DPA — Processor to Sub-Processor (EU/UK GDPR) review
Data Processing Agreement from a processor to its sub-processor under GDPR and UK GDPR. Checks cover Article 28(3) enumerated clauses, Articles 28(2)/(4)/(9) subprocessor governance, Articles 27, 30, 32, 33(2), 35, 37, and Chapter V international transfers — with an emphasis on Article 28(4) flow-down (the sub-processor must be bound by the same data-protection obligations as the upstream processor-controller DPA).
Review your document — free → See a sample report- 58 document-specific checks
- + 112 general checks
- Nothing uploaded
- Free forever (MIT)
What it checks
Subject-matter of processing identified
DPA must identify the subject-matter of the processing.
Critical · DPA-001
Duration of processing specified
DPA must specify the duration of the processing.
Critical · DPA-002
Nature and purpose of processing
DPA must describe the nature and purpose of the processing.
Critical · DPA-003
Type of personal data identified
DPA must identify the type of personal data processed.
Critical · DPA-004
Categories of data subjects identified
DPA must identify the categories of data subjects.
Critical · DPA-005
Obligations and rights of the controller stated
DPA must state the obligations and rights of the controller.
Critical · DPA-006
Processing only on documented instructions
Processor must process personal data only on documented instructions from the controller.
Critical · DPA-007
Confidentiality of authorised persons
Persons authorised to process personal data must commit themselves to confidentiality.
Critical · DPA-008
Article 32 security measures incorporated
DPA must require the processor to take all measures required pursuant to Article 32.
Critical · DPA-009
Subprocessor terms (Art. 28(2) and (4))
DPA must respect the conditions for engaging another processor.
Critical · DPA-010
Assist controller in responding to data-subject rights
Processor must assist the controller in responding to data-subject rights requests.
Critical · DPA-011
Assist controller with Articles 32–36 obligations
Processor must assist the controller with Articles 32–36 obligations (security, breach, DPIA, prior consultation).
Critical · DPA-012
Deletion or return at end of services
Processor must, at the choice of the controller, delete or return all personal data after the end of the provision of services.
Critical · DPA-013
Information available for compliance demonstration
Processor must make available all information necessary to demonstrate compliance with Article 28.
Critical · DPA-014
Subprocessor prior written authorisation (Art. 28(2))
Processor must obtain prior specific or general written authorisation before engaging a subprocessor.
Critical · DPA-015
Subprocessor change notification + objection right
Where general authorisation is used, controller must be informed of intended changes and have the opportunity to object.
Critical · DPA-016
Subprocessor flow-down of same obligations (Art. 28(4))
The DPA must require that any subprocessor the processor engages is bound by contract to the same data-protection obligations — a term Art. 28(3)(d) makes mandatory whether or not one is engaged yet.
Critical · DPA-017
DPA in writing including electronic form
DPA must be in writing, including in electronic form.
Warning · DPA-018
Pseudonymisation / encryption referenced
Art. 32(1)(a) lists pseudonymisation and encryption as appropriate measures where relevant.
Warning · DPA-019
Confidentiality / integrity / availability / resilience
Art. 32(1)(b) — ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems.
Warning · DPA-020
Restore availability after incident
Art. 32(1)(c) — ability to restore availability and access to personal data in a timely manner.
Warning · DPA-021
Regular testing of measures
Art. 32(1)(d) — process for regularly testing, assessing and evaluating effectiveness.
Warning · DPA-022
'Appropriate measures' undefined hand-waving
Flags DPAs that reference 'appropriate measures' without an Annex of technical and organisational measures.
Warning · DPA-023
Processor breach notice to controller (Art. 33(2))
Processor must notify the controller without undue delay after becoming aware of a personal data breach.
Critical · DPA-024
'Without undue delay' present
Breach-notification clause should include 'without undue delay'.
Warning · DPA-025
Breach-notice content elements (Art. 33(3))
Breach notification should include the Article 33(3) content elements (nature, categories, contact, consequences, measures).
Warning · DPA-026
Breach notice timing stricter than 'undue delay'
Flags fixed breach-notice deadlines that exceed regulator expectations (e.g., > 72 hours from controller awareness, > 5 days from processor awareness).
Warning · DPA-027
Article 30 records of processing assistance
Processor should assist controller with Art. 30 records of processing activities (RoPA).
Warning · DPA-028
DPIA assistance (Art. 35)
Processor should assist controller with Data Protection Impact Assessments under Art. 35.
Warning · DPA-029
Article 27 EU representative referenced (where applicable)
Non-EU processors should reference their EU representative under Art. 27.
Warning · DPA-030
Article 37 DPO referenced (where applicable)
Where required, the DPA should reference the Data Protection Officer under Art. 37.
Warning · DPA-031
International transfer mechanism named
Where international transfers occur, the DPA must name a Chapter V mechanism.
Critical · DPA-032
EU SCCs incorporated by reference
DPA should incorporate EU SCCs by reference where transfers require them.
Warning · DPA-033
Transfer Impact Assessment (TIA) referenced
Following Schrems II, parties should reference a TIA where Chapter V transfers occur.
Warning · DPA-034
Deletion-or-return choice belongs to processor
Flags clauses where the processor (not the controller) chooses between deletion and return.
Warning · DPA-035
Audit-substitution eliminates audit entirely
Flags SOC 2 / ISO substitution that eliminates the controller's audit right rather than substituting it.
Warning · DPA-036
Processor unilaterally amends instructions
Flags clauses where the processor may deviate from controller instructions unilaterally.
Warning · DPA-037
Personal data scope defined or annexed
DPA should define personal data scope in an Annex (Annex I for SCCs).
Warning · DPA-038
Technical and organisational measures annex
DPA should include an Annex describing technical and organisational measures (Annex II for SCCs).
Warning · DPA-039
Subprocessor list annex
DPA should include a list of approved subprocessors (Annex III for SCCs Modules 2 & 3).
Warning · DPA-040
GDPR-current terminology (Personal Data Breach defined)
DPA should track GDPR terminology (Personal Data Breach, Data Subject, Processor, Controller).
Warning · DPA-041
Controller / Processor roles named
DPA should clearly identify which party is the Controller and which is the Processor.
Critical · DPA-042
Signature block present
DPA should be signed by an authorised representative of each party.
Warning · DPA-043
Effective date present
DPA should state an effective date.
Warning · DPA-044
Term and termination clauses
DPA should state its term and termination conditions.
Warning · DPA-045
Governing-law clause present
DPA should specify governing law (typically EU Member State or UK).
Warning · DPA-046
Liability allocation
DPA should allocate liability between Controller and Processor.
Warning · DPA-047
Controller indemnifies Processor for GDPR fines
Flags clauses where the controller indemnifies the processor for the processor's own GDPR liability.
Warning · DPA-048
Processor caps audit cost on controller exclusively
Flags clauses where the controller must bear the entire cost of any audit, including audits triggered by processor breach.
Warning · DPA-049
Personal data referenced in document
DPA should reference 'personal data'; absence likely means the wrong template.
Critical · DPA-050
Notice clause present
DPA should specify how formal notices (including breach notices) are delivered.
Warning · DPA-051
Survival of GDPR obligations post-termination
DPA should state that obligations applicable to retained personal data survive termination.
Warning · DPA-052
Records of subprocessor changes available
Processor should keep records of subprocessor changes available on request.
Warning · DPA-053
Onward transfer obligations (SCC Clause 8.8)
Where SCCs apply, the DPA should reference onward-transfer obligations per SCC Clause 8.8.
Warning · DPA-054
Local-law disclosure obligations (Clause 14 / 15)
Where SCCs apply, processor must notify controller of legally-binding requests by public authorities.
Warning · DPA-055
Adequacy: reliance on the EU-US Data Privacy Framework
Flags reliance on the EU-US Data Privacy Framework (or its UK extension) so the importer's certification and a fallback transfer mechanism are confirmed.
Warning · TRANSFER-017
Adequacy decision currency clause
Where an adequacy decision is relied on, the DPA should anchor the reliance with a fallback for invalidation.
Warning · TRANSFER-018
TIA / Transfer Risk Assessment reference
Where SCCs / IDTA cover transfers to a non-adequate country, the DPA must reference a TIA / TRA.
Critical · TRANSFER-019
Every run also applies 112 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.
Sources
Often reviewed with
How it works
- Open vaulytica.com — no account, nothing to install.
- Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
- Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
More privacy & data protection documents
- Biometric Data Consent (BIPA-style)
- Children's Privacy Notice (COPPA)
- Cookie / Tracking Notice
- Data Sharing Agreement (Research / Inter-Agency)
- DPA — CCPA Service Provider (CPRA-aligned)
- DPA — Controller to Processor (EU/UK)
- DPA — Multi-State US (CCPA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, DPDPA)
- Data Protection Impact Assessment (GDPR Art. 35)
- Data-Incident Notification Template
- Privacy Notice (GDPR)
- Privacy Notice (US / CCPA)
- Privacy Policy Linter
- Records of Processing Activities (GDPR Art. 30)
- EU Standard Contractual Clauses — Module 2 (Controller to Processor)
- EU Standard Contractual Clauses — Module 3 (Processor to Processor)
- SMS / Telemarketing Consent Disclosure
- UK International Data Transfer Addendum / IDTA
- Vendor Security Addendum
- Vendor Security Questionnaire (SIG / CAIQ)