Data processing agreement

The contract between a controller and a processor that sets out how the processor may handle personal data, as Article 28(3) of the GDPR requires.

Article 28(3) lists what it must cover: the subject matter, duration, nature and purpose of the processing, the types of personal data and categories of data subjects, and the processor’s obligations. Those include acting only on the controller’s documented instructions, confidentiality, security, the rules for engaging subprocessors, help with data subject requests and breaches, deleting or returning the data at the end, and audits.

SaaS vendors usually offer their DPA as an addendum to their terms. It often sets the notice period for new subprocessors and the way to object, so a change to the DPA can matter as much as a change to the list.

Source: GDPR Art. 28(3) ↗

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.