72-hour duty to the supervisory authority under Article 33(1) is not the same clock. The EDPB Guidelines 9/2022 on personal data breach notification treat the controller as becoming aware once the processor has informed it. A late processor notice therefore compresses the controller’s own window to assess and, where required, notify the supervisory authority. That is why the contractual hour count in the DPA matters in practice.

Audit rights: certifications are not a blank cheque

Article 28(3)(h) expects the processor to make available information necessary to demonstrate compliance and to allow for and contribute to audits. SaaS DPAs usually narrow that to annual rights, questionnaires, or the production of SOC 2 and penetration-test summaries.

As of 25 September 2026, Stripe’s DPA contributes to audits by making audit reports available following the user’s written request. HubSpot’s DPA, on request, supplies its SOC 2 report and summary copies of penetration-testing reports on a confidential basis. Atlassian’s DPA, on the same check date, frames customer audits as no more than once every twelve months, with findings limited to information relevant to the customer. None of those models is automatically “bad”. What fails a review is a clause that promises cooperation while giving you no practical way to verify anything when a questionnaire answer conflicts with the subprocessor list.

Pair the audit clause with whatever SOC 2 the vendor will share (Type II covers a period; it still does not replace the DPA fields above). Our note on SOC 2 Type I versus Type II covers what to open in the report itself.

Transfers and retention: two more fields worth one pass

While you are in the document, capture transfer mechanisms and end-of-contract retention in the same notes. Stripe’s DPA (25 September 2026 check) names the 2021 standard contractual clauses and Data Privacy Framework self-certification. HubSpot adds binding corporate rules alongside SCCs and the Data Privacy Framework. Atlassian references SCCs, the Data Privacy Framework and adequacy decisions. Our comparison of standard contractual clauses versus the Data Privacy Framework is the deeper read; for this checklist, you only need to record which tools the DPA actually names and whether a fallback survives if one falls away.

On retention, look for deletion or return on termination, any residual copies, and whether backups sit outside the promise. As of the same check date, Stripe and HubSpot each state deletion or return when the agreement ends. Atlassian states deletion of all customer personal data following expiration or termination, in accordance with its documentation (deletion only on that reading, not a customer choice of return). Note the procedure document each vendor points to; the DPA sentence is only half the control.

The one checklist worth running this week

Open one live vendor’s data processing agreement and its current subprocessor list side by side. Fill this grid before you touch another PDF:

  1. Advance notice period (days) and delivery channel.
  2. Objection window (days from what trigger) and consequence of objecting.
  3. Breach notification period (hours or “undue delay” only) and what starts the clock.
  4. Audit right model (on-site, annual, certifications only) and last evidence you hold.
  5. Transfer mechanisms named, plus deletion or return on termination.
  6. Owner on your team for notices, and the mailbox that must receive them.

If any cell is blank, “reasonable” or “as required by law” with no number, that is your finding. Re-run the same grid when the DPA version changes; ClauseTrail’s DPA and contract terms we watch are built around those fields so mid-cycle edits do not wait for renewal.

ClauseTrail reads vendor DPAs, privacy policies, terms of service, subprocessor lists and AI-usage terms every day, and alerts compliance teams when the commitments above change. See what we watch in vendor contracts and pricing.

Frequently Asked Questions

What is a data processing agreement under the GDPR?

A data processing agreement is the contract (or other binding act) between a controller and a processor that Article 28(3) requires. It sets how the processor may handle personal data: instructions, security, subprocessors, assistance with breaches and data-subject rights, and what happens to the data when the relationship ends.

How much subprocessor notice should a data processing agreement give?

There is no single statutory number of days in Article 28. Common SaaS practice is around 30 days’ advance notice before a new subprocessor processes customer data, with an email or subscription channel. Treat “reasonable notice” without a period, or silent list updates, as a gap to negotiate or accept with a recorded risk decision.

What is the difference between notice and an objection window?

Notice is how early the vendor tells you a subprocessor will be added. The objection window is how long you have after that notice (or another stated trigger) to object on data-protection grounds, and whether objection blocks the engagement or only lets you terminate. A review should record both, not merge them.

Does the GDPR set a 72-hour deadline for processor-to-controller breach notice?

Article 33(2) requires processors to notify controllers “without undue delay”. The familiar 72-hour figure in Article 33(1) is the controller’s duty to the supervisory authority. Many DPAs still choose 48 or 72 hours as the contractual processor-to-controller clock; read the number and the trigger the vendor actually signed.

Are SOC 2 reports enough to satisfy DPA audit rights?

Usually not on their own. SOC 2 evidence can support the information and audit cooperation the DPA promises, especially where the clause limits you to reports and certifications. It does not replace checking subprocessor notice, breach timing or transfer language in the data processing agreement itself.

Written from the primary sources as they stood on 8 October 2026. General information, not legal advice.

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.