DPA checker: does your data processing agreement meet GDPR Article 28?
Paste a vendor's data processing agreement (DPA) and get a clause-by-clause read against Article 28 GDPR: what is there, what is weak, and what to ask the vendor for. Free, no account, and the text is not stored.
Paste the full DPA, including annexes such as the security measures and sub-processor list if you have them. Between 500 and 60,000 characters. For a PDF or Word file, open it, select all, copy and paste here.
0 characters
Privacy: the text is sent to Validemic's server in the EU and checked by AI models from the EU-hosted AI providers named on our Trust page, which do not use it for training. We do not store the text and do not write it to our logs. Even so, remove personal data the check does not need, such as signatories' names.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
How the checker works
The checker reads the text you paste and compares it with each requirement in Article 28 GDPR, the article that governs contracts between a controller (here, the university) and a processor (the vendor). For every requirement it reports one of three results:
- Found the text clearly covers the requirement, with a short quote so you can find the clause.
- Partial the topic is addressed, but vaguely, with conditions that weaken it, or only by reference to a document you did not paste.
- Not found the pasted text does not address it.
Every quote is checked against your text before it is shown, so a quote the AI did not take word for word from the agreement is dropped rather than displayed.
What Article 28 requires, clause by clause
Article 28(3) GDPR says processing by a processor must be governed by a contract or other legal act that is binding on the processor. The list below follows the text of the Regulation as published on EUR-Lex [1], with the EDPB's reading from Guidelines 07/2020 [2].
The description of the processing
The contract must set out the subject-matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. The EDPB says this should be specific: naming categories such as "personal data pursuant to Article 4(1) GDPR" is not enough [2].
(a) Documented instructions
The processor may process personal data only on documented instructions from the controller, including for transfers to a third country. If Union or Member State law requires something else, the processor must tell the controller first, unless that law forbids it.
(b) Confidentiality
Everyone authorised to process the data must be bound by confidentiality, either by contract or by a statutory duty.
(c) Security under Article 32
The processor must take all measures required by Article 32. In practice the DPA should describe or annex the technical and organisational measures, rather than promise "appropriate security".
(d), Article 28(2) and 28(4): sub-processors
A processor may not engage another processor without the controller's prior specific or general written authorisation. With a general authorisation, the processor must inform the controller of intended additions or replacements so the controller can object. Any sub-processor must be bound by the same data protection obligations, and the original processor remains fully liable for the sub-processor's performance [1]. The EDPB adds that the contract should set a reasonable timeframe for objections and say what happens after an objection [2].
(e) Data subject rights
Taking into account the nature of the processing, the processor must help the controller answer requests from people exercising their rights under Chapter III, such as access, rectification and erasure.
(f) Assistance with Articles 32 to 36
The processor must assist with security, breach notification to the supervisory authority and to individuals, data protection impact assessments, and prior consultation with the authority.
(g) Deletion or return
At the end of the service, the controller chooses whether the processor deletes or returns all personal data, and existing copies must be deleted unless EU or national law requires storage.
(h) Information and audits
The processor must make available all information needed to demonstrate compliance and allow for and contribute to audits, including inspections, by the controller or an auditor it mandates. The same paragraph requires the processor to tell the controller immediately if it thinks an instruction infringes data protection law.
Article 28(1): sufficient guarantees
Before any of this, the controller may only use processors providing sufficient guarantees of appropriate technical and organisational measures. Article 28(5) allows an approved code of conduct or certification to serve as one element of those guarantees [1].
What a good DPA adds
The EDPB is clear that the agreement "should not merely restate the provisions of the GDPR" but say how the requirements will be met [2]. That is why the checker also looks for four practical points:
- Breach notice timeframe. Article 33(2) requires the processor to notify the controller without undue delay. The EDPB suggests the contract may set a specific timeframe, such as a number of hours, plus a contact point and minimum content [2]. The controller's own deadline to the authority is, where feasible, 72 hours under Article 33(1) [1].
- International transfers. Where data leaves the EU/EEA, Chapter V applies: an adequacy decision under Article 45 or appropriate safeguards such as standard contractual clauses under Article 46 [1]. A DPA should name processing locations and the mechanism used.
- Practical audit terms. The EDPB says the parties should work out which type of audit is appropriate (remote, on-site or another way of gathering the information), with the final choice resting with the controller [2]. Look for notice periods, costs and whether certification reports can replace an audit.
- Deletion in practice. The EDPB says the processor should confirm that deletion is completed within an agreed timescale [2].
The European Commission's standard contractual clauses for controllers and processors (Implementing Decision (EU) 2021/915) are a useful benchmark: they cover each Article 28 point and leave blanks for timeframes such as the advance notice of sub-processor changes [3].
Limits of an automated check
Validemic's analysisA clause can be present and still be unacceptable: a 30-day breach notice or an audit right limited to a summary report would satisfy a keyword search but not most universities. Treat "Found" as "a clause exists, read it", not as approval. The checker also cannot see documents the DPA refers to (master agreement, security annex, online sub-processor list) unless you paste them, and it does not assess whether the vendor actually follows the agreement. For research data, special category data or large-scale processing, combine the DPA review with a data protection impact assessment and your institution's own requirements.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 28, 33 and 44 to 46, OJ L 119, 4.5.2016. EUR-Lex: eur-lex.europa.eu/eli/reg/2016/679/oj/eng. Retrieved 7 October 2026.
- European Data Protection Board, Guidelines 07/2020 on the concepts of controller and processor in the GDPR, version 2.1, Part II section 1 (paragraphs 111 to 160). edpb.europa.eu. Retrieved 7 October 2026.
- Commission Implementing Decision (EU) 2021/915 on standard contractual clauses between controllers and processors under Article 28(7) GDPR, Clause 7.7. EUR-Lex: eur-lex.europa.eu/eli/dec_impl/2021/915/oj/eng. Retrieved 7 October 2026.
About this page
Requirement wording checked against the GDPR text on EUR-Lex and EDPB Guidelines 07/2020 on 7 October 2026. The checker uses AI models from EU-hosted providers at a fixed setting, and its output is sanitised on our server: every requirement appears exactly once and quotes must match your text. If you spot an error in this page or a result that looks wrong, please contact us and we will correct it.
Frequently asked questions
Is a DPA the same as a data processing agreement or a processor agreement?
Yes. Data processing agreement, data processing addendum, processor agreement and DPA all refer to the contract or other legal act that Article 28(3) GDPR requires between a controller and a processor. In Swedish it is a personuppgiftsbiträdesavtal, in Dutch a verwerkersovereenkomst.
Does a DPA that copies the wording of Article 28 meet the requirements?
It covers the minimum list, but the EDPB says the agreement should not merely restate the GDPR and should explain concretely how each obligation will be met, for example which security measures apply and how quickly breaches are reported. That is why this checker marks vague clauses as partial.
Can I check a PDF or Word file?
Not directly. Open the file, select all text, copy it and paste it into the box. Plain .txt files can be loaded with the file button. Include the annexes (security measures, sub-processor list) if you have them, because the checker only sees what you paste.
Is the text I paste stored or used to train AI?
No. The text is sent to Validemic's server in the EU, checked by the EU-hosted AI providers named on our Trust page, and discarded after the result is returned. We log only its length. Our AI providers do not use it for training.
Is the result legal advice?
No. It is an automated first read that helps you spot gaps quickly. Always read the flagged clauses yourself, and involve your DPO or legal team before signing.