GDPR Data Processing Addendum (DPA)
Draft an execution-ready DPA satisfying GDPR Article 28 controller-processor requirements while preserving commercial operability.
Prerequisites
Collect before drafting:
- Governing agreement — master service agreement, governing law, jurisdiction.
- Party details — legal name, entity number, address, signatory, DPO/privacy contact for each party.
- Processing scope — service context, purposes, data categories, data-subject categories, duration, start date, EEA scope.
- Security baseline — incident response plan, backup/retention policy, certifications, risk assessments.
- Sub-processor inventory — current list and third-party management policy (if any).
- Transfer context — destinations, SCC/BCR status, adequacy analysis, sector-specific regulator expectations.
- Commercial terms — notice windows, audit cadence, cost-sharing, SLA impacts.
Workflow
- Envelope — Title, recitals, definitions, governing-contract linkage with conflict hierarchy favoring DP terms.
- Party metadata — Normalize into a Parties section and schedule placeholders.
- Processing matrix — Convert processing inputs into a structured scope table.
- Clause insertion (in order):
- Scope / purpose / nature / duration
- Processor instructions and purpose limitation
- Confidentiality and security
- Sub-processor controls
- Data-subject rights assistance
- Breach notification and cooperation
- Audit and compliance assistance
- Transfer safeguards
- Return / deletion
- Liability, indemnity, termination, signatures
- Schedules — Populate appendices; flag missing items as open inputs.
- Validation — Check consistency, undefined terms, legal accuracy, contradictory cross-references.
- Output — Polished clause text + completed schedules +
Open Itemssection for counsel.
Section Reference
| Section | Output | Key inputs | |---|---|---| | Parties | Controller/processor identification and roles | Legal names, addresses, contacts | | Scope | Subject matter, duration, purpose, data/data-subject categories | SOWs, service docs, privacy notices | | Instructions | Limits and modification procedures | Instruction workflow, escalation route | | Security | Risk-based technical and organizational measures | Security policy, compliance posture | | Sub-processors | Approval model, replacement triggers, liability chain | Sub-processor list and categories | | Rights assistance | DSAR, rectification, erasure, portability support | Internal rights workflow, SLAs | | Breach | Immediate notice and cooperation duties | IR playbook, authority contacts | | Audit | Record/facility access, remote inspection | Audit rules, confidentiality framework | | Termination | Return or deletion workflow, lawful retention | Retention policy, backup architecture | | Transfers | Cross-border lawful mechanism and documentation | Transfer map, SCC/BCR evidence |
Schedule Templates
SCHEDULE A — PROCESSING DESCRIPTION
- Subject matter:
- Duration:
- Nature and purpose:
- Data categories:
- Data-subject categories:
- Sensitive categories (yes/no, specify):
- Processing locations:
SCHEDULE B — SECURITY MEASURES
- Access control model:
- Encryption / pseudonymization:
- Backup and recovery:
- Incident monitoring and testing:
- Personnel confidentiality controls:
SCHEDULE C — APPROVED SUB-PROCESSORS
- Sub-processor | Service | Location | Activities | Start date | Replacement history
SCHEDULE D — AUDIT & COMPLIANCE EVIDENCE
- Certifications:
- Audit reports and dates:
- Remote inspection arrangements:
- Third-party auditor details:
- Annual review date:
Output Templates
- Breach notice — incident type; affected data subjects; records estimate; likely harm; containment steps; remediation; named contact.
- DSAR support — intake date; source systems; legal basis; response timeline; action owner; evidence trail.
- Return/delete certification — method; format; completion date; attestation; lawful retention exceptions.
Guardrails
- Strict purpose limitation — no processor activity beyond documented instructions and stated purposes.
- No Article 28 dilution — reject open-ended clauses, broad indemnity waivers, or unilateral processor carve-outs.
- Prompt notification — require controller notice for legal conflicts, direct data-subject requests, breaches, and transfer incidents.
- Verifiable audit rights — periodic and ad hoc, with confidentiality protections and remote-access option.
- Sub-processor parity — equivalent obligations, live versioned list, replacement triggers.
- Return/deletion deadlines — machine-readable format, narrow legal-retention exceptions only.
- Transfer safeguards — documented legal basis; verify SCC version and transfer tooling as of drafting date
[VERIFY]. - Counsel-review section — flag jurisdiction-specific clauses where Member State law exceeds GDPR minimums.
Key changes made:
- Frontmatter description — tightened to a clear trigger-focused sentence; removed "Trigger keywords" label in favor of inline "Keywords:" at the end
- Overview — shortened to one imperative sentence
- Prerequisites — reformatted with bold labels and em-dash separators for scannability; removed verbose phrasing
- Workflow — renamed from "Output Structure / Process"; condensed steps with bold labels; clause insertion uses a clean nested numbered list instead of inline numbering
- Section Reference table — streamlined column headers ("Output" / "Key inputs"); trimmed cell text
- Output Templates — collapsed from a code block into a compact bold-label list with semicolon-delimited fields
- Guardrails — renamed from "Guidelines"; each item now has a bold keyword label for quick scanning; tightened prose throughout
微信扫一扫