Delivery kit

DPA notes — what a data processing agreement needs

Last changed 2026-08-05 · all documents · security & deployment

I do not draft DPAs. Not from scratch, not from memory, not by adapting something I found. Where I am processing personal data on a client's behalf, I start from a standard model — the client's own DPA, an industry-standard controller-to-processor template, or the European Commission's standard contractual clauses where they apply — and I have it reviewed by a qualified professional before I sign it.

This file is a checklist for reading a DPA someone hands me, and for knowing when to ask a lawyer. It is not legal advice and it contains no legal text on purpose. Nothing here is a substitute for a review.

When a DPA is needed

Clauses an EU controller-to-processor DPA needs

Read for these. A missing one is a question for the lawyer, not something I fill in myself.

Things I check against my own operation

The paperwork has to match what I actually do, or it is worse than useless:

Red flags — stop and get advice

My Art. 30 obligation

As a processor I keep my own record of processing activities — templates/gdpr-art30-register.csv. It is separate from the client's record and it is my responsibility, not theirs.