Reviewing a data processing agreement: what to look for before signing
For: Procurement, legal and IT leads
Updated: 2026-09
Six points decide a DPA review: subject matter and instruction binding, the sub-processor chain and your right to object, place of processing, assistance with data subject rights, the breach notification route, and what happens to the data when the contract ends.
Data processing agreements are almost always supplied by the vendor and almost always signed unread. That is understandable, because they resemble one another closely — and risky, because the differences sit exactly where it matters in a live incident.
This checklist is written for reviewing, not for drafting. It helps locate the few points where a standard document diverges from what you actually need.
The checklist
- 01
Check subject matter and data categories concretely
The agreement must name nature, purpose, duration, data categories and the groups of people affected. Generic wording with no link to your actual use is a warning sign.
Done when: The data categories described match what you in fact put into the system.
- 02
Read the instruction binding and its exceptions
The processor may act only on documented instruction. Check which exceptions the agreement carves out — in particular processing for the vendor’s own purposes.
Done when: It is clear whether and for what the vendor may use the data for its own purposes, such as product improvement.
- 03
Clarify the sub-processor chain and objection right
A list of sub-processors belongs in the agreement, along with a procedure for new ones. What matters is whether you can object and what an objection actually achieves.
Done when: The current list is available and the notice period for new sub-processors is named.
- 04
Pin down the place of processing
Not only the primary location but also support and remote access. Support from a third country is processing, even where data is not stored there.
Done when: The agreement names the processing locations, and remote access from third countries is expressly addressed.
- 05
Check assistance with data subject rights
You have to answer access and erasure requests within the deadline. Where the vendor offers only a general assistance commitment, establish the concrete route and response time.
Done when: The procedure for an access request is described rather than merely promised in general terms.
- 06
Check the breach notification route
You face a short deadline towards the supervisory authority. Where the agreement says only that notification will be prompt, settle the channel and recipient in advance.
Done when: Channel, recipient and expected response time are named and known internally.
- 07
Settle return and deletion at contract end
Check the format in which data comes back, the deletion deadline and whether confirmation of deletion is provided for. These points are frequently missing or vague.
Done when: Export format, deletion deadline and confirmation are named in the agreement.
Common mistakes
- —The agreement gets signed but the annex with the sub-processor list is never read — although that is where the actual information sits.
- —A clause permits use of the data for the vendor’s own purposes, such as product improvement. That is no longer plain processing on behalf.
- —Support sits in a third country, which does not appear in the agreement because storage is in the EU.
- —No export format is agreed for contract end. The export is then technically possible but practically unusable.
What this checklist does not cover
- —This is a review aid and does not replace legal review, particularly where special categories of data are involved.
- —It does not cover contractual safeguards for third-country transfers. Standard contractual clauses and transfer impact assessments are their own subject.
- —Joint controllership requires a different type of agreement with different requirements; the boundary has to be assessed case by case.
Parent service: IT Consulting
Matching offers
GDPR & revDSG audit for SaaS
A data protection audit for SaaS checks whether data flows, processing agreements, deletion concept, and technical measures are GDPR- and revDSG-compliant. The output is a concrete finding with prioritised fixes — from people who run SaaS themselves.
IT strategy & roadmap
An IT strategy answers which technical investments advance your business goals most — and in what order. The result is a prioritised roadmap that turns a diffuse wish list into an executable plan with clear action areas and milestones.
FAQ
Can we negotiate a large vendor’s standard agreement?
With large platform vendors, usually not. The review still pays off, because it shows which residual risks you are accepting and what has to be mitigated elsewhere.
Do we need a DPA for small tools too?
Once personal data is processed on your behalf, yes — regardless of scale. Small tools such as error tracking or form services are precisely the ones that get overlooked.
What applies to Swiss companies?
The revised Swiss data protection act also requires contractual regulation of processing on behalf. Where there is an EU nexus, Article 28 GDPR applies in addition.
More checklists
Technical due diligence: what can be established in a few days
Technical due diligence under time pressure concentrates on six questions: does the architecture carry the planned growth path, how large is the technical debt, does the system depend on individuals, how do security and licensing stand, and can operations be handed over.
Technical SEO review: the points that actually block indexing
Most technical SEO problems trace back to a handful of causes: pages are not indexable, canonicals point elsewhere, the sitemap lists pages that should not be indexed, hreflang is not reciprocal, or pages carry almost no internal links.
Visibility in AI answers: a checklist for being citable
Being citable in AI answers rests on a few properties: a short self-contained answer near the top, unambiguous statements instead of marketing language, verifiable claims with a date and an author, clean access for AI crawlers, and identifiable authorship.
