vaulytica

Free DPA checker for GDPR and US privacy laws.

Drop a Data Processing Agreement and see which required terms are present, which are missing, and which are too weak — checked against the text of the GDPR, UK GDPR, the CCPA and other US state privacy laws, with every finding linked to the provision it relies on.

Check your DPA now →

What it checks in a DPA

GDPR Article 28(3) required terms

Documented instructions, confidentiality of personnel, security, sub-processing, assistance with data-subject rights, deletion or return, and audit rights.

Sub-processor governance

Prior authorization, notice of changes and flow-down of obligations under Articles 28(2), 28(4) and 28(9).

Security, breach notice and DPIA assistance

Article 32 security measures, Article 33(2) notice to the controller, and Article 35 support.

International transfers

Chapter V transfer mechanisms, including the EU Standard Contractual Clauses, the UK IDTA and Addendum, and Swiss FADP terms.

CCPA / CPRA service-provider terms

The contract terms Cal. Civ. Code § 1798.140(ag) and 11 CCR § 7051 require for service-provider status.

Other US state privacy laws

Processor-contract requirements under Virginia, Colorado, Connecticut, Utah, Texas, Oregon and other state laws.

What you get

A Word report

A findings index by severity, then each finding in full: the quoted clause, its position, the rule, and its source.

Comments on your own draft

Your .docx back with each finding attached as a Word comment on the clause it is about.

Deadlines on your calendar

Renewal, notice and cure dates the document states, as an .ics file.

Obligations and fix lists

Who owes what, and what to fix, as spreadsheets you can sort and share.

See a real sample report →

How it works

  1. Open vaulytica.com — no account, nothing to install.
  2. Drop your PDF or DOCX. It is read inside your browser tab; nothing is uploaded.
  3. Get your report in seconds. The document type is detected and only the checks that belong to it run.
Check your DPA now →

Questions

Which DPAs does it support?

Controller-to-processor and processor-to-sub-processor DPAs under the EU and UK GDPR, CCPA service-provider agreements, and multi-state US DPAs.

Can it check a DPA against its privacy notice or main agreement?

Yes. Drop the documents together and they are cross-checked, for example a privacy notice that denies a disclosure its own DPA authorizes.

Is it safe to use on a confidential DPA?

Yes. The analysis runs in your browser. Nothing is uploaded, logged or retained, and you can confirm that in your browser's Network tab.

Other free reviews