Free tool

DPA checker: does your data processing agreement meet GDPR Article 28?

Paste a vendor's data processing agreement (DPA) and get a clause-by-clause read against Article 28 GDPR: what is there, what is weak, and what to ask the vendor for. Free, no account, and the text is not stored.

Published 7 October 2026 · Sources checked 7 October 2026

Paste the full DPA, including annexes such as the security measures and sub-processor list if you have them. Between 500 and 60,000 characters. For a PDF or Word file, open it, select all, copy and paste here.

0 characters

Privacy: the text is sent to Validemic's server in the EU and checked by AI models from the EU-hosted AI providers named on our Trust page, which do not use it for training. We do not store the text and do not write it to our logs. Even so, remove personal data the check does not need, such as signatories' names.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

On this page
  1. How the checker works
  2. What Article 28 requires, clause by clause
  3. What a good DPA adds
  4. Limits of an automated check
  5. Sources
  6. About this page

How the checker works

The checker reads the text you paste and compares it with each requirement in Article 28 GDPR, the article that governs contracts between a controller (here, the university) and a processor (the vendor). For every requirement it reports one of three results:

Every quote is checked against your text before it is shown, so a quote the AI did not take word for word from the agreement is dropped rather than displayed.

What Article 28 requires, clause by clause

Article 28(3) GDPR says processing by a processor must be governed by a contract or other legal act that is binding on the processor. The list below follows the text of the Regulation as published on EUR-Lex [1], with the EDPB's reading from Guidelines 07/2020 [2].

The description of the processing

The contract must set out the subject-matter and duration of the processing, its nature and purpose, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. The EDPB says this should be specific: naming categories such as "personal data pursuant to Article 4(1) GDPR" is not enough [2].

(a) Documented instructions

The processor may process personal data only on documented instructions from the controller, including for transfers to a third country. If Union or Member State law requires something else, the processor must tell the controller first, unless that law forbids it.

(b) Confidentiality

Everyone authorised to process the data must be bound by confidentiality, either by contract or by a statutory duty.

(c) Security under Article 32

The processor must take all measures required by Article 32. In practice the DPA should describe or annex the technical and organisational measures, rather than promise "appropriate security".

(d), Article 28(2) and 28(4): sub-processors

A processor may not engage another processor without the controller's prior specific or general written authorisation. With a general authorisation, the processor must inform the controller of intended additions or replacements so the controller can object. Any sub-processor must be bound by the same data protection obligations, and the original processor remains fully liable for the sub-processor's performance [1]. The EDPB adds that the contract should set a reasonable timeframe for objections and say what happens after an objection [2].

(e) Data subject rights

Taking into account the nature of the processing, the processor must help the controller answer requests from people exercising their rights under Chapter III, such as access, rectification and erasure.

(f) Assistance with Articles 32 to 36

The processor must assist with security, breach notification to the supervisory authority and to individuals, data protection impact assessments, and prior consultation with the authority.

(g) Deletion or return

At the end of the service, the controller chooses whether the processor deletes or returns all personal data, and existing copies must be deleted unless EU or national law requires storage.

(h) Information and audits

The processor must make available all information needed to demonstrate compliance and allow for and contribute to audits, including inspections, by the controller or an auditor it mandates. The same paragraph requires the processor to tell the controller immediately if it thinks an instruction infringes data protection law.

Article 28(1): sufficient guarantees

Before any of this, the controller may only use processors providing sufficient guarantees of appropriate technical and organisational measures. Article 28(5) allows an approved code of conduct or certification to serve as one element of those guarantees [1].

What a good DPA adds

The EDPB is clear that the agreement "should not merely restate the provisions of the GDPR" but say how the requirements will be met [2]. That is why the checker also looks for four practical points:

The European Commission's standard contractual clauses for controllers and processors (Implementing Decision (EU) 2021/915) are a useful benchmark: they cover each Article 28 point and leave blanks for timeframes such as the advance notice of sub-processor changes [3].

Limits of an automated check

Validemic's analysis

A clause can be present and still be unacceptable: a 30-day breach notice or an audit right limited to a summary report would satisfy a keyword search but not most universities. Treat "Found" as "a clause exists, read it", not as approval. The checker also cannot see documents the DPA refers to (master agreement, security annex, online sub-processor list) unless you paste them, and it does not assess whether the vendor actually follows the agreement. For research data, special category data or large-scale processing, combine the DPA review with a data protection impact assessment and your institution's own requirements.

Sources

  1. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 28, 33 and 44 to 46, OJ L 119, 4.5.2016. EUR-Lex: eur-lex.europa.eu/eli/reg/2016/679/oj/eng. Retrieved 7 October 2026.
  2. European Data Protection Board, Guidelines 07/2020 on the concepts of controller and processor in the GDPR, version 2.1, Part II section 1 (paragraphs 111 to 160). edpb.europa.eu. Retrieved 7 October 2026.
  3. Commission Implementing Decision (EU) 2021/915 on standard contractual clauses between controllers and processors under Article 28(7) GDPR, Clause 7.7. EUR-Lex: eur-lex.europa.eu/eli/dec_impl/2021/915/oj/eng. Retrieved 7 October 2026.

About this page

Requirement wording checked against the GDPR text on EUR-Lex and EDPB Guidelines 07/2020 on 7 October 2026. The checker uses AI models from EU-hosted providers at a fixed setting, and its output is sanitised on our server: every requirement appears exactly once and quotes must match your text. If you spot an error in this page or a result that looks wrong, please contact us and we will correct it.

Frequently asked questions

Is a DPA the same as a data processing agreement or a processor agreement?

Yes. Data processing agreement, data processing addendum, processor agreement and DPA all refer to the contract or other legal act that Article 28(3) GDPR requires between a controller and a processor. In Swedish it is a personuppgiftsbiträdesavtal, in Dutch a verwerkersovereenkomst.

Does a DPA that copies the wording of Article 28 meet the requirements?

It covers the minimum list, but the EDPB says the agreement should not merely restate the GDPR and should explain concretely how each obligation will be met, for example which security measures apply and how quickly breaches are reported. That is why this checker marks vague clauses as partial.

Can I check a PDF or Word file?

Not directly. Open the file, select all text, copy it and paste it into the box. Plain .txt files can be loaded with the file button. Include the annexes (security measures, sub-processor list) if you have them, because the checker only sees what you paste.

Is the text I paste stored or used to train AI?

No. The text is sent to Validemic's server in the EU, checked by the EU-hosted AI providers named on our Trust page, and discarded after the result is returned. We log only its length. Our AI providers do not use it for training.

Is the result legal advice?

No. It is an automated first read that helps you spot gaps quickly. Always read the flagged clauses yourself, and involve your DPO or legal team before signing.