Free DPA checker for GDPR and US privacy laws.
Drop a Data Processing Agreement and see which required terms are present, which are missing, and which are too weak — checked against the text of the GDPR, UK GDPR, the CCPA and other US state privacy laws, with every finding linked to the provision it relies on.
Check your DPA now →- Free forever (MIT)
- Nothing uploaded
- No account
- 1,825 cited checks
- PDF or DOCX
What it checks in a DPA
GDPR Article 28(3) required terms
Documented instructions, confidentiality of personnel, security, sub-processing, assistance with data-subject rights, deletion or return, and audit rights.
Sub-processor governance
Prior authorization, notice of changes and flow-down of obligations under Articles 28(2), 28(4) and 28(9).
Security, breach notice and DPIA assistance
Article 32 security measures, Article 33(2) notice to the controller, and Article 35 support.
International transfers
Chapter V transfer mechanisms, including the EU Standard Contractual Clauses, the UK IDTA and Addendum, and Swiss FADP terms.
CCPA / CPRA service-provider terms
The contract terms Cal. Civ. Code § 1798.140(ag) and 11 CCR § 7051 require for service-provider status.
Other US state privacy laws
Processor-contract requirements under Virginia, Colorado, Connecticut, Utah, Texas, Oregon and other state laws.
What you get
A Word report
A findings index by severity, then each finding in full: the quoted clause, its position, the rule, and its source.
Comments on your own draft
Your .docx back with each finding attached as a Word comment on the clause it is about.
Deadlines on your calendar
Renewal, notice and cure dates the document states, as an .ics file.
Obligations and fix lists
Who owes what, and what to fix, as spreadsheets you can sort and share.
How it works
- Open vaulytica.com — no account, nothing to install.
- Drop your PDF or DOCX. It is read inside your browser tab; nothing is uploaded.
- Get your report in seconds. The document type is detected and only the checks that belong to it run.
Questions
Which DPAs does it support?
Controller-to-processor and processor-to-sub-processor DPAs under the EU and UK GDPR, CCPA service-provider agreements, and multi-state US DPAs.
Can it check a DPA against its privacy notice or main agreement?
Yes. Drop the documents together and they are cross-checked, for example a privacy notice that denies a disclosure its own DPA authorizes.
Is it safe to use on a confidential DPA?
Yes. The analysis runs in your browser. Nothing is uploaded, logged or retained, and you can confirm that in your browser's Network tab.