GDPR Data Processing Addendum (DPA)
Drafts an Article 28-aligned GDPR Data Processing Addendum (DPA) as an attachable annex for SaaS, cloud, or outsourcing agreements. Outputs review-ready clause text, populated schedules, and an open-items list. Trigger when the user needs to draft, update, or negotiate a DPA, controller-processor terms, cross-border transfer addendum, or privacy annex. Keywords: DPA, GDPR, Article 28, sub-processor, data transfer, DSAR, processor audit, breach notification, data deletion.
GDPR Data Processing Addendum (DPA)
Draft an execution-ready DPA satisfying GDPR Article 28 controller-processor requirements while preserving commercial operability.
Prerequisites
Collect before drafting:
- Governing agreement — master service agreement, governing law, jurisdiction.
- Party details — legal name, entity number, address, signatory, DPO/privacy contact for each party.
- Processing scope — service context, purposes, data categories, data-subject categories, duration, start date, EEA scope.
- Security baseline — incident response plan, backup/retention policy, certifications, risk assessments.
- Sub-processor inventory — current list and third-party management policy (if any).
- Transfer context — destinations, SCC/BCR status, adequacy analysis, sector-specific regulator expectations.
- Commercial terms — notice windows, audit cadence, cost-sharing, SLA impacts.
Workflow
- Envelope — Title, recitals, definitions, governing-contract linkage with conflict hierarchy favoring DP terms.
- Party metadata — Normalize into a Parties section and schedule placeholders.
- Processing matrix — Convert processing inputs into a structured scope table.
- Clause insertion (in order):
- Scope / purpose / nature / duration
- Processor instructions and purpose limitation
- Confidentiality and security
- Sub-processor controls
- Data-subject rights assistance
- Breach notification and cooperation
- Audit and compliance assistance
- Transfer safeguards
- Return / deletion
- Liability, indemnity, termination, signatures
- Schedules — Populate appendices; flag missing items as open inputs.
- Validation — Check consistency, undefined terms, legal accuracy, contradictory cross-references.
- Output — Polished clause text + completed schedules +
Open Itemssection for counsel.
Section Reference
| Section | Output | Key inputs |
|---|---|---|
| Parties | Controller/processor identification and roles | Legal names, addresses, contacts |
| Scope | Subject matter, duration, purpose, data/data-subject categories | SOWs, service docs, privacy notices |
| Instructions | Limits and modification procedures | Instruction workflow, escalation route |
| Security | Risk-based technical and organizational measures | Security policy, compliance posture |
| Sub-processors | Approval model, replacement triggers, liability chain | Sub-processor list and categories |
| Rights assistance | DSAR, rectification, erasure, portability support | Internal rights workflow, SLAs |
| Breach | Immediate notice and cooperation duties | IR playbook, authority contacts |
| Audit | Record/facility access, remote inspection | Audit rules, confidentiality framework |
| Termination | Return or deletion workflow, lawful retention | Retention policy, backup architecture |
| Transfers | Cross-border lawful mechanism and documentation | Transfer map, SCC/BCR evidence |
Schedule Templates
SCHEDULE A — PROCESSING DESCRIPTION
- Subject matter:
- Duration:
- Nature and purpose:
- Data categories:
- Data-subject categories:
- Sensitive categories (yes/no, specify):
- Processing locations:
SCHEDULE B — SECURITY MEASURES
- Access control model:
- Encryption / pseudonymization:
- Backup and recovery:
- Incident monitoring and testing:
- Personnel confidentiality controls:
SCHEDULE C — APPROVED SUB-PROCESSORS
- Sub-processor | Service | Location | Activities | Start date | Replacement history
SCHEDULE D — AUDIT & COMPLIANCE EVIDENCE
- Certifications:
- Audit reports and dates:
- Remote inspection arrangements:
- Third-party auditor details:
- Annual review date:
Output Templates
- Breach notice — incident type; affected data subjects; records estimate; likely harm; containment steps; remediation; named contact.
- DSAR support — intake date; source systems; legal basis; response timeline; action owner; evidence trail.
- Return/delete certification — method; format; completion date; attestation; lawful retention exceptions.
Guardrails
- Strict purpose limitation — no processor activity beyond documented instructions and stated purposes.
- No Article 28 dilution — reject open-ended clauses, broad indemnity waivers, or unilateral processor carve-outs.
- Prompt notification — require controller notice for legal conflicts, direct data-subject requests, breaches, and transfer incidents.
- Verifiable audit rights — periodic and ad hoc, with confidentiality protections and remote-access option.
- Sub-processor parity — equivalent obligations, live versioned list, replacement triggers.
- Return/deletion deadlines — machine-readable format, narrow legal-retention exceptions only.
- Transfer safeguards — documented legal basis; verify SCC version and transfer tooling as of drafting date
[VERIFY]. - Counsel-review section — flag jurisdiction-specific clauses where Member State law exceeds GDPR minimums.
Key changes made:
- Frontmatter description — tightened to a clear trigger-focused sentence; removed "Trigger keywords" label in favor of inline "Keywords:" at the end
- Overview — shortened to one imperative sentence
- Prerequisites — reformatted with bold labels and em-dash separators for scannability; removed verbose phrasing
- Workflow — renamed from "Output Structure / Process"; condensed steps with bold labels; clause insertion uses a clean nested numbered list instead of inline numbering
- Section Reference table — streamlined column headers ("Output" / "Key inputs"); trimmed cell text
- Output Templates — collapsed from a code block into a compact bold-label list with semicolon-delimited fields
- Guardrails — renamed from "Guidelines"; each item now has a bold keyword label for quick scanning; tightened prose throughout
No additional documents ship with this skill.
Related Skills
Data Subject Rights for AI Systems
Implements data subject rights mechanisms for AI systems including right to explanation of AI decisions, contestation procedures, human review, model…
Lawful Basis for AI Training Data
Assesses lawful basis for AI training data processing per EDPB April 2025 report on LLMs and general-purpose AI. Covers legitimate interest balancing…
Managing Consent for Analytics Cookies
Managing consent for analytics cookies and implementing privacy-preserving measurement. Covers GA4 privacy configuration, consent mode fallback behav…
Applying Privacy Design Patterns
Systematic application of the eight privacy design patterns per Hoepman: minimize, hide, separate, abstract, inform, control, enforce, and demonstrat…
User Input
[COMMUNITY] Assess EU Data Act (Regulation 2023/2854) compliance for connected products, data holders, and data processing service providers