Skip to content
Innopulse Consulting

Reviewing a data processing agreement: what to look for before signing

For: Procurement, legal and IT leads

Updated: 2026-09

In short

Six points decide a DPA review: subject matter and instruction binding, the sub-processor chain and your right to object, place of processing, assistance with data subject rights, the breach notification route, and what happens to the data when the contract ends.

Data processing agreements are almost always supplied by the vendor and almost always signed unread. That is understandable, because they resemble one another closely — and risky, because the differences sit exactly where it matters in a live incident.

This checklist is written for reviewing, not for drafting. It helps locate the few points where a standard document diverges from what you actually need.

The checklist

  1. 01

    Check subject matter and data categories concretely

    The agreement must name nature, purpose, duration, data categories and the groups of people affected. Generic wording with no link to your actual use is a warning sign.

    Done when: The data categories described match what you in fact put into the system.

  2. 02

    Read the instruction binding and its exceptions

    The processor may act only on documented instruction. Check which exceptions the agreement carves out — in particular processing for the vendor’s own purposes.

    Done when: It is clear whether and for what the vendor may use the data for its own purposes, such as product improvement.

  3. 03

    Clarify the sub-processor chain and objection right

    A list of sub-processors belongs in the agreement, along with a procedure for new ones. What matters is whether you can object and what an objection actually achieves.

    Done when: The current list is available and the notice period for new sub-processors is named.

  4. 04

    Pin down the place of processing

    Not only the primary location but also support and remote access. Support from a third country is processing, even where data is not stored there.

    Done when: The agreement names the processing locations, and remote access from third countries is expressly addressed.

  5. 05

    Check assistance with data subject rights

    You have to answer access and erasure requests within the deadline. Where the vendor offers only a general assistance commitment, establish the concrete route and response time.

    Done when: The procedure for an access request is described rather than merely promised in general terms.

  6. 06

    Check the breach notification route

    You face a short deadline towards the supervisory authority. Where the agreement says only that notification will be prompt, settle the channel and recipient in advance.

    Done when: Channel, recipient and expected response time are named and known internally.

  7. 07

    Settle return and deletion at contract end

    Check the format in which data comes back, the deletion deadline and whether confirmation of deletion is provided for. These points are frequently missing or vague.

    Done when: Export format, deletion deadline and confirmation are named in the agreement.

Common mistakes

  • The agreement gets signed but the annex with the sub-processor list is never read — although that is where the actual information sits.
  • A clause permits use of the data for the vendor’s own purposes, such as product improvement. That is no longer plain processing on behalf.
  • Support sits in a third country, which does not appear in the agreement because storage is in the EU.
  • No export format is agreed for contract end. The export is then technically possible but practically unusable.

What this checklist does not cover

  • This is a review aid and does not replace legal review, particularly where special categories of data are involved.
  • It does not cover contractual safeguards for third-country transfers. Standard contractual clauses and transfer impact assessments are their own subject.
  • Joint controllership requires a different type of agreement with different requirements; the boundary has to be assessed case by case.

Parent service: IT Consulting

FAQ

Can we negotiate a large vendor’s standard agreement?

With large platform vendors, usually not. The review still pays off, because it shows which residual risks you are accepting and what has to be mitigated elsewhere.

Do we need a DPA for small tools too?

Once personal data is processed on your behalf, yes — regardless of scale. Small tools such as error tracking or form services are precisely the ones that get overlooked.

What applies to Swiss companies?

The revised Swiss data protection act also requires contractual regulation of processing on behalf. Where there is an EU nexus, Article 28 GDPR applies in addition.

LM
Reviewed by
Founder & CEO · MSc Innovation Management (FFHS) · Author of “Identity Over Discipline”
Working on something similar?

Reviewing a data processing agreement: what to look for before signing