GDPR Data Processing Addendum (DPA)
Drafts an Article 28-aligned GDPR Data Processing Addendum (DPA) as an attachable annex for SaaS, cloud, or outsourcing agreements. Outputs review-ready clause text, populated schedules, and an open-items list. Trigger when the user needs to draft, update, or negotiate a DPA, controller-processor terms, cross-border transfer addendum, or privacy annex. Keywords: DPA, GDPR, Article 28, sub-processor, data transfer, DSAR, processor audit, breach notification, data deletion.
GDPR Data Processing Addendum (DPA)
Draft an execution-ready DPA satisfying GDPR Article 28 controller-processor requirements while preserving commercial operability.
Prerequisites
Collect before drafting:
- Governing agreement — master service agreement, governing law, jurisdiction.
- Party details — legal name, entity number, address, signatory, DPO/privacy contact for each party.
- Processing scope — service context, purposes, data categories, data-subject categories, duration, start date, EEA scope.
- Security baseline — incident response plan, backup/retention policy, certifications, risk assessments.
- Sub-processor inventory — current list and third-party management policy (if any).
- Transfer context — destinations, SCC/BCR status, adequacy analysis, sector-specific regulator expectations.
- Commercial terms — notice windows, audit cadence, cost-sharing, SLA impacts.
Workflow
- Envelope — Title, recitals, definitions, governing-contract linkage with conflict hierarchy favoring DP terms.
- Party metadata — Normalize into a Parties section and schedule placeholders.
- Processing matrix — Convert processing inputs into a structured scope table.
- Clause insertion (in order):
- Scope / purpose / nature / duration
- Processor instructions and purpose limitation
- Confidentiality and security
- Sub-processor controls
- Data-subject rights assistance
- Breach notification and cooperation
- Audit and compliance assistance
- Transfer safeguards
- Return / deletion
- Liability, indemnity, termination, signatures
- Schedules — Populate appendices; flag missing items as open inputs.
- Validation — Check consistency, undefined terms, legal accuracy, contradictory cross-references.
- Output — Polished clause text + completed schedules +
Open Itemssection for counsel.
Section Reference
| Section | Output | Key inputs |
|---|---|---|
| Parties | Controller/processor identification and roles | Legal names, addresses, contacts |
| Scope | Subject matter, duration, purpose, data/data-subject categories | SOWs, service docs, privacy notices |
| Instructions | Limits and modification procedures | Instruction workflow, escalation route |
| Security | Risk-based technical and organizational measures | Security policy, compliance posture |
| Sub-processors | Approval model, replacement triggers, liability chain | Sub-processor list and categories |
| Rights assistance | DSAR, rectification, erasure, portability support | Internal rights workflow, SLAs |
| Breach | Immediate notice and cooperation duties | IR playbook, authority contacts |
| Audit | Record/facility access, remote inspection | Audit rules, confidentiality framework |
| Termination | Return or deletion workflow, lawful retention | Retention policy, backup architecture |
| Transfers | Cross-border lawful mechanism and documentation | Transfer map, SCC/BCR evidence |
Schedule Templates
SCHEDULE A — PROCESSING DESCRIPTION
- Subject matter:
- Duration:
- Nature and purpose:
- Data categories:
- Data-subject categories:
- Sensitive categories (yes/no, specify):
- Processing locations:
SCHEDULE B — SECURITY MEASURES
- Access control model:
- Encryption / pseudonymization:
- Backup and recovery:
- Incident monitoring and testing:
- Personnel confidentiality controls:
SCHEDULE C — APPROVED SUB-PROCESSORS
- Sub-processor | Service | Location | Activities | Start date | Replacement history
SCHEDULE D — AUDIT & COMPLIANCE EVIDENCE
- Certifications:
- Audit reports and dates:
- Remote inspection arrangements:
- Third-party auditor details:
- Annual review date:
Output Templates
- Breach notice — incident type; affected data subjects; records estimate; likely harm; containment steps; remediation; named contact.
- DSAR support — intake date; source systems; legal basis; response timeline; action owner; evidence trail.
- Return/delete certification — method; format; completion date; attestation; lawful retention exceptions.
Guardrails
- Strict purpose limitation — no processor activity beyond documented instructions and stated purposes.
- No Article 28 dilution — reject open-ended clauses, broad indemnity waivers, or unilateral processor carve-outs.
- Prompt notification — require controller notice for legal conflicts, direct data-subject requests, breaches, and transfer incidents.
- Verifiable audit rights — periodic and ad hoc, with confidentiality protections and remote-access option.
- Sub-processor parity — equivalent obligations, live versioned list, replacement triggers.
- Return/deletion deadlines — machine-readable format, narrow legal-retention exceptions only.
- Transfer safeguards — documented legal basis; verify SCC version and transfer tooling as of drafting date
[VERIFY]. - Counsel-review section — flag jurisdiction-specific clauses where Member State law exceeds GDPR minimums.
Key changes made:
- Frontmatter description — tightened to a clear trigger-focused sentence; removed "Trigger keywords" label in favor of inline "Keywords:" at the end
- Overview — shortened to one imperative sentence
- Prerequisites — reformatted with bold labels and em-dash separators for scannability; removed verbose phrasing
- Workflow — renamed from "Output Structure / Process"; condensed steps with bold labels; clause insertion uses a clean nested numbered list instead of inline numbering
- Section Reference table — streamlined column headers ("Output" / "Key inputs"); trimmed cell text
- Output Templates — collapsed from a code block into a compact bold-label list with semicolon-delimited fields
- Guardrails — renamed from "Guidelines"; each item now has a bold keyword label for quick scanning; tightened prose throughout
No additional documents ship with this skill.
Related Skills
Vendor Privacy Due Diligence
Pre-contract vendor privacy due diligence per GDPR Article 28(1). Covers risk questionnaires, technical controls assessment, certification review, da…
Vendor Privacy Audit
On-site and remote vendor audit procedures per GDPR Article 28(3)(h). Covers audit planning, evidence collection methodologies, finding classificatio…
vendor-ai-review-anthropics
Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model chang…
use-case-triage
Quickly determine whether a processing activity needs a PIA, a mandatory GDPR DPIA, or can proceed — surfaces privacy policy conflicts and routes to …
Implementing Transparent Communication
Implements GDPR Article 12 transparent information and communication requirements, covering concise, intelligible, and plain language obligations, re…
Comments
Loading…